Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Guide for Conducting Risk Assessments



Ronald S. Ross


The purpose of Special Publication 800-30 is to provide guidance for conducting risk assessments of federal information systems and organizations, amplifying the guidance provided in Special Publication 800-39. This document provides guidance for carrying out each of the three steps in the risk assessment process (i.e., prepare for the assessment, conduct the assessment, and maintain the assessment) and how risk assessments and other organizational risk management processes complement and inform each other. [Supersedes SP 800-30 (July 2002):]
Special Publication (NIST SP) - 800-30 Rev 1
Report Number
800-30 Rev 1


analysis approach, monitoring risk, risk assessment, risk management, Risk Management Framework, risk model, RMF, threat sources


Ross, R. (2012), Guide for Conducting Risk Assessments, Special Publication (NIST SP), National Institute of Standards and Technology, Gaithersburg, MD, [online], (Accessed July 15, 2024)


If you have any questions about this publication or are having problems accessing it, please contact

Created September 17, 2012, Updated January 27, 2020