NIST SP 800-39
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Assess Step (Risk Assessing)
Execute the Assess step per NIST SP 800-39 Chapter 3 Section 3.2 using NIST SP 800-30 (Risk Assessments) as the supporting methodology. Risk assessment must occur at all three tiers: Tier 1 organisation-wide assessment (strategic risk + supply chain + geopolitical + mission dependency), Tier 2 mission and business process assessment (architecture risk + information protection prioritisation + cross-system dependencies), Tier 3 information system assessment (categorisation + threat events + vulnerabilities + likelihood + impact + system risk). Assessments must use a methodology consistent with the risk frame established in Frame. Outputs feed the Respond step and inform risk-based decisions at each tier. The Assess step at Tier 3 directly feeds the NIST SP 800-37 RMF Prepare (P-3 + P-14) and Authorize (R-2) steps.
- Tier 1 organisational risk assessment with strategic risk register
- Tier 2 mission/business process risk assessment per critical function
- Tier 3 information system risk assessments per NIST SP 800-30 feeding RMF Prepare and Authorize
- documented assessment methodology consistent across tiers
- Tier 1 assessment skipped or limited to information security
- Tier 2 assessments produced per system rather than per mission/business process
- inconsistent methodologies across tiers preventing aggregation
Frame Step (Risk Framing)
Execute the Frame step per NIST SP 800-39 Chapter 3 Section 3.1. Framing produces a risk frame that establishes the context within which risk-based decisions are made. The risk frame must capture (a) risk assumptions about threats, vulnerabilities, impact, likelihood, predisposing conditions and uncertainty, (b) risk constraints (legislative, regulatory, contractual, organisational, financial, operational), (c) risk tolerance for each risk category (mission impact, financial loss, regulatory penalty, reputation, safety), (d) risk priorities and trade-offs across competing objectives. Framing must also establish trust relationships and information sharing arrangements per Section 2.3.4 (validated trust + direct historical trust + mediated trust + mandated trust) with mission partners, supply chain, service providers, customers, and external information sources. Output: documented risk fra
- documented risk frame approved at executive level with assumptions + constraints + tolerance + priorities
- trust-relationship register naming mission partners + suppliers + service providers + customers with basis of trust per SP 800-39 Section 2.3.4 categories
- risk frame propagation evidence to Tier 2 and Tier 3
- risk tolerance undocumented so impact ratings cannot be defended
- trust relationships implicit (everyone trusted equally) producing inconsistent decisions
- Tier 2/Tier 3 risk activities operate without an explicit risk frame
Monitor Step (Risk Monitoring)
Execute the Monitor step per NIST SP 800-39 Chapter 3 Section 3.4. Risk monitoring must address (a) effectiveness of risk responses (are implemented controls and other responses achieving intended risk reduction), (b) changes to information systems and operating environments (changes to threat landscape + technology stack + mission + organisation + dependencies), (c) verification of compliance with risk decisions (are accepted-risk conditions still valid + are control selections still appropriate), (d) continuous monitoring strategy aligned with NIST SP 800-137 for information security continuous monitoring, (e) updates to risk posture and reporting to Risk Executive Function + Authorising Officials + Senior Leadership at appropriate cadence, (f) reassessment triggers (significant change + incident + new threat intelligence + control failure + annual cycle). Monitor outputs feed back int
- continuous monitoring strategy per SP 800-137 aligned with risk decisions
- response effectiveness evidence per implemented response
- change tracking covering threat + technology + mission + organisation + dependencies
- reassessment trigger log with documented triggers fired and responses
- monitoring tools deployed without strategy producing data nobody consumes
- no closed loop from Monitor back to Frame/Assess/Respond
- annual reassessment skipped because no significant change triggered earlier
Respond Step (Risk Responding)
Execute the Respond step per NIST SP 800-39 Chapter 3 Section 3.3. Risk response includes (a) identifying alternative courses of action for responding to risk (accept + avoid + mitigate + share + transfer per Section 2.5.2), (b) evaluating alternatives against the risk frame and assessment outputs, (c) deciding on the appropriate response considering cost + effectiveness + acceptability + feasibility, (d) implementing the selected response by mapping to controls per NIST SP 800-53 + organisational change + contractual mechanisms + insurance + service-level agreements as appropriate, (e) documenting and communicating risk decisions with rationale to affected stakeholders at each tier. Risk sharing and transfer arrangements (Section 2.5.2.4) must be explicitly evaluated for supply chain risk per NIST SP 800-161 and other sharing relationships.
- response alternatives register per assessed risk (accept + avoid + mitigate + share + transfer)
- documented risk-response decisions with rationale + accepting authority + re-evaluation trigger
- response implementation evidence (controls + contracts + insurance + organisational change)
- risk sharing/transfer arrangements documented for supply chain and partner relationships
- risk acceptance via inaction rather than explicit decision
- no re-evaluation trigger on accepted risk so it ages indefinitely
- supply chain risk transfer assumed but not contracted
Risk Executive Function
Operate the Risk Executive Function per NIST SP 800-39 Section 2.3 (Risk Management Roles and Responsibilities) and Appendix D (Risk Management Roles). The Risk Executive Function is a senior position (or formally-constituted group) that (a) develops a holistic view of risk to organisational operations and assets + individuals + other organisations + the Nation, (b) ensures consistent risk decisions across the enterprise informed by the risk frame, (c) coordinates Tier 1 + Tier 2 + Tier 3 risk activities, (d) manages risk-related information sharing inside and outside the organisation, (e) provides oversight for risk management activities carried out by mission/business owners and information system owners, (f) advises authorising officials on enterprise risk implications of authorisation decisions. The Risk Executive Function must have a documented charter + meeting cadence + decision a
- Risk Executive Function charter + cadence + decision authority + reporting lines
- REF coordination evidence across Tier 1/Tier 2/Tier 3 activities
- REF advice to authorising officials documented in authorisation packages
- REF reporting to senior leadership + board / audit committee
- Risk Executive Function defined on paper but not staffed
- REF does not consume Tier 2/Tier 3 outputs
- REF reporting stops at CIO rather than reaching board / audit committee
Roles and Governance Integration
Define and operate the risk management roles per NIST SP 800-39 Appendix D and integrate them with broader governance per Section 2.2. Roles include (a) Head of Agency (Chief Executive Officer) accountable for risk management programme, (b) Risk Executive (Function), (c) Chief Information Officer (CIO), (d) Senior Information Security Officer (SAISO), (e) Senior Agency Privacy Officer (SAPO), (f) Authorising Official, (g) Authorising Official Designated Representative, (h) Information System Owner, (i) Information Owner / Steward, (j) Information System Security Officer (ISSO), (k) Mission / Business Owner, (l) Common Control Provider, (m) Enterprise Architect, (n) Information Security Architect, (o) Information System Security Engineer (ISSE), (p) Security Control Assessor. Each role must have documented responsibilities + reporting lines + decision authority + integration with broader
- named individuals or roles for SP 800-39 Appendix D roles per system + organisation
- responsibility matrix integrating risk management roles with broader governance (board, audit committee, risk committee, ERM)
- decision authority and reporting lines documented per role
- roles defined in policy but not implemented in operations
- no integration between IT/cyber risk roles and broader enterprise risk management function
- responsibility matrix exists but is out of date with current organisation
Supply Chain, Sharing, Strategy Maintenance
Operate supply chain risk management + information sharing + risk management strategy maintenance per NIST SP 800-39 (foundational reference) and the implementing publications NIST SP 800-161 (Supply Chain Risk Management Practices) + NIST SP 800-150 (Cyber Threat Information Sharing). Supply chain risk management must (a) identify supply chain risks during Frame + Assess + Respond + Monitor, (b) integrate with procurement + contracts + vendor management + service provider oversight, (c) align supply chain risk responses with overall risk frame. Information sharing must (a) define what information is shared with whom on what basis under what trust assumption, (b) integrate with CISA + sector ISACs + threat intelligence providers + mission partners + customers + suppliers, (c) preserve confidentiality + integrity of shared information per organisational policy + legal constraint. Risk man
- supply chain risk management evidence per SP 800-161 integrated with Frame/Assess/Respond/Monitor cycles
- information sharing register naming what is shared with whom under what trust assumption
- annual strategy review evidence + refresh on significant change + lessons-learned log
- supply chain risk treated as procurement issue rather than enterprise risk
- information sharing ad-hoc without governance over what is shared with whom
- strategy never refreshed despite organisational or threat changes
Three-Tier Risk Management Hierarchy
Establish an organisation-wide risk management strategy per NIST SP 800-39 Chapter 2 (Fundamentals) covering the three-tier hierarchy (Tier 1 Organisation + Tier 2 Mission/Business Process + Tier 3 Information System) and Chapter 3 Section 3.1 (Frame Risk). The strategy must define purpose + scope + assumptions + constraints + risk tolerance + risk priorities + risk-to-be-shared-across-tiers, all aggregated upward and propagated downward across the three tiers. Tier 1 governs organisational risk decisions (risk appetite + budget + executive accountability + Risk Executive Function). Tier 2 governs mission and business process risk (enterprise architecture + segment architecture + protection priorities). Tier 3 governs information system risk (system categorisation + control selection + authorisation decisions per NIST SP 800-37). The strategy document must name the Risk Executive Functio
- approved risk management strategy citing three-tier hierarchy (T1 organisation + T2 mission/business + T3 system)
- Tier 1 risk decisions and risk appetite statement
- Tier 2 enterprise/segment architecture risk decisions
- Tier 3 system-level authorisation decisions
- named Risk Executive Function + Information Security Architect + Authorising Official per tier
- risk decisions made at Tier 3 only with no Tier 1/Tier 2 aggregation
- Risk Executive Function role unstaffed or unnamed
- Tier 2 architecture risk decisions made without explicit risk framing
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-39 framework page.