Risk Management
DETAIL

NIST SP 800-39 — Managing Information Security Risk: Organization, Mission, and Information System View

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

arrow_back
arrow_forward

Overview

NIST SP 800-39 is a risk management framework that helps organizations identify, assess, and manage information security risk across all levels of the enterprise. It establishes a structured approach for integrating risk management into organizational processes to support cybersecurity and compliance objectives.

Published by the National Institute of Standards and Technology (NIST), this framework is widely adopted by federal agencies, contractors, and organizations seeking robust approaches to information security risk management. NIST SP 800-39 provides guidance for addressing risk at the organizational, mission, and information system levels, covering areas such as risk assessment, security controls, incident response, and governance.

Organizations implement NIST SP 800-39 by embedding risk management practices into their existing security, compliance, and governance programs. The framework supports alignment with other NIST standards (such as NIST RMF and NIST SP 800-53), enabling continuous risk evaluation, effective incident handling, and informed decision-making to strengthen overall cybersecurity posture.

Why it Matters

NIST SP 800-39 enables organizations to manage information securityrisk systematically across all levels, supporting mission objectivesand regulatory compliance.

Key benefits include:

  • Strengthen risk management governance

Establish aconsistent enterprise-wide approach to prioritizing, assessing, andresponding to security risks in alignment with business objectives.

  • Enhance incident response capabilities

Improve theability to identify, assess, and effectively respond to securityevents, reducing the potential impact of cyber incidents.

  • Support regulatory compliance

Facilitatealignment with federal and industry standards for risk management,helping organizations meet statutory and contractual requirements.

  • Improve decision-making

Enable leadershipto make informed resource allocation and risk treatment decisionsbased on comprehensive, organization-wide risk insights.

  • Promote operational resilience

Reducevulnerability to disruptions by integrating risk management intobusiness processes, ensuring continuity of critical operations.

How it Works

NIST SP 800-39 structures enterprise risk management around athree-tiered model—organization, mission/business process, andinformation system—combined with a risk management lifecycle thatframes risk, assesses risk, responds to risk, and monitors risk. Itestablishes governance roles and processes that align securitycontrols, organizational objectives, and compliance requirementsacross these tiers.

In practice organizations apply NIST SP 800-39 by framing risktolerance, conducting risk assessments at each tier, mapping findingsto security controls (often via NIST SP 800-53), and prioritizingresponses and remediations. Continuous monitoring and reporting keepgovernance informed, support compliance evidence, and enableadjustments to security practices and incident response based onchanging threats and business needs.

Using SmartSuite, teams can operationalize NIST SP 800-39 bymaintaining control libraries and a centralized risk register,governing policies, collecting evidence, and tracking compliancetasks. SmartSuite workflows assign remediation actions, schedulereassessments and monitoring feeds, and produce audit-ready reportsand dashboards to support governance and executive decision-making.

Key Elements

  • Organizational Risk Governance Structure

Establishesroles, responsibilities, and oversight mechanisms for enterprise-widerisk management and decision-making.

  • Enterprise Risk Management Process

Describes arecurring, structured approach for identifying, assessing, andresponding to security risks at all levels.

  • Mission and Business Process View

Organizes riskmanagement activities around mission objectives and critical businessoperations.

  • Information System Risk Perspective

Defines theevaluation and management of risks specific to systems handlingorganizational information.

  • Risk Assessment Methodology

Specifiescriteria, methods, and tools for analyzing potential securitythreats, vulnerabilities, and impacts.

  • Continuous Risk Monitoring

Provides ongoingmechanisms to track, review, and update risk posture in response tochanging organizational conditions.

  • Integration with Security Standards

Outlinesalignment of risk management activities with related NIST guidelinesand federal security requirements.

Framework Scope

NIST SP 800-39 is adopted by federal agencies, contractors, andenterprises managing sensitive or mission-critical information. Theframework governs information systems and organizational processesthat require structured risk management, and is typically integratedwhen improving risk assessment practices or enhancing cybersecurityposture, supporting assurance programs and continuous risk oversightacross varied operational environments.

Framework Objectives

NIST SP 800-39 provides a comprehensive approach to managingcybersecurity risk and strengthening organizational governance.

Establish a structured risk management process at organizational,mission, and system levels

Enhance cybersecurity governance to support informed risk-baseddecision-making

Support compliance with relevant laws, regulations, and securitystandards

Improve operational resilience through continuous risk evaluation andmitigation

Promote effective data protection by embedding security controlsacross environments

Enable readiness for audits with documented risk management andoversight practices NIST SP 800-39 provides enterprise riskmanagement guidance that complements the NIST Risk ManagementFramework (SP 800-37) and control catalogues like SP 800-53, andaligns with ISO 31000/ISO 27001 risk principles. Organizations adoptSP 800-39 for governance-driven risk programs, regulatory alignment,integrating security with mission objectives, and enterprise-widedecision-making.

Framework in Context

NIST SP 800-39provides enterprise risk management guidance that complements theNIST Risk Management Framework (SP 800-37) and control catalogueslike SP 800-53, and aligns with ISO 31000/ISO 27001 risk principles.Organizations adopt SP 800-39 for governance-driven risk programs,regulatory alignment, integrating security with mission objectives,and enterprise-wide decision-making.

Common Framework Mappings

Organizations map NIST SP 800-39 to common governance, riskmanagement, and control frameworks to harmonize risk assessments,control selection, and compliance across enterprise programs andexternal requirements.

Mapped frameworks include:

CIS Critical Security Controls

COBIT

FedRAMP

ISO/IEC 27001

ISO/IEC 27005

NIST Cybersecurity Framework

NIST SP 800-53

SOC 2

At a Glance
NIST SP 800-39 (2011)
  • checklist
    Classification
    Category
    info
    Risk Management
    Domain
    info
    Risk Management
    Framework Family
    info
    NIST Special Publications
  • info
    Regulatory Context
    Type
    info
    Regulation
    Legal Instrument
    info
    Framework
    Sector
    info
    Cross-Sector
    Industry
    info
    Cross-Industry
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    Global
    Region Detail
    info
    United States
    Publisher
    info
    National Institute of Standards and Technology (NIST)
  • published_with_changes
    Versioning
    Version
    info
    Rev. 1
    Effective Date
    info
    March 2011
    Issue Date
    info
    March 2011
  • graph_3
    Adoption
    Adoption Model
    info
    Risk Management
    Implementation Complexity
    info
    High
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

NIST SP 800-39 is publicly available from NIST. License included with platform

Official Resources
NIST SP 800-39: Managing Information Security Risk
Defines the management of information security risk in organizational processes.
chevron_forward
NIST Risk Management Framework (RMF)
Outlines the process for risk management in federal information systems.
chevron_forward
NIST SP 800-53: Security and Privacy Controls
Provides controls to protect organizational operations and assets from cybersecurity risks.
chevron_forward
NIST Cybersecurity Framework
Describes common policies to improve cybersecurity risk management.
chevron_forward
NIST Risk Management Overview
Describes integration of risk management into organizational processes.
chevron_forward
SMARTSUITE

How SmartSuite Supports MPA Content Security Program

Manage content protection governance and enforce security practices required to safeguard pre-release media assets and production workflows.

Content Security Control Library

Organize MPA security requirements for production, post-production, storage, and distribution environments with assigned ownership.

Production and Asset Access Governance

Control and document user access to sensitive content, systems, and facilities involved in media production workflows.

Vendor and Production Partner Oversight

Track security requirements, assessments, and contractual obligations for vendors handling pre-release content.

Security Assessments and Compliance Tracking

Manage internal reviews and studio assessments validating adherence to MPA content protection practices.

Incident and Content Leakage Response

Coordinate investigation, escalation, and remediation of security incidents involving protected media assets.

Program Reporting and Studio Assurance

Provide dashboards showing compliance status, open issues, vendor risks, and overall content security readiness.

Related frameworks

COSO ERM 2017

COSO ERM is a framework that helps organizations identify, assess, manage, and monitor enterprise risks to achieve objectives.

Learn More
arrow_forward
ISO 31000:2018

ISO 31000 provides guidelines for identifying, assessing, and managing organizational risks to improve resilience and decision-making.

Learn More
arrow_forward
ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

Learn More
arrow_forward
NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

Learn More
arrow_forward
NIST 800-37 Rev.2

NIST RMF provides a structured process to select, implement, assess, authorize, and continuously monitor cybersecurity and privacy controls.

Learn More
arrow_forward
NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For NIST SP 800-39 (Managing Information Security Risk)

What is NIST SP 800-39 used for?

NIST SP 800-39 provides a structured approach to managing information security risk across an entire organization. It helps organizations identify, assess, and respond to security risks at the organizational, business process, and information system levels, supporting overall cybersecurity resilience.

Is NIST SP 800-39 mandatory or certifiable?

NIST SP 800-39 is not a certifiable standard, but it is mandatory for U.S. federal agencies as part of their information security programs. Organizations in regulated sectors or working with government agencies often adopt it voluntarily to align with federal risk management best practices and demonstrate due diligence.

Who should use NIST SP 800-39, and what is its scope?

NIST SP 800-39 applies to organizations seeking a comprehensive, enterprise-wide risk management strategy for information security. Its scope includes all organizational levels, from governance and mission/business processes to individual information systems, making it suitable for entities of various sizes and industries.

What are the key concepts in NIST SP 800-39?

Key concepts in NIST SP 800-39 include its three-tiered risk management model (organization, mission/business process, and information system), the risk management lifecycle (framing, assessing, responding, and monitoring risk), and governance processes for integrating risk management throughout the organization.

How do organizations implement NIST SP 800-39?

Organizations implement NIST SP 800-39 by establishing risk management policies, defining risk tolerance, performing risk assessments at each tier, and mapping identified risks to specific controls. Continuous monitoring, documented reporting, and coordinated governance ensure effective risk response and mitigation over time.

How does NIST SP 800-39 relate to other NIST frameworks?

NIST SP 800-39 serves as an overarching risk management framework that aligns with other NIST publications, such as NIST SP 800-53 for security controls and the NIST Risk Management Framework (RMF). It provides the structure for integrating these controls and standards into a unified risk management program.

What are the ongoing compliance requirements for NIST SP 800-39?

Ongoing compliance with NIST SP 800-39 requires regular risk assessments, updates to control implementation, incident response readiness, and continuous monitoring of risks and controls. Governance and documentation are essential to demonstrate compliance and adapt to evolving threats and organizational changes.

How would SmartSuite support NIST SP 800-39?

SmartSuite enables organizations to manage NIST SP 800-39 by centralizing risk assessment data, maintaining control libraries, and tracking risk mitigation actions. It supports collection of compliance evidence, facilitates audit readiness with dashboard reporting, automates monitoring workflows, and streamlines governance for executive oversight.

Operationalize NIST SP 800-39 with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

Schedule a Demo
chevron_forward
Demo Library
chevron_forward