Risk Management Framework: Helping Organizations Implement Effective Information Security Programs
The management of risks to information technology (IT) systems is a fundamental component of every organization’s information security program. An effective risk management process enables an organization to protect its information assets and supports its ability to carry out its mission successfully. The Information Technology Laboratory of the National Institute of Standards and Technology (NIST) has developed a Risk Management Framework that integrates the essential steps of the risk management process to support organizational managers in making informed decisions regarding the security of their information systems.
NIST’s Risk Management Framework provides a structured process and information to help organizations identify the risks to their information systems, assess the risks, and take steps to reduce risks to an acceptable level. The Federal Information Security Management Act (FISMA) of 2002, Title III of the E-Government Act (Public Law 107-347), requires federal agencies to protect the information and information technology systems that support their operations and assets. NIST develops information security standards and guidelines to help federal agencies plan, implement, and manage comprehensive, risk-based, and balanced information security programs.
See Risk Management Framework: Helping Organizations Implement Effective Information Security Programs from NIST, The National Institute of Standards and Technology, Information Technology Laboratory.
Tags: information security, National Institute of Standards and Technology, NIST, Risk Management, risk management framework, RMF



