Risk management
Term · Cybersecurity · MLC-T-CYB-003607
1. The process of managing risks to organizational operations (including mission, functions, image, or reputation), organizational assets, or individuals resulting from the operation of an information system, and includes: (i) the conduct of a risk assessment; (ii) the implementation of a risk mitigation strategy; and (iii) employment of techniques and procedures for the continuous monitoring of the security state of the information system.
2. The program and supporting processes to manage information security risk to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, and includes: (i) establishing the context for risk-related activities; (ii) assessing risk; (iii) responding to risk once determined; and (iv) monitoring risk over time.
3. Coordinated activities to direct and control an organization with regard to risk.
4. The process of managing risks to agency operations (including mission, functions, image, or reputation), agency assets, or individuals resulting from the operation of an information system. It includes risk assessment; cost-benefit analysis; the selection, implementation, and assessment of security controls; and the formal authorization to operate the system. The process considers effectiveness, efficiency, and constraints due to laws, directives, policies, or regulations.
5. The program and supporting processes to manage risk to agency operations (including mission, functions, image, reputation), agency assets, individuals, other organizations, and the Nation, and includes: establishing the context for risk-related activities; assessing risk; responding to risk once determined; and monitoring risk over time.
6. The program and supporting processes to manage risk to agency operations (including mission, functions, image, reputation), agency assets, individuals, other organizations, and the Nation, and includes: establishing the context for risk-related activities, assessing risk, responding to risk once determined, and monitoring risk over time.
7. The program and supporting processes to manage risk to agency operations (including mission, functions, image, reputation), agency assets, individuals, other organizations, and the Nation, and includes establishing the context for risk-related activities; assessing risk; responding to risk once determined; and monitoring risk over time.
8. The process of managing risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system, and includes: (i) the conduct of a risk assessment; (ii) the implementation of a risk mitigation strategy; and (iii) employment of techniques and procedures for the continuous monitoring of the security state of the information system.
9. The program and supporting processes to manage information security risk to organizational operations (including mission, functions, images, and reputation), organizational assets, individuals, other organizations, and the Nation, and includes: (i) establishing the context for risk-related activities, (ii) assessing risk, (iii) responding to risk once determined, and (iv) monitoring risk over time.
10. The program and supporting processes that manage information security risk to organizational operations (i.e., mission, functions, image, reputation), organizational assets, individuals, and other organizations and that include (i) establishing the context for risk-related activities, (ii) assessing risk, (iii) responding to risk once determined, and (iv) monitoring risk over time.
11. The total process of identifying, controlling, and eliminating or minimizing uncertain events that may adversely affect system resources. It includes risk analysis, cost benefit analysis, selection, implementation and test, security evaluation of safeguards, and overall security review.
12. An ISCM capability that focuses on reducing the successful exploits of the other non-meta capabilities that occur because the risk management process fails to correctly identify and prioritize actions and investments needed to lower the risk profile.
13. See Capability, Manage and Assess Risk.
14. The program and supporting processes to manage information security risk to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, and includes:
(i) establishing the context for risk-related activities;
(ii) assessing risk;
(iii) responding to risk once determined; and
(iv) monitoring risk over time.
15. The process of identifying, assessing, and responding to risk.
| Identifier | MLC-T-CYB-003607 |
|---|---|
| Field | Cybersecurity |
| Synonyms | Capability, Manage and Assess Risk |
| References | FIPS 200; CNSSI 4009-2022 from NIST SP 800-39; NIST SP 800-12 Rev. 1 from NIST SP 800-39; NIST SP 800-128 from NIST SP 800-39; NIST SP 800-137 from FIPS 200 (Adapted); NIST SP 800-30 Rev. 1 from NIST SP 800-39; NIST SP 800-39; NIST IR 8323r1 from NIST SP 800-39; NIST IR 8401 from NIST SP 800-39; NIST IR 8441 from NIST SP 800-39; NISTIR 7621 Rev. 1; NIST SP 800-160v1r1 from ISO Guide 73; NIST SP 800-34 Rev. 1; NIST SP 800-128; NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); NIST SP 800-53 Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-53A Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-53B from OMB Circular A-130 (2016); NIST SP 800-161r1-upd1 [11/1/2024 errata update] from NIST SP 800-53 Rev. 5; NIST SP 800-18r2 from OMB Circular A-130 (2016); NIST SP 800-82r3 from FIPS 200 (adapted); NIST SP 800-175A; NIST SP 800-63-4; NIST SP 800-63A-4; NISTIR 4734; NISTIR 8011 Vol. 1; NISTIR 8170; NIST Cybersecurity Framework Version 1.1; NIST Privacy Framework Version 1.0; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-003607",
"term": "Risk management",
"field": "Cybersecurity",
"definition": "1. The process of managing risks to organizational operations (including mission, functions, image, or reputation), organizational assets, or individuals resulting from the operation of an information system, and includes: (i) the conduct of a risk assessment; (ii) the implementation of a risk mitigation strategy; and (iii) employment of techniques and procedures for the continuous monitoring of the security state of the information system.\n\n2. The program and supporting processes to manage information security risk to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, and includes: (i) establishing the context for risk-related activities; (ii) assessing risk; (iii) responding to risk once determined; and (iv) monitoring risk over time.\n\n3. Coordinated activities to direct and control an organization with regard to risk.\n\n4. The process of managing risks to agency operations (including mission, functions, image, or reputation), agency assets, or individuals resulting from the operation of an information system. It includes risk assessment; cost-benefit analysis; the selection, implementation, and assessment of security controls; and the formal authorization to operate the system. The process considers effectiveness, efficiency, and constraints due to laws, directives, policies, or regulations.\n\n5. The program and supporting processes to manage risk to agency operations (including mission, functions, image, reputation), agency assets, individuals, other organizations, and the Nation, and includes: establishing the context for risk-related activities; assessing risk; responding to risk once determined; and monitoring risk over time.\n\n6. The program and supporting processes to manage risk to agency operations (including mission, functions, image, reputation), agency assets, individuals, other organizations, and the Nation, and includes: establishing the context for risk-related activities, assessing risk, responding to risk once determined, and monitoring risk over time.\n\n7. The program and supporting processes to manage risk to agency operations (including mission, functions, image, reputation), agency assets, individuals, other organizations, and the Nation, and includes establishing the context for risk-related activities; assessing risk; responding to risk once determined; and monitoring risk over time.\n\n8. The process of managing risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system, and includes: (i) the conduct of a risk assessment; (ii) the implementation of a risk mitigation strategy; and (iii) employment of techniques and procedures for the continuous monitoring of the security state of the information system.\n\n9. The program and supporting processes to manage information security risk to organizational operations (including mission, functions, images, and reputation), organizational assets, individuals, other organizations, and the Nation, and includes: (i) establishing the context for risk-related activities, (ii) assessing risk, (iii) responding to risk once determined, and (iv) monitoring risk over time.\n\n10. The program and supporting processes that manage information security risk to organizational operations (i.e., mission, functions, image, reputation), organizational assets, individuals, and other organizations and that include (i) establishing the context for risk-related activities, (ii) assessing risk, (iii) responding to risk once determined, and (iv) monitoring risk over time.\n\n11. The total process of identifying, controlling, and eliminating or minimizing uncertain events that may adversely affect system resources. It includes risk analysis, cost benefit analysis, selection, implementation and test, security evaluation of safeguards, and overall security review.\n\n12. An ISCM capability that focuses on reducing the successful exploits of the other non-meta capabilities that occur because the risk management process fails to correctly identify and prioritize actions and investments needed to lower the risk profile.\n\n13. See Capability, Manage and Assess Risk.\n\n14. The program and supporting processes to manage information security risk to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, and includes:\n(i) establishing the context for risk-related activities;\n(ii) assessing risk;\n(iii) responding to risk once determined; and\n(iv) monitoring risk over time.\n\n15. The process of identifying, assessing, and responding to risk.",
"synonyms": [
"Capability, Manage and Assess Risk"
],
"references": [
"FIPS 200",
"CNSSI 4009-2022 from NIST SP 800-39; NIST SP 800-12 Rev. 1 from NIST SP 800-39; NIST SP 800-128 from NIST SP 800-39; NIST SP 800-137 from FIPS 200 (Adapted); NIST SP 800-30 Rev. 1 from NIST SP 800-39; NIST SP 800-39; NIST IR 8323r1 from NIST SP 800-39; NIST IR 8401 from NIST SP 800-39; NIST IR 8441 from NIST SP 800-39; NISTIR 7621 Rev. 1",
"NIST SP 800-160v1r1 from ISO Guide 73",
"NIST SP 800-34 Rev. 1",
"NIST SP 800-128; NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); NIST SP 800-53 Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-53A Rev. 5 from OMB Circular A-130 (2016)",
"NIST SP 800-53B from OMB Circular A-130 (2016)",
"NIST SP 800-161r1-upd1 [11/1/2024 errata update] from NIST SP 800-53 Rev. 5; NIST SP 800-18r2 from OMB Circular A-130 (2016)",
"NIST SP 800-82r3 from FIPS 200 (adapted)",
"NIST SP 800-175A",
"NIST SP 800-63-4; NIST SP 800-63A-4",
"NISTIR 4734",
"NISTIR 8011 Vol. 1",
"NISTIR 8170",
"NIST Cybersecurity Framework Version 1.1; NIST Privacy Framework Version 1.0",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/risk-management/"
}
Record 3,590 of 4,669 in Cybersecurity terminology (MLC-0102). Request the full dataset.