The following comparison helps readers recognize related risk management activities across three publications. It is an editorial explanation, not an official crosswalk or evidence that applying one publication satisfies another.

Editorial comparison of ISO 31000, NIST SP 800-39 and COSO risk-management concepts; the complete comparison is in the accompanying table.
Editorial comparison, not an official crosswalk. The complete comparison follows in a selectable table. Open full-size diagram.
NIST SP 800-39ISO 31000:2018COSO ERM 2017
Frame riskScope, context and criteriaGovernance, culture, strategy and objectives
Assess riskIdentify, analyse and evaluate riskIdentify and prioritise risks to objectives
Respond to riskSelect and implement risk treatmentChoose responses and consider the risk portfolio
Monitor riskMonitor, review, record and reportReview performance, adapt and communicate

The activities overlap and inform each other. Read the table as a comparison of purposes; the rows are not a required sequence or a clause-by-clause equivalence.

NIST SP 800-39 addresses information security risk across the organization, mission or business process, and information system levels. NIST publication

ISO 31000 provides general risk management guidelines. Its scope differs from the ISMS requirements in ISO/IEC 27001. ISO publication

COSO's 2017 ERM framework connects risk with strategy and performance. Its governance and information-related themes support the work throughout; they are not confined to one row of this table. COSO ERM framework