Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Prioritizing Cybersecurity Risk for Enterprise Risk Management

Published

Author(s)

Stephen Quinn, Nahla Ivy, Matthew Barrett, Greg Witte, Robert Gardner

Abstract

This document is the second in a series that supplements NIST Interagency Report (IR) 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM). This series provides additional detail regarding the enterprise application of cybersecurity risk information; the previous document, NIST IR 8286A, provided detail regarding stakeholder risk guidance and risk identification and analysis. This second publication describes the need for determining the priorities of each of those risks in light of their potential impact on enterprise objectives, as well as options for properly treating that risk. This report describes how risk priorities and risk response information are added to the cybersecurity risk register (CSRR) in support of an overall enterprise risk register. Information about the selection of and projected cost of risk response will be used to maintain a composite view of cybersecurity risks throughout the enterprise, as detailed in NIST IR 8286C. These composite views may be used to confirm and, if necessary, adjust risk strategy to ensure mission success.
Citation
NIST Interagency/Internal Report (NISTIR) - 8286B-upd1
Report Number
8286B-upd1

Keywords

cybersecurity risk management, cybersecurity risk measurement, cybersecurity risk register (CSRR), enterprise risk management (ERM), risk aggregation, risk conditioning, risk optimization, risk prioritization, risk response.

Citation

Quinn, S. , Ivy, N. , Barrett, M. , Witte, G. and Gardner, R. (2025), Prioritizing Cybersecurity Risk for Enterprise Risk Management, NIST Interagency/Internal Report (NISTIR), National Institute of Standards and Technology, Gaithersburg, MD, [online], https://doi.org/10.6028/NIST.IR.8286B-upd1, https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=959558 (Accessed March 31, 2025)

Issues

If you have any questions about this publication or are having problems accessing it, please contact reflib@nist.gov.

Created February 26, 2025