NIST SP 800-39 describes four connected components of risk management. Information flows between them as the organisation's context, assessments and responses change. Treat them as an ongoing process, rather than four tasks completed once.

Frame, assess, respond and monitor risk exchange information in both directions; framing sits at the centre of the process.
Frame, assess, respond and monitor exchange information throughout the risk management process. Redrawn from NIST SP 800-39. Open full-size diagram.

Frame risk

Establish the context, assumptions, constraints and risk tolerance that guide decisions. Define how the organisation will assess, respond to and monitor risk.

Assess risk

Identify and analyse risk in that context, considering threats, vulnerabilities, likelihood and potential impacts. Record uncertainty and the evidence supporting the assessment.

Respond to risk

Evaluate possible responses, select an appropriate course of action and implement it. The response should reflect the organisation's objectives, constraints and tolerance.

Monitor risk

Review changes in the environment and the effectiveness of the selected responses. Feed the findings back into framing, assessment and response decisions.

Source: NIST SP 800-39, Managing Information Security Risk.