Using Business Impact Analysis to Inform Risk Prioritization and Response: NIST IR 8286D available for public comment

2 views
Skip to first unread message

NIST Cybersecurity and Privacy Program

unread,
Jun 10, 2022, 8:36:44 AM6/10/22
to brothermike...@googlegroups.com
NIST

View As Web Page

Header

NIST Cybersecurity and Privacy Program

Using Business Impact Analysis to Inform Risk Prioritization and Response: NIST IR 8286D available for public comment

Traditional business impact analyses (BIAs) have been successfully used for business continuity and disaster recovery (BC/DR) by triaging damaged infrastructure recovery actions that are primarily based on the duration and cost of system outages (i.e., availability compromise). However, BIA analyses can be easily expanded to consider other cyber-risk compromises and remedies.

This initial public draft of NIST IR 8286D, Using Business Impact Analysis to Inform Risk Prioritization and Response, provides comprehensive asset confidentiality and integrity impact analyses to accurately identify and manage asset risk propagation from system to organization and from organization to enterprise, which in turn better informs Enterprise Risk Management deliberations. This document adds expanded BIA protocols to inform risk prioritization and response by quantifying the organizational impact and enterprise consequences of compromised IT Assets.

The public comment period for this draft is open through July 18, 2022. See the publication details for a copy of the draft and instructions for submitting comments.

 

NOTE: A call for patent claims is included on page iii of this draft. For additional information, see Information Technology Laboratory (ITL) Patent Policy--Inclusion of Patents in ITL Publications.

Read More

NIST Cybersecurity and Privacy Program
NIST Applied Cybersecurity Division (ACD)
Questions/Comments about this notice: nisti...@nist.gov
CSRC Website questions: webmast...@nist.gov

Connect with us

facebooktwitteryoutubelinkedinflickr

Received this email from a friend? Subscribe here.

ITL NIST

Subscriber services:

Manage Preferences  |  Unsubscribe  |  Help


If you have questions or problems with the subscription service, please contact subscriberhelp.govdelivery.com.
Technical questions? Contact inqu...@nist.gov. (301) 975-NIST (6478).

This service is provided to you at no charge by National Institute of Standards and Technology (NIST). 100 Bureau Drive, Stop 1070 · Gaithersburg, MD 20899 · 301-975-6478

GovDelivery logo
Reply all
Reply to author
Forward
0 new messages