NIST’s how-to for prioritizing risk

Editor’s Note: Draft NISTIR 8179, Criticality Analysis Process Model; Prioritizing Systems and Components,” is available here.

From: GCN | Cybereye

Some of the hardest parts of a security professional’s job are identifying which elements in an enterprise infrastructure pose the greatest risk and keeping that infrastructure secure going forward. The underlying constraint in these considerations is how to do this with a less-than-infinite budget.


That’s what the National Institute of Standards and Technology most recent guidance on risk assessment aims to address. Unlike other cybersecurity guidance NIST has published, however, this document includes a step-by-step process that agencies can use to identify the most critical parts of an infrastructure so they can better choose what to upgrade and where to spend their (usually scarce) dollars.

Read Complete Article


Leave a Reply

Your email address will not be published.

Please Answer: *