Book
Guide for Conducting Risk Assessments (NIST SP 800-30 Rev. 1)
by National Institute of Standards and Technology (NIST) · 2012 · 1 reading card · public domain
1 card
Guide for Conducting Risk Assessments (NIST SP 800-30 Rev. 1) · 2012
A risk owner is someone who can allocate budget and stop an activity, not someone who keeps a register.
The definition in the NIST risk assessment guide (SP 800-30 Rev. 1, 2012) is useful precisely because it is dull: risk is a measure of how far an entity is threatened by a circumstance or event, as a function of adverse impact and likelihood of occurrence. ISO 31000:2018 says the same thing differently — the effect of uncertainty on objectives — and adds what the first phrasing lacks: risk is measured against objectives, not against assets. Three terms get confused constantly. Risk appetite is how much risk the organisation seeks in order to reach its objectives; it is a board decision, not a security team decision. Tolerance is the accepted deviation around that appetite, expressed as concrete thresholds that trigger a reaction. The risk owner is the person with the authority and accountability to treat it, meaning someone who can allocate budget and stop an activity. In ISO/IEC 27001:2022, clause 6.1.3 requires owners to approve the treatment plan and accept residual risks.
“Risk is a measure of the extent to which an entity is threatened by a potential circumstance or event, and is typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence.”