From the course: ISACA Certified Information Security Manager (CISM) Cert Prep

Unlock this course with a free trial

Join today to access over 26,100 courses taught by industry experts.

NIST 800-39

NIST 800-39

- [Instructor] Okay, why don't we take a look at a special publication from NIST, National Institute of Standards and Technologies, and this is NIST 800-39, which is Managing Information Security Risk. Perfect for this course. And there are other organizations that have other risk frameworks, and other risk mitigation documents, or risk assessment documents, but I think NIST is very closely aligned with ISACA's methodology and approach. So let's start off by looking at 800-39. So here we're looking to manage the organizational security risk at three basic levels. The organization, the mission, and the individual information systems. We'll come and talk about this as the three tiers within the organization. We'll look at that in just a few minutes. But basically, what NIST 800-39 tells us, is there are a set of processes that we performed in managing risk. So in the middle we see frame. Risk framing. And what risk framing means is that we put the risk into context, and it's in context…

Contents