Integrating Cybersecurity and Enterprise Risk Management (ERM) (2nd Draft)

The National Institute of Standards and Technology (‘NIST’) is seeking comments from business continuity professionals on it recently released second Draft NISTIR 8286 Integrating Cybersecurity and Enterprise Risk Management (‘ERM’) (‘the Draft’) to promote greater understanding of the relationship between cyber security risk management and ERM and the benefits of integrating those approaches. The Draft ... Read more

The National Institute of Standards and Technology (‘NIST’) is seeking comments from business continuity professionals on it recently released second Draft NISTIR 8286 Integrating Cybersecurity and Enterprise Risk Management (‘ERM’) (‘the Draft’) to promote greater understanding of the relationship between cyber security risk management and ERM and the benefits of integrating those approaches.

The Draft contains the same main concepts as the initial public draft, but their presentation has been revised to clarify the concepts and address public comments submitted for the initial draft.

The abstract for the Draft states: The increasing frequency, creativity, and variety of cybersecurity attacks means that all enterprises should ensure cybersecurity risk is getting the appropriate attention within their enterprise risk management (ERM) programs. This document is intended to help individual organizations within an enterprise improve their cybersecurity risk information, which they provide as inputs to their enterprise’s ERM processes through communications and risk information sharing. By doing so, enterprises and their component organizations can better identify, assess, and manage their cybersecurity risks in the context of their broader mission and business objectives. Focusing on the use of risk registers to set out cybersecurity risk, this document explains the value of rolling up measures of risk usually addressed at lower system and organization levels to the broader enterprise level.

To take part in the consultation visit the website. Comments on the Draft can be submitted to nistir8286@nist.gov by 21 August 2020.

News, Safety and Security

Sponsored Content

Webinars, Podcasts & Videos

Business Continuity Webinar

Did You Miss Our Latest Business Continuity Webinar?

It's not too late! You can still watch the “Business Continuity Exercise Planning and Facilitation Techniques To Start Now” video webinar.

facility resilience webinar

From Prevention To Action: The Role Of Facilities Management In Handling Emergencies And Maintenance

This free webinar on facility resilience will provide actionable strategies to safeguard assets, protect lives, and ensure operational continuity.

adaptive decision-making

Listen Now: Decision-Making During A Crisis

Robert C. Chandler, Ph.D, Founder and Principal of Emperiria discusses his research on adaptive decision-making in this podcast.

Receive the latest articles in your inbox

Share to...