NIST SP 800-39
NIST SP 800-39 is a guidance document published by the National Institute of Standards and Technology (NIST) that helps an organization manage information security risk across the entire enterprise rather than for a single system in isolation. It describes how to set up an organization-wide program for identifying, assessing, and responding to security risks tied to an organization's operations, missions, and information systems. It offers a structured way of thinking about risk at multiple levels of an organization.
NIST Special Publication 800-39, titled "Managing Information Security Risk: Organization, Mission, and Information System," is NIST guidance (originally issued in 2011) that provides the foundational, multi-tiered approach to organization-wide information security risk management. It frames risk management as a process encompassing establishing the context for risk-related activities, and addresses risk across organizational operations, missions, and information systems. As NIST guidance, it is generally non-binding on its own but is widely referenced within the broader NIST Risk Management Framework (RMF) body of publications. Readers should verify the current applicable revision and consult companion RMF publications for assessment and authorization specifics, which fall outside the scope of this document.
Why it matters
NIST SP 800-39 matters because it addresses a gap that many organizations struggle with: managing information security risk holistically across the enterprise rather than treating each system as an isolated compliance exercise. Published by NIST in 2011, it provides the foundational, multi-tiered perspective that ties information security risk to an organization's operations, missions, and individual information systems. For compliance officers and information system security managers, this framing is important because it reinforces a distinction that experts insist upon: compliance with a control set for a single system is not the same as managing organizational risk. A system can be technically compliant and still contribute to unacceptable enterprise-level risk if broader organizational context is ignored.
Who it's relevant to
Inside SP 800-39
Common questions
Answers to the questions practitioners most commonly ask about SP 800-39.