Security Assessment Standards and Frameworks - NIST Risk Management Framework
2 slides · 1 min read · Domain 6
Security Assessment Standards and Frameworks - NIST Risk Management Frameworks
NIST Risk Management Framework
NIST Risk Management Framework For U.S. government agencies and many of their contractors, the Risk Management Framework, SP 800-37r2, serves as the standard against which audits and control assessments will be performed.
The framework is widely used as a best practice assessment standard, as it has developed through input from academia, private sector entities and individuals and multiple government agencies.
Two other documents that provide further implementation details and requirements in this family are:
- NIST SP 800-53 r5, NIST Security and Privacy Controls for Information Systems and Organization. This provides a customizable, flexible set of controls that organizations can use to protect the security and privacy of information and information systems from a wide variety of threats and risks. It uses a functional approach, more so than a theoretical or conceptual one, to focus on the degree of assurance, or confidence that the controls use to achieve their purpose.
- NIST SP 800-171r1, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. When private companies become part of a Federal government supply chain or process, they need to take on the responsibility of protecting information covered by this security category.
