HomeFrameworksDefense, Supply Chain & NIST CatalogueNIST SP 800-39

Framework  Defense, Supply Chain & NIST Catalogue

NIST SP 800-39

NIST Special Publication 800-39, "Managing Information Security Risk: Organization, Mission, and Information System View", published March 2011, is the top-level document in the NIST risk management series.

It describes how an organization should frame, assess, respond to, and monitor information security risk, and it introduces the three-tier model (Tier 1 organization, Tier 2 mission and business process, Tier 3 information system) that later NIST documents, including SP 800-37 and the IR 8286 series, build on.

It is deliberately broad: the detailed procedures live in SP 800-30 (assessment) and SP 800-37 (system authorization). There is no certification.

Organizations adopting it produce a risk management strategy that states risk tolerance and assumptions, governance structures and roles at each tier, a risk assessment approach, risk response decisions, and a monitoring strategy that feeds back into the strategy.

AI-compiled
Share
Sponsored
NIST
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with NIST SP 800-39
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Directed at US federal agencies under FISMA; voluntary for others. It is frequently referenced in enterprise risk programs that want a recognized structure for cybersecurity governance.

What the assessor asks to see

Risk management strategy including risk tolerance and framing assumptions; governance charter and role assignments across the three tiers; risk assessment methodology; risk response decisions and rationale; monitoring strategy and reports; evidence that system-level risk decisions trace back to organizational risk tolerance.

Assessors

Who assesses NIST SP 800-39

None.

No firm has claimed a NIST SP 800-39 assessor listing yet. Claim yours →

Consultants

Who helps with NIST SP 800-39

Risk and governance consultancies use it to design risk management strategies and governance charters. Engagements are typically strategy and policy work of a few weeks to a few months.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a NIST SP 800-39 consultant listing yet. Claim yours →

Need a hand implementing it?

Find a Consultant for NIST SP 800-39

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with NIST SP 800-39

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.