Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

PM-9 — Risk Management Strategy

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

0Enhancements
1Parameters
1Baseline memberships
3Assessment methods

PM — Program Management · NIST SP 800-53 Release 5.2.0

Privacy
Official NIST control content

Control statement

  1. a.Develops a comprehensive strategy to manage:
    1. 1.Security risk to organizational operations and assets, individuals, other organizations, and the Nation associated with the operation and use of organizational systems; and
    2. 2.Privacy risk to individuals resulting from the authorized processing of personally identifiable information;
  2. b.Implement the risk management strategy consistently across the organization; and
  3. c.Review and update the risk management strategy [Organization-defined: frequency] or as required, to address organizational changes.
Official NIST discussion

Discussion

An organization-wide risk management strategy includes an expression of the security and privacy risk tolerance for the organization, security and privacy risk mitigation strategies, acceptable risk assessment methodologies, a process for evaluating security and privacy risk across the organization with respect to the organization’s risk tolerance, and approaches for monitoring risk over time. The senior accountable official for risk management (agency head or designated official) aligns information security management processes with strategic, operational, and budgetary planning processes. The risk executive function, led by the senior accountable official for risk management, can facilitate consistent application of the risk management strategy organization-wide. The risk management strategy can be informed by security and privacy risk-related inputs from other sources, both internal and external to the organization, to ensure that the strategy is broad-based and comprehensive. The supply chain risk management strategy described in [PM-30](#pm-30) can also provide useful inputs to the organization-wide risk management strategy.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

frequencythe frequency at which to review and update the risk management strategy is defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Risk Management Strategy as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to enterprise program governance, accountability, resources, metrics, and organization-wide risk decisions.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • program charters and policies
  • governance meeting records
  • risk and performance metrics
  • resource and responsibility assignments

Common failure patterns

  • program metrics count activity instead of outcomes
  • system-level risks never reach enterprise governance
  • responsibilities assigned without authority or resources
  • privacy and security managed in separate silos

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. PM-09a.
    1. PM-09a.01a comprehensive strategy is developed to manage security risk to organizational operations and assets, individuals, other organizations, and the Nation associated with the operation and use of organizational systems;
    2. PM-09a.02a comprehensive strategy is developed to manage privacy risk to individuals resulting from the authorized processing of personally identifiable information;
  2. PM-09b.the risk management strategy is implemented consistently across the organization;
  3. PM-09c.the risk management strategy is reviewed and updated [Organization-defined: frequency] or as required to address organizational changes.

Examine

  • Information security program plan
  • privacy program plan
  • risk management strategy
  • supply chain risk management strategy
  • procedures addressing the development, implementation, review, and update of the risk management strategy
  • risk assessment results relevant to the risk management strategy
  • other relevant documents or records

Interview

  • Organizational personnel with information security and privacy program planning and plan implementation responsibilities
  • organizational personnel responsible for the development, implementation, review, and update of the risk management strategy
  • organizational personnel with information security and privacy responsibilities

Test

  • Organizational processes for the development, implementation, review, and update of the risk management strategy
  • mechanisms supporting the development, implementation, review, and update of the risk management strategy
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Source record

Authoritative sources