U.S. Federal Government Risk Management Initiatives

The U.S. federal government has taken many steps to help companies manage IT risks. The initiatives covered in this section are:

  • National Institute of Standards and Technology (NIST)
  • Department of Homeland Security (DHS)
  • National Cybersecurity and Communications Integration Center (NCCIC)
  • United States Computer Emergency Readiness Team (US-CERT)
  • MITRE Corporation and the CVE list

FIGURE 2-3 shows the relationships among many of these organizations. There are two primary paths, under the U.S. Department of Commerce or the DHS.

A hierarchy diagram listing U S federal government organizations involved in risk management initiatives and how they are related.

FIGURE 2-3 Relationships among organizations involved in the ...

Get Managing Risk in Information Systems, 3rd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.