Control statement
- a.Develops a comprehensive strategy to manage:
- 1.Security risk to organizational operations and assets, individuals, other organizations, and the Nation associated with the operation and use of organizational systems; and
- 2.Privacy risk to individuals resulting from the authorized processing of personally identifiable information;
- b.Implement the risk management strategy consistently across the organization; and
- c.Review and update the risk management strategy [Organization-defined: frequency] or as required, to address organizational changes.
Discussion
An organization-wide risk management strategy includes an expression of the security and privacy risk tolerance for the organization, security and privacy risk mitigation strategies, acceptable risk assessment methodologies, a process for evaluating security and privacy risk across the organization with respect to the organization’s risk tolerance, and approaches for monitoring risk over time. The senior accountable official for risk management (agency head or designated official) aligns information security management processes with strategic, operational, and budgetary planning processes. The risk executive function, led by the senior accountable official for risk management, can facilitate consistent application of the risk management strategy organization-wide. The risk management strategy can be informed by security and privacy risk-related inputs from other sources, both internal and external to the organization, to ensure that the strategy is broad-based and comprehensive. The supply chain risk management strategy described in [PM-30](#pm-30) can also provide useful inputs to the organization-wide risk management strategy.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Risk Management Strategy as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to enterprise program governance, accountability, resources, metrics, and organization-wide risk decisions.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- program charters and policies
- governance meeting records
- risk and performance metrics
- resource and responsibility assignments
Common failure patterns
- program metrics count activity instead of outcomes
- system-level risks never reach enterprise governance
- responsibilities assigned without authority or resources
- privacy and security managed in separate silos
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- PM-09a.
- PM-09a.01a comprehensive strategy is developed to manage security risk to organizational operations and assets, individuals, other organizations, and the Nation associated with the operation and use of organizational systems;
- PM-09a.02a comprehensive strategy is developed to manage privacy risk to individuals resulting from the authorized processing of personally identifiable information;
- PM-09b.the risk management strategy is implemented consistently across the organization;
- PM-09c.the risk management strategy is reviewed and updated [Organization-defined: frequency] or as required to address organizational changes.
Examine
- Information security program plan
- privacy program plan
- risk management strategy
- supply chain risk management strategy
- procedures addressing the development, implementation, review, and update of the risk management strategy
- risk assessment results relevant to the risk management strategy
- other relevant documents or records
Interview
- Organizational personnel with information security and privacy program planning and plan implementation responsibilities
- organizational personnel responsible for the development, implementation, review, and update of the risk management strategy
- organizational personnel with information security and privacy responsibilities
Test
- Organizational processes for the development, implementation, review, and update of the risk management strategy
- mechanisms supporting the development, implementation, review, and update of the risk management strategy
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.