Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Staging Cybersecurity Risks for Enterprise Risk Management and Governance Oversight

Published

Author(s)

Stephen Quinn, Nahla Ivy, Matthew Barrett, Robert Gardner, Matthew Smith, Greg Witte

Abstract

This document is the third in a series that supplements NIST Interagency Report (IR) 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM). This series provides additional details regarding enterprise application of cybersecurity risk information; the previous documents, IRs 8286A and 8286B, provide details regarding stakeholder risk direction and methods for assessing and managing cybersecurity risk in light of enterprise objectives. This report, IR 8286C, describes how information recorded in cybersecurity risk registers may be integrated as part of a holistic approach to ensuring that risks to information and technology are properly considered for the enterprise risk portfolio. This cohesive understanding supports an enterprise risk register and enterprise risk profile that, in turn, support the achievement of enterprise objectives.
Citation
NIST Interagency/Internal Report (NISTIR) - 8286Cr1
Report Number
8286Cr1

Keywords

cybersecurity risk management (CSRM), cybersecurity risk measurement, cybersecurity risk register (CSRR), enterprise risk management (ERM), enterprise risk profile (ERP), enterprise risk register (ERR), key performance indicator (KPI), key risk indicator (KRI), risk prioritization.

Citation

Quinn, S. , Ivy, N. , Barrett, M. , Gardner, R. , Smith, M. and Witte, G. (2025), Staging Cybersecurity Risks for Enterprise Risk Management and Governance Oversight, NIST Interagency/Internal Report (NISTIR), National Institute of Standards and Technology, Gaithersburg, MD, [online], https://doi.org/10.6028/NIST.IR.8286Cr1, https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=960492 (Accessed December 19, 2025)

Issues

If you have any questions about this publication or are having problems accessing it, please contact [email protected].

Created December 18, 2025
Was this page helpful?