Transcription of Draft NISTIR 8286C, Staging Cybersecurity Risks for ...
1 Withdrawn Draft Warning Notice The attached Draft document has been withdrawn and is provided solely for historical purposes. It has been superseded by the document identified below. Withdrawal Date September 14, 2022 Original Release Date January 26, 2022 Superseding Document Status Final Series/Number NIST IR 8286C Title Staging Cybersecurity Risks for Enterprise Risk Management and Governance Oversight Publication Date September 2022 DOI CSRC URL Additional Information Draft NISTIR 8286C 1 Staging Cybersecurity Risks for 2 Enterprise Risk Management and 3 Governance Oversight 4 5 Stephen Quinn 6 Nahla Ivy 7 Matthew Barrett 8 Greg Witte 9 R.
2 K. Gardner 10 11 12 13 This publication is available free of charge from: 14 15 16 17 18 Draft NISTIR 8286C 19 Staging Cybersecurity Risks for 20 Enterprise Risk Management and 21 Governance Oversight 22 23 Stephen Quinn Matthew Barrett 24 Computer Security Division CyberESI Consulting Group, Inc. 25 Information Technology Laboratory Baltimore, MD 26 27 Nahla Ivy Greg Witte 28 Enterprise Risk Management Office Huntington Ingalls Industries 29 Office of Financial Resource Management Annapolis Junction, MD 30 31 R. K. Gardner 32 New World Technology Partners 33 Annapolis, MD 34 35 36 This publication is available free of charge from: 37 38 39 40 January 2022 41 42 43 44 Department of Commerce 45 Gina M.
3 Raimondo, Secretary 46 47 National Institute of Standards and Technology 48 James K. Olthoff, Performing the Non-Exclusive Functions and Duties of the Under Secretary of Commerce 49 for Standards and Technology & Director, National Institute of Standards and Technology 50 National Institute of Standards and Technology Interagency or Internal Report 8286C 51 44 pages ( January 2022) 52 This publication is available free of charge from: 53 Certain commercial entities, equipment, or materials may be identified in this document in order to describe an 55 experimental procedure or concept adequately.
4 Such identification is not intended to imply recommendation or 56 endorsement by NIST, nor is it intended to imply that the entities, materials, or equipment are necessarily the best 57 available for the purpose. 58 There may be references in this publication to other publications currently under development by NIST in accordance 59 with its assigned statutory responsibilities. The information in this publication, including concepts and methodologies, 60 may be used by federal agencies even before the completion of such companion publications. Thus, until each 61 publication is completed, current requirements, guidelines, and procedures, where they exist, remain operative.
5 For 62 planning and transition purposes, federal agencies may wish to closely follow the development of these new 63 publications by NIST. 64 Organizations are encouraged to review all Draft publications during public comment periods and provide feedback to 65 NIST. Many NIST Cybersecurity publications, other than the ones noted above, are available at 66 68 69 70 71 72 Public comment period: January 26, 2022 March 11, 2022 Submit comments on this publication to: National Institute of Standards and Technology Attn: Applied Cybersecurity Division, Information Technology Laboratory 100 Bureau Drive (Mail Stop 2000) Gaithersburg, MD 20899-2000 All comments are subject to release under the Freedom of Information Act (FOIA).
6 73 NISTIR 8286C ( Draft ) Staging Cybersecurity Risks FOR ERM AND GOVERNANCE OVERSIGHT ii Reports on Computer Systems Technology 74 The Information Technology Laboratory (ITL) at the National Institute of Standards and 75 Technology (NIST) promotes the economy and public welfare by providing technical 76 leadership for the Nation s measurement and standards infrastructure. ITL develops tests, test 77 methods, reference data, proof of concept implementations, and technical analyses to advance the 78 development and productive use of information technology. ITL s responsibilities include the 79 development of management, administrative, technical, and physical standards and guidelines for 80 the cost-effective security and privacy of other than national security-related information in federal 81 information systems.
7 82 Abstract 83 This document is the third in a series that supplements NIST Interagency/Internal Report ( NISTIR ) 84 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM). This document 85 provides additional detail regarding the enterprise application of Cybersecurity risk information. 86 The previous documents, NISTIRs 8286A and 8286B, provided detail regarding stakeholder risk 87 direction and methods for assessing and managing Cybersecurity risk in light of enterprise 88 objectives. NISTIR 8286C describes how information, as recorded in Cybersecurity risk registers 89 (CSRRs), may be integrated as part of a holistic approach to ensuring that Risks to information and 90 technology are properly considered for the enterprise risk portfolio.
8 This cohesive understanding 91 supports an enterprise risk register (ERR) and enterprise risk profile (ERP) that, in turn, support 92 the achievement of enterprise objectives. 93 Keywords 94 Cybersecurity risk management; Cybersecurity risk measurement; Cybersecurity risk register 95 (CSRR); enterprise risk management (ERM); key performance indicator (KPI); key risk indicator 96 (KRI); risk acceptance; risk aggregation; risk avoidance; risk conditioning; risk mitigation; risk 97 optimization; risk prioritization; risk response; risk sharing; risk transfer. 98 Acknowledgments 99 The authors wish to thank those who have contributed to the creation of this Draft .
9 A detailed 100 acknowledgment will be included in the final publication. 101 Document Conventions 102 For this document, the terms Cybersecurity and information security are used interchangeably. 103 While information security is generally considered to be all-encompassing including the 104 Cybersecurity domain the term Cybersecurity has expanded in conventional usage to be 105 equivalent to information security. Likewise, the terms Cybersecurity Risk Management (CSRM) 106 and Information Security Risk Management (ISRM) are used interchangeably based on the same 107 reasoning.
10 108 NISTIR 8286C ( Draft ) Staging Cybersecurity Risks FOR ERM AND GOVERNANCE OVERSIGHT iii Note to Reviewers 109 The authors are grateful for the feedback and support provided by the community in response to 110 Draft publications. In support of the final edition of this report, NIST asks that readers review the 111 following questions and consider these in your feedback and recommendations. 112 1. Is the use of risk criteria for risk reporting, escalation and elevation, and the 113 normalization of Cybersecurity Risks at the organizational and enterprise level effectively 114 discussed? 115 2. Have the differences and distinctions between risk aggregation, deduplication, 116 normalization, optimization, and prioritization been made clear?