Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Integrating Cybersecurity and Enterprise Risk Management (ERM)

Published

Author(s)

Kevin M. Stine, Stephen D. Quinn, Gregory A. Witte, Robert Gardner

Abstract

The increasing frequency, creativity, and severity of cybersecurity attacks means that all enterprises should ensure that cybersecurity risk is receiving appropriate attention within their enterprise risk management (ERM) programs. This document is intended to help individual organizations within an enterprise improve their cybersecurity risk information, which they provide as inputs to their enterprise's ERM processes through communications and risk information sharing. By doing so, enterprises and their component organizations can better identify, assess, and manage their cybersecurity risks in the context of their broader mission and business objectives. Focusing on the use of risk registers to set out cybersecurity risk, this document explains the value of rolling up measures of risk usually addressed at lower system and organization levels to the broader enterprise level.
Citation
NIST Interagency/Internal Report (NISTIR) - 8286
Report Number
8286

Keywords

cybersecurity risk management (CSRM), cybersecurity risk measurement, cybersecurity risk profile, cybersecurity risk register (CSRR), enterprise risk management (ERM), enterprise risk profile, risk appetite, risk tolerance

Citation

Stine, K. , Quinn, S. , Witte, G. and Gardner, R. (2020), Integrating Cybersecurity and Enterprise Risk Management (ERM), NIST Interagency/Internal Report (NISTIR), National Institute of Standards and Technology, Gaithersburg, MD, [online], https://doi.org/10.6028/NIST.IR.8286 (Accessed July 17, 2024)

Issues

If you have any questions about this publication or are having problems accessing it, please contact reflib@nist.gov.

Created October 12, 2020, Updated October 15, 2020