Inside Cybersecurity

May 1, 2024

Daily News

NIST opens comment period on cyber and enterprise risk management guide

By Charlie Mitchell / December 15, 2020

A new draft from the National Institute of Standards and Technology offers further guidance on integrating cyber into broader enterprise risk management efforts, building off an October report with more details and examples.

The agency will accept comments through Feb. 1 on draft NISTIR 8286A, “Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management,” which fleshes out “concepts introduced in NISTIR 8286. … It specifically highlights that cybersecurity risk management is an integral part of ERM—both taking its direction...


Log in to access this content.


Not a subscriber? Sign up for 30 days free access to exclusive news and analysis on cybersecurity regulations and more.