Risk assessment frameworks
There are many industry-standard risk assessment frameworks that a risk manager can choose to perform a risk assessment. The risk manager is responsible for ensuring that the organization utilizes the framework that makes the most sense for its risk assessment.
The following is a summary of common industry risk assessment frameworks:
Framework |
Description |
NIST SP 800-30 |
Risk management for general information systems |
NIST SP 800-37 |
Risk management for federal information systems |
NIST SP 800-161 |
Risk management for supply chain management |
ISO/IEC 27005 |
Risk management for information systems |
ISO/IEC 31010 |
Risk management... |