Is there a common list of Risk Frameworks that logically categorize common IT Risk Statements?

Jim Lamadrid
Kilo Contributor

Hello all: I've been struggling with how to properly categorize risk by the Risk Framework in the GRC Risk Application.  I've taken the GRC Fundamentals class and the examples of Risk Framework categories were: 

1. Physical and Environmental Threats

2. Third Party and Supply Chain Threats

I understand SN does not provide content, but has anyone curated a good set of Risk Frameworks they'd like to share?  We've referenced NIST, but can't find the right fit.   

Sleepless in Salt Lake 

1 ACCEPTED SOLUTION

Community Alums
Not applicable

Probably NIST is the most used but there are few others from ISACA or ISO - it all depends of your organization. The security and privacy control families outlined by NIST 800-53 are flexible, customizable and can be implemented by organizations as part of their overall risk management strategy. The controls cover areas such as access control, security awareness training, formal risk assessments, incident response or continuous monitoring to support organizational risk management. Have you read the information provided by NIST already?

Consider also publications from:

View solution in original post

6 REPLIES 6

Community Alums
Not applicable

Probably NIST is the most used but there are few others from ISACA or ISO - it all depends of your organization. The security and privacy control families outlined by NIST 800-53 are flexible, customizable and can be implemented by organizations as part of their overall risk management strategy. The controls cover areas such as access control, security awareness training, formal risk assessments, incident response or continuous monitoring to support organizational risk management. Have you read the information provided by NIST already?

Consider also publications from:

JohnJasinski
Tera Expert
Consider checking publications from ISACA: COBIT 5 for Risk; and Risk Scenarios using COBIT. Consider entering into GRC for risks and policies. COBIT 2019 Governance and Management Objectives book is free. Share link. Watch www.ISACA.org/COBIT site for more. Also consider learning about CRISC certification program and study guide.

Jim Lamadrid
Kilo Contributor

Thank you Rafael and John for your guidance. I've read through NIST and ISACA COBIT 5 and will have to look deeper into ISO.  I appreciate the quick replies. 

Jan Spurlin
ServiceNow Employee
ServiceNow Employee

@Jim Lamadrid  - another item that may help you is to check out your companies 10k report. There is a standard section in the 10k that lists the top risks for a company. It is always interesting to see what the executives think of as the top risks for a company. If your organization is not public, then consider checking the 10k for a competitor that is public or in the same type of business. I have found some interesting risks and insights by doing this.