Risk Management Framework Process Map
PNNL-28347 Prepared for the Department of Energy under Contract DE-AC05-76RL01830 Risk Management Framework Process Map Prepared for the Federal Energy Management Program November 2018 ME Mylrea MD Watson SNG Gourisetti JE Castleberry M Touhiduzzaman iii Acronyms and Abbreviations AO Authorizing Official ISO Information System Owner ISSO Information System Security Officer NIST National Institute of Standards & Technology POA&M Plan of Action and Milestones RAR Risk Assessment Report RMF Risk Management Framework SAR Security Assessment Report SCA Security Control Assessor SCTM Security Controls Traceability Matrix SP Special Publication SSP System Security Plan iv Contents Acronyms and Abbreviations ........................................ ........................................ ...................................... iii Introduction.
Enterprise risk management involves a multitiered approach connecting strategic goals with the daily operations of information systems. Figure 3 depicts this structured risk management process (NIST 2011b). Figure 3. Multi-Tiered Risk Management Strategy. Tier 1 frames the organization risk and informs all other activities.
Download Risk Management Framework Process Map
Information
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document: