Framework Defense, Supply Chain & NIST Catalogue
NIST SP 800-39
NIST Special Publication 800-39, "Managing Information Security Risk: Organization, Mission, and Information System View", published March 2011, is the top-level document in the NIST risk management series.
It describes how an organization should frame, assess, respond to, and monitor information security risk, and it introduces the three-tier model (Tier 1 organization, Tier 2 mission and business process, Tier 3 information system) that later NIST documents, including SP 800-37 and the IR 8286 series, build on.
It is deliberately broad: the detailed procedures live in SP 800-30 (assessment) and SP 800-37 (system authorization). There is no certification.
Organizations adopting it produce a risk management strategy that states risk tolerance and assumptions, governance structures and roles at each tier, a risk assessment approach, risk response decisions, and a monitoring strategy that feeds back into the strategy.
help
Who has to comply
Directed at US federal agencies under FISMA; voluntary for others. It is frequently referenced in enterprise risk programs that want a recognized structure for cybersecurity governance.
What the assessor asks to see
Risk management strategy including risk tolerance and framing assumptions; governance charter and role assignments across the three tiers; risk assessment methodology; risk response decisions and rationale; monitoring strategy and reports; evidence that system-level risk decisions trace back to organizational risk tolerance.
Assessors
Who assesses NIST SP 800-39
None.
No firm has claimed a NIST SP 800-39 assessor listing yet. Claim yours →
Consultants
Who helps with NIST SP 800-39
Risk and governance consultancies use it to design risk management strategies and governance charters. Engagements are typically strategy and policy work of a few weeks to a few months.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a NIST SP 800-39 consultant listing yet. Claim yours →
Software
Tools for NIST SP 800-39
Tools that name this framework in their own material.
Need a hand implementing it?
Find a Consultant for NIST SP 800-39
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with NIST SP 800-39
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.