conducting-cyber-risk-assessment-with-nist-800-30

Featured

Conduct a defensible cybersecurity risk assessment using the NIST SP 800-30 Rev 1 methodology: prepare scope and a risk model, identify threat sources and threat events, identify vulnerabilities and predisposing conditions, determine likelihood and impact, compute risk, and communicate results as a prioritized risk register. Use when an organization needs an actual risk *assessment* (not a maturity score), when a control framework (CSF, ISO 27001, RMF, SOC 2, PCI) requires a documented risk analysis as input, when leadership asks "what are our top risks and how bad are they", when assessing risk for a new system or major change, or when building a risk register from scratch. This is the methodology that feeds framework selection, ATO packages, and treatment decisions. Keywords: risk assessment, NIST 800-30, threat modeling, likelihood and impact, risk register, risk analysis, threat sources, vulnerabilities, risk determination, qualitative risk, risk matrix, residual risk, risk treatment.

AI & Automation 57 stars 12 forks Updated 1 weeks ago MIT

Install

View on GitHub

Quality Score: 89/100

Stars 20%
59
Recency 20%
90
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Conducting a Cyber Risk Assessment with NIST SP 800-30 ## When to Use - When the organization needs a real risk *assessment* — an analysis of specific threats, likelihoods, and impacts — rather than a maturity score against a framework. (Maturity tells you how mature your practices are; a risk assessment tells you what could hurt you and how badly.) - When another framework requires a documented risk analysis as a mandatory input: NIST CSF (ID.RA), ISO 27001 (Clause 6.1.2), NIST RMF / 800-37 (the Prepare and Select steps), SOC 2 (CC3), PCI DSS, or HIPAA (§164.308(a)(1)(ii)(A)). - When standing up or significantly changing a system and you must understand its risk before authorization or go-live. - When leadership asks for the organization's top risks, ranked, with a rationale they can defend to a board or regulator. - When building or refreshing an enterprise risk register. ## Prerequisites - An inventory of in-scope assets, systems, and the information types they handle (system boundary defined). - Access to threat intelligence (internal incident history, sector ISAC feeds, MITRE ATT&CK) to ground threat-event likelihood in observed behavior. - Vulnerability data (scan results, pen-test findings, configuration/architecture review) for the in-scope systems. - Business context: which missions/processes the systems support, and what impact to confidentiality, integrity, or availability would mean in business terms. - Agreement on the **risk model and scales** before scori...

Details

Author
adriannoes
Repository
adriannoes/awesome-agentic-ai
Created
11 months ago
Last Updated
1 weeks ago
Language
Jupyter Notebook
License
MIT

Integrates with

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Listed

nist-ai-rmf-assessment

Run a gap assessment against the NIST AI Risk Management Framework — GOVERN, MAP, MEASURE, MANAGE — and produce prioritised findings with evidence. Use this whenever NIST AI RMF, AI RMF 1.0, the AI risk management framework, trustworthy AI characteristics, or the Generative AI Profile (NIST AI 600-1) comes up; whenever a US-based or federally-connected organisation needs an AI risk assessment; whenever someone asks "how mature is our AI governance?", "what's our AI risk posture?", or "where are the gaps in how we manage AI?"; and whenever a customer, regulator, insurer, or procurement process asks an organisation to demonstrate AI risk management against a recognised framework. Also use it when an organisation wants a voluntary framework to structure AI governance and has not chosen one, since AI RMF is the most common starting point and maps onward to ISO 42001 and the EU AI Act.

0 Updated today
PKusch
AI & Automation Listed

nist-ai-rmf-assessment

Run a gap assessment against the NIST AI Risk Management Framework — GOVERN, MAP, MEASURE, MANAGE — and produce prioritised findings with evidence. Use this whenever NIST AI RMF, AI RMF 1.0, the AI risk management framework, trustworthy AI characteristics, or the Generative AI Profile (NIST AI 600-1) comes up; whenever a US-based or federally-connected organisation needs an AI risk assessment; whenever someone asks "how mature is our AI governance?", "what's our AI risk posture?", or "where are the gaps in how we manage AI?"; and whenever a customer, regulator, insurer, or procurement process asks an organisation to demonstrate AI risk management against a recognised framework. Also use it when an organisation wants a voluntary framework to structure AI governance and has not chosen one, since AI RMF is the most common starting point and maps onward to ISO 42001 and the EU AI Act.

0 Updated 3 days ago
patkusch
AI & Automation Featured

nist-800-53

NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200 system categorization, control tailoring and overlays, privacy controls (PT family), supply chain risk management (SR family), assessment procedures (SP 800-53A), OSCAL, RMF integration (SP 800-37), and mapping to FedRAMP, FISMA, CMMC 2.0, and ISO 27001. Use for any federal system security controls, FISMA compliance, RMF step guidance, control narrative writing, or baseline tailoring question.

890 Updated 5 days ago
Sushegaad