NIST SP 800-39 describes four connected components: framing, assessing, responding to and monitoring risk. They inform one another as objectives, evidence and operating conditions change.
ISO 31000 provides general risk management guidelines. Its assessment process distinguishes identification, analysis and evaluation, within a broader approach that includes communication, consultation, monitoring, review, recording and reporting. ISO 31000 is not an information security management system specification; ISO/IEC 27001 addresses ISMS requirements. This comparison is explanatory, not a formal equivalence between the publications. NIST SP 800-39, ISO 31000:2018, ISO/IEC 27001:2022.
Frame risk
Establish the environment in which decisions will be made. Identify objectives, assumptions, constraints, priorities, appetite, tolerance and decision authority. The resulting strategy should explain how the organisation intends to assess, respond to and monitor risk. Make the risk perceptions behind investment and operational decisions explicit, including the boundaries within which teams may decide and when they must escalate.
Make these choices usable by the people doing the work. For example, specify which criteria apply to a supplier assessment, who can accept the resulting risk and what conditions require escalation.
Assess risk
Identify the threats, weaknesses, potential consequences and likelihood relevant to the stated scope. Consider harm to operations, assets and people, as well as harm that could pass through your organisation to customers, partners or wider services. Include vulnerabilities inside the organisation and in the external systems or services on which it depends. Analyse the scenarios using the agreed model and evidence, then compare the results with the organisation's criteria to decide where action is needed.
Keep the three assessment activities distinct:
| Activity | Question it helps answer |
|---|---|
| Identification | What could affect the objectives, and how? Find, recognise and describe the risks using relevant, current information. |
| Analysis | What are the scenario's characteristics, uncertainty and potential consequences? Examine sources, events, likelihood, existing controls and their effectiveness. |
| Evaluation | How does the result compare with the criteria for a decision? Determine whether further action is required and which results need attention. |
Document uncertainty and limitations along with the rating. A numerical score without its assumptions is difficult to review or reproduce.
Respond to risk
Develop and compare response options, select a course of action consistent with the organisation's risk tolerance and implement the agreed response. Applying the same risk frame across teams makes these decisions comparable. Record the decision authority, reasoning, responsible people and follow-up needed.
In CSFaaS, a response and its justification belong to the risk record. Recommended controls and remediation plans support implementation where applicable. A planned treatment is not evidence that the target exposure has already been achieved.
Monitor risk
Review whether the response is implemented and effective, whether the scenario or operating environment has changed and whether the original assumptions remain sound. Check the resulting security requirements against the business functions, policies and applicable obligations from which they were derived; completing a task alone does not show that those requirements are satisfied. Feed new findings back into the risk frame, assessment and response.
Set review triggers as well as dates: a material supplier change, new vulnerability, failed control or changed business objective may justify reassessment before the next scheduled review. The cycle supports informed decisions rather than a one-time approval that can be left unchanged indefinitely.