Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Enterprise Impact of Information & Communications Technology Risk



Stephen Quinn, Nahla Ivy, Matthew Barrett, Larry Feldman, Daniel Topper, Greg Witte, Karen Scarfone, Robert Gardner, Julie Chua


All enterprises should ensure that information and communications technology (ICT) risk receives appropriate attention within their enterprise risk management (ERM) programs. This document is intended to help individual organizations within an enterprise improve their ICT risk management (ICTRM). This can enable enterprises and their component organizations to better identify, assess, and manage their ICT risks in the context of their broader mission and business objectives. This document explains the value of rolling up and integrating risks that may be addressed at lower system and organizational levels to the broader enterprise level by focusing on the use of ICT risk registers as input to the enterprise risk profile.
Special Publication (NIST SP) - 800-221
Report Number


enterprise risk management (ERM), enterprise risk profile (ERP), enterprise risk register (ERR), information and communications technology (ICT), ICT risk, ICT risk management (ICTRM), ICT risk measurement, risk appetite, risk register, risk tolerance.


Quinn, S. , Ivy, N. , Barrett, M. , Feldman, L. , Topper, D. , Witte, G. , Scarfone, K. , Gardner, R. and Chua, J. (2023), Enterprise Impact of Information & Communications Technology Risk, Special Publication (NIST SP), National Institute of Standards and Technology, Gaithersburg, MD, [online],, (Accessed June 15, 2024)


If you have any questions about this publication or are having problems accessing it, please contact

Created November 17, 2023