Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management: NISTIR 8286A | NIST

Title: NIST Releases Updated Guide for Integrating Cybersecurity Risk Management with Enterprise Risk Management

The National Institute of Standards and Technology (NIST) has published an updated version of its guide for integrating cybersecurity risk management (CSRM) with enterprise risk management (ERM). NISTIR 8286A, titled “Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management,” builds on the concepts introduced in NISTIR 8286.

The report emphasizes the importance of incorporating cybersecurity risk management into the overall enterprise risk management framework, given the increasing frequency and severity of cyber threats. It clarifies various aspects of CSRM and incorporates feedback from the second public comment period.

A companion document, NISTIR 8286C – Staging Cybersecurity Risks for Enterprise Risk Management and Governance Oversight, is expected to be released for review and comment in the coming weeks.

Source: https://www.nist.gov/news-events/news/2021/11/identifying-and-estimating-cybersecurity-risk-enterprise-risk-management

Keywords: Quantum, Enterprise, Risk

Relevance to Rolling Plan

StandardsGPT

Ask your questions!