The US NIST has publishing two new guidance documents, NIST SP 800-221 and NIST SP 800-221A, which focus on integrating ICT risk management into ERM programs.
NIST states that enterprise risk management programs should consider ICT risks alongside those in other risk disciplines, such as financial or legal, considering impacts on mission and business objectives, strategic planning, and oversight. To assist in this area, NIST has issuing two documents showcasing best practices on how to better integrate ICT risk programs into an overarching ERM portfolio:
NIST Special Publication 800-221, Enterprise Impact of Information and Communications Technology Risk: Governing and Managing ICT Risk Programs Within an Enterprise Risk Portfolio
This helps in understanding the relationship between ICT risk management and ERM – and the benefits of integrating these areas. NIST SP 800-221includes guidance on how all ICT risk programs, including individual programs such as privacy, supply chain, and cyber security, integrate into ERM.
NIST Special Publication 800-221A Information and Communications Technology (ICT) Risk Outcomes: Integrating ICT Risk Management Programs with the Enterprise Risk Portfolio
NIST SP 800-221A provides desired outcomes and applicable references common across all types of ICT risk; it offers a common language for understanding, managing, and expressing ICT risk to internal and external stakeholders and can help identify and prioritize actions to reduce ICT risk.






