NISTIR 8286ANISTIRFinalpublication
NISTIR 8286A - Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management
Provides detailed guidance on identifying and estimating cybersecurity risks within the context of enterprise risk management. Extends NISTIR 8286 with methods for creating cybersecurity risk registers and quantifying risk exposure.
Publication Number
8286A
Series
NISTIR
Status
Final
Date
2021-11
risk identificationrisk estimationERMrisk register