CCAK

 View Only

NIST Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management

  • 1.  NIST Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management

    Posted Dec 15, 2020 01:23:00 AM
      |   view attached
    Hi All,

    NIST has released Draft NISTIR 8286A, Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management (ERM), for public comment. This report provides a more in-depth discussion of the concepts introduced in NISTIR 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM). It specifically highlights that cybersecurity risk management (CSRM) is an integral part of ERM-both taking its direction from ERM and informing it. The increasing frequency, creativity, and severity of cybersecurity attacks mean that all enterprises should ensure that cybersecurity risk is receiving appropriate attention within their ERM programs by ensuring the CSRM program is anchored within the context of ERM. This document is intended to help individual organizations that are already familiar with NISTIR 8286.

    The public comment period for this draft is open through February 1, 2021. See the publication details for a copy of the draft and instructions for submitting comments.



    ------------------------------
    Michael Roza CPA, CISA, CIA, MBA, Exec MBA
    ------------------------------