Hi All,
NIST just released for comment – NISTIR 8286C, Staging Cybersecurity Risks for Enterprise Risk Management and Governance Oversight
This document is the third in a series that supplements NIST Interagency/Internal Report (NISTIR)
8286, Integrating Cybersecurity and Enterprise Risk Management (ERM). This document
provides additional detail regarding the enterprise application of cybersecurity risk information.
The previous documents, NISTIRs 8286A and 8286B, provided detail regarding stakeholder risk
direction and methods for assessing and managing cybersecurity risk in light of enterprise
objectives. NISTIR 8286C describes how information, as recorded in cybersecurity risk registers
(CSRRs), may be integrated as part of a holistic approach to ensuring that risks to information and
technology are properly considered for the enterprise risk portfolio. This cohesive understanding
supports an enterprise risk register (ERR) and enterprise risk profile (ERP) that, in turn, support
the achievement of enterprise objectives.
Public comment period: January 26, 2022 – March 11, 2022
Submit comments on this publication to:
[email protected]------------------------------
Michael Roza CPA, CISA, CIA, MBA, Exec MBA
------------------------------