From the course: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

Unlock this course with a free trial

Join today to access over 23,200 courses taught by industry experts.

Risk management frameworks

Risk management frameworks

- [Instructor] Risk management is a complex topic, and fortunately, organizations don't need to design their own risk management processes from the ground up. Risk management frameworks provide proven, time-tested techniques for performing enterprise risk management. One of the most widely used risk management frameworks was developed by the National Institute of Standards and Technology, a US federal government agency. The NIST process is mandatory for many government computer systems, but private organizations have also widely adopted this approach because they find it helpful. The framework is found in NIST Special Publication 800-37. This document runs over 60 pages and includes great detail on the framework. That's good reading for anyone involved in risk management. The publication is available for free on NIST's website. For our purposes, an overview of the six steps in the process will be more than enough to prepare for the exam. This diagram shows the six steps involved in…

Contents