Guide to Conducting Risk Assessments
Overview of NIST Special Publication 800-30, Revision 1
NIST Risk Management Framework (RMF) Team
sec-cert@[Link]
Risk Management Framework Overview
The RMF provides a structured, yet flexible process
for managing cybersecurity and privacy risk to
information & systems that includes system
categorization, control selection, implementation,
assessment, authorization, and continuous
monitoring.
2
Risk Management Framework Steps
Essential activities to prepare the organization
to manage security and privacy risks
Categorize the system and information
processed, stored, and transmitted based on an
impact analysis
Select the set of NIST SP 800-53 controls to
protect the system based on risk assessment(s)
Implement the controls and document how
controls are deployed
Assess to determine if the controls are in place,
operating as intended, and producing the
desired results
Senior official makes a risk-based decision
to authorize the system (to operate)
Continuously monitor control implementation
and risks to the system 3
Risk Management and Risk Assessment
• Risk assessment is a key component of a holistic risk
management process (as defined in NIST SP 800-39, Managing
ASSESS
Information Security Risk: Organization, Mission, and System
View)
• Risk management processes include:
FRAME • Framing Risk
• Assessing Risk
• Responding to Risk
MONITOR RESPOND
• Monitoring Risk
4
Framing Assessment
Establishing the context for how Identify threat sources & events,
ASSESS
organizations manage information vulnerabilities, determine risk (impact &
security risk likelihood) & uncertainty
FRAME
RISK
MONITOR RESPOND
Response Monitoring
Develop risk response strategy (accept, Verify implementation, determine
reject, mitigate, share/transfer risk) & effectiveness of risk mitigation
courses of action measures, identify changes
5
Key Terms in Risk Assessment
Risk
Risk Assessment Threat
Vulnerability Impact Likelihood
6
Organization-Wide Risk Assessment
Broad-based risk perspective
Strategic
Focus
Level 1: Support organization-wide
strategies/policies/procedures Level 1
Organiza�on
Level 2: Support determination of
Level 2 Tac�cal
mission/business process protection, inform
Mission / Business Process Focus
decisions on use of systems
Level 3
Level 3: Focused on individual systems, System (Environment of Opera�on)
can be conducted during each step of
More detailed and granular risk perspective
the RMF
Three Levels of Organiza�on-Wide
Risk Management 7
NIST SP 800-30, Revision 1: Organization
Chapter 1 - Introduction
Risk Assessment Goal
Chapter 2 – Process overview and terminology
Chapter 3 – Risk assessment process activities • Determination of risk
Supporting appendices, including: • What is the degree of
• Threat sources and threat events potential harm?
• Vulnerabilities and predisposing conditions • How likely would such
• Likelihood of threat occurrence
• Impact harm occur?
• Risk and uncertainty
• Prioritization of risks
8
Risk Management Framework Steps
Essential activities to prepare the organization
to manage security and privacy risks
Categorize the system and information
processed, stored, and transmitted based on an
impact analysis
Select the set of NIST SP 800-53 controls to
protect the system based on risk assessment(s)
Implement the controls and document how
controls are deployed
Assess to determine if the controls are in place,
operating as intended, and producing the
desired results
Senior official makes a risk-based decision
to authorize the system (to operate)
Continuously monitor control implementation
and risks to the system 9
Risk Assessment (RA) Process
Prepare Conduct Maintain
Identify Identify scope Identify threat Identify threat Ongoing
purpose of RA of RA sources events Monitoring
Identify Identify Update RA
Identify Determine
assumptions sources of using results
vulnerabilities likelihood
& constraints information of monitoring
Determine
Define or Determine
adverse
refine the risk risk
impacts
model
10
Assessment Approaches
Quantitative Qualitative
• Based on numbers where proportionality of • Based on non-numerical levels such as low,
values is maintained in and out of the context of moderate, and high
the assessment; higher degree of repeatability
• Results typically easier to convey to decision
• Qualitative-like subjective interpretations may makers
still be involved
• Extra work required to ensure repeatability and
• Benefits may be outweighed by costs in time, reproducibility
effort, and tools
Semi-Quantitative
• Based on scales or representative numbers
whose values/proportions are not maintained in
other contexts, e.g., 0-15, 16-35, 35-70, 71-85,
86-100)
• Expert judgment needed to assign values
appropriately/reduce subjectivity
11
STAY IN TOUCH
CONTACT US
[Link]/RMF sec-cert@[Link]
@NISTcyber
12