Contact Us | Print Page | Sign In | Join Now
Ask the Experts
Blog Home All Blogs
Search all posts for:   

 

View all (37) posts »
 

How can Chief Risk Officers (CRO) and ERM practitioners support Cyber Risk professionals to integrate existing cyber risk management models into the overall framework?

Posted By AFERM, Monday, April 15, 2019
Updated: Monday, November 25, 2024

AFERM EXPERTS SAY...

Version 1.1 of the National Institute of Standards and Technology (NIST) Framework for Improving Critical Infrastructure Cybersecurity, released in July 2018, makes it much easier for CROs and Chief Information Officers (CIO) to align the cybersecurity framework with the agency’s ERM program.  Revised definitions and the introduction of various terms (e.g., risk tolerance) makes the NIST framework align more closely with existing ERM terminology and approaches.  Additionally, Version 1.1 explicitly acknowledges that the NIST framework is not intended to be rigidly applied, but instead, tailored to the needs and environment of the organization.  As stated on page vi, “The decision about how to apply it is left to the implementing organization.”  The greater compatibility with ERM and the flexibility and encouragement to tailor both risk management efforts to the organization provide the basis for integrating cybersecurity within the broader ERM framework.  Figure 2 on page 12 shows an example of how the NIST framework integrates with overall agency risk management efforts.  The revised framework can be found here.

This post has not been tagged.

Permalink | Comments (0)
 
© Copyright 2014-2024 AFERM. All Rights Reserved.
Association for Federal Enterprise Risk Management
1050 Connecticut Ave NW, PO Box 66281 | Washington, DC 20035-6281
Contact Us | | Privacy Notice
Request Organization Information
DUNS: 045074054 | CAGE Code: 7PL42
Association for Federal Enterprise Risk Management is a registered 501(c)(3) non-profit organization. Contributions to AFERM are tax deductible to the extent permitted by law. Membership dues and event registration fees are not considered contributions.