Skip to main content
Category: NIST Standards & Publications

NIST SP 800-39

Also known as: SP 800-39, Managing Information Security Risk: Organization, Mission, and Information System View, NIST Special Publication 800-39
Simply put

NIST SP 800-39 is a guidance document published by the National Institute of Standards and Technology (NIST) that helps an organization manage information security risk across the entire enterprise rather than for a single system in isolation. It describes how to set up an organization-wide program for identifying, assessing, and responding to security risks tied to an organization's operations, missions, and information systems. It offers a structured way of thinking about risk at multiple levels of an organization.

Formal definition

NIST Special Publication 800-39, titled "Managing Information Security Risk: Organization, Mission, and Information System," is NIST guidance (originally issued in 2011) that provides the foundational, multi-tiered approach to organization-wide information security risk management. It frames risk management as a process encompassing establishing the context for risk-related activities, and addresses risk across organizational operations, missions, and information systems. As NIST guidance, it is generally non-binding on its own but is widely referenced within the broader NIST Risk Management Framework (RMF) body of publications. Readers should verify the current applicable revision and consult companion RMF publications for assessment and authorization specifics, which fall outside the scope of this document.

Why it matters

NIST SP 800-39 matters because it addresses a gap that many organizations struggle with: managing information security risk holistically across the enterprise rather than treating each system as an isolated compliance exercise. Published by NIST in 2011, it provides the foundational, multi-tiered perspective that ties information security risk to an organization's operations, missions, and individual information systems. For compliance officers and information system security managers, this framing is important because it reinforces a distinction that experts insist upon: compliance with a control set for a single system is not the same as managing organizational risk. A system can be technically compliant and still contribute to unacceptable enterprise-level risk if broader organizational context is ignored.

Who it's relevant to

Compliance Officers and Risk Managers
Those responsible for organization-wide risk programs use SP 800-39 as a conceptual foundation for framing, assessing, and responding to information security risk across missions and systems. It helps them articulate why enterprise context should shape system-level decisions, but they should pair it with companion RMF publications for assessment and authorization specifics that SP 800-39 does not cover.
Information System Security Managers (ISSMs)
ISSMs supporting systems under the NIST RMF benefit from SP 800-39's multi-tiered perspective, which situates individual system risk within broader organizational and mission risk. It reinforces that a technically compliant system may still present organizational risk, though managers must confirm how their specific agency or DoD implementation tailors and applies this guidance.
Authorizing Officials
Officials making risk-based decisions can use SP 800-39's framing of organizational, mission, and information system risk to ground authorization decisions in enterprise context. Because the document is guidance and generally non-binding on its own, authorizing officials should rely on the governing RMF authorization publications for the formal criteria and processes that bind their decisions.
Government Contractors and Assessors
Contractors and auditors working with federal customers may encounter SP 800-39 as background for understanding an organization's risk management approach. They should treat it as foundational guidance rather than a checklist, verify the current applicable revision, and confirm the binding contractual and regulatory requirements that actually govern a given engagement.

Inside SP 800-39

Managing Information Security Risk (Publication Purpose)
NIST SP 800-39, titled 'Managing Information Security Risk: Organization, Mission, and Information System View,' provides the flagship guidance from NIST for an organization-wide, integrated approach to managing information security risk. It is guidance for federal information systems and is generally non-binding on non-federal entities except where incorporated by contract or regulation; readers should verify the current revision against the official NIST text.
Three-Tiered Risk Management Approach
The publication structures risk management across three tiers: Tier 1 (organization level), Tier 2 (mission/business process level), and Tier 3 (information system level). This layered model is intended to promote traceability and consistency of risk decisions from the enterprise down to individual systems.
Risk Management Process Components
SP 800-39 describes four generally recognized components of the risk management process: framing risk, assessing risk, responding to risk, and monitoring risk. These components are intended to be complementary and iterative rather than strictly sequential.
Risk Framing and Risk Tolerance
The document emphasizes establishing a risk frame, which produces the context, assumptions, constraints, and risk tolerance that guide risk-based decisions throughout the organization. This framing informs how the other components are executed.
Relationship to Companion Publications
SP 800-39 functions as the overarching, strategic-level guidance within a family of related NIST publications. It is distinct from the assessment-focused and control-focused documents in the NIST catalog, and does not itself provide the control baselines or the step-by-step system authorization process found in separate publications. Readers should confirm the specific companion documents and their current revisions against official NIST sources.

Common questions

Answers to the questions practitioners most commonly ask about SP 800-39.

Is NIST SP 800-39 the same as the Risk Management Framework (RMF) described in NIST SP 800-37?
No. NIST SP 800-39 and NIST SP 800-37 are distinct publications with different purposes, though they are complementary. NIST SP 800-39 provides the organization-wide, strategic framework for managing information security risk across an enterprise, addressing risk at the organization, mission/business process, and information system tiers. NIST SP 800-37 defines the RMF as the process applied primarily at the system level to categorize, select controls, implement, assess, authorize, and monitor. Treating 800-39 as merely another name for the RMF conflates the broader risk management program with the system-focused lifecycle process. Readers should consult the current revisions of both documents to confirm how NIST characterizes their relationship.
Does following NIST SP 800-39 by itself make an organization compliant or secure?
No. NIST SP 800-39 offers guidance for structuring an organization-wide risk management approach, but compliance and security are not the same thing, and adherence to a guidance document does not by itself establish either. The publication is generally non-binding guidance rather than a mandatory control set; specific compliance obligations flow from authorities such as FISMA, agency policy, DoD issuances, or contractual clauses, depending on the system and its scope. Achieving a defensible security posture also depends on effective implementation, continuous monitoring, and tailoring to the actual threat environment, none of which is guaranteed by referencing the framework. Verify applicable mandates against current authoritative sources for your system category.
How does NIST SP 800-39 relate to the other NIST risk and control publications we already use?
NIST SP 800-39 is generally positioned as the flagship document for organization-wide information security risk management, providing context within which other publications operate. In most implementations it works alongside a risk assessment methodology publication for conducting assessments, the RMF process publication for the system lifecycle, and a control catalog for selecting and tailoring safeguards. Rather than replacing these, 800-39 is intended to give the multi-tier strategic structure that helps organizations relate assessment results, control selection, and authorization decisions to broader mission and business objectives. Confirm the specific document relationships and current revisions in the applicable NIST texts.
Who within an organization is responsible for carrying out the risk management approach described in NIST SP 800-39?
The publication generally frames information security risk management as an enterprise responsibility spanning multiple organizational tiers rather than a task owned solely by system-level staff. In most implementations, senior leaders and governance bodies address risk at the organization tier, mission and business process owners address it at the mission/business tier, and system owners and security personnel address it at the information system tier. Exact role assignments vary by agency and organizational structure and may be defined further in agency policy or supplementary DoD or civilian guidance. Confirm specific responsibilities against your organization's governance documents and the current text of the publication.
Does using NIST SP 800-39 differ for DoD systems versus federal civilian systems?
The core risk management concepts in NIST SP 800-39 are broadly applicable, but how they are operationalized commonly differs across communities. DoD systems are generally governed through DoD RMF implementation guidance and issuances, national security systems may follow separate overlays and authorities, and federal civilian agency systems typically apply the framework in the context of FISMA and agency-specific policy. State, local, tribal, and territorial organizations may adopt the concepts voluntarily but are not bound by the same federal mandates. Because tailoring, overlays, and governing directives vary, verify the specific implementation requirements for your system's category against current authoritative sources.
How should the multi-tier risk approach in NIST SP 800-39 connect to system-level authorization decisions?
The framework is generally intended to ensure that decisions made at the information system tier, such as control selection and authorization, are informed by risk context established at the organization and mission/business process tiers. In practice this means an authorization decision should reflect not only system-specific risk but also organizational risk tolerance and mission priorities communicated from higher tiers. It is worth emphasizing that any resulting Authority to Operate is time-bound and subject to continuous monitoring rather than permanent, and that assessment activities inform but do not equal the authorization decision. Confirm how your organization links these tiers in its governance documentation and the current publication text.

Common misconceptions

SP 800-39 is the Risk Management Framework (RMF) that agencies follow to authorize systems.
SP 800-39 provides the higher-level, organization-wide strategy for managing information security risk and is not itself the step-by-step RMF used to categorize, select controls, and authorize individual systems. The RMF steps are described in separate NIST guidance, and the two should not be treated as interchangeable. Verify the applicable publications against current NIST sources.
SP 800-39 contains the security control baselines organizations must implement.
SP 800-39 addresses the process and governance of managing risk across the organization; it does not provide the security and privacy control catalog or baselines, which are maintained in a separate NIST control publication. Practitioners should not cite SP 800-39 as the source of specific control requirements.
Following SP 800-39 is a mandatory legal requirement for all organizations.
As NIST guidance, SP 800-39 is generally directive for federal information systems and non-binding for others unless it is incorporated through contract, regulation, or agency policy. State, local, tribal, and private-sector obligations may differ, and readers should confirm applicability to their own environment.

Best practices

Apply the three-tiered model deliberately, ensuring that risk decisions at the organization and mission/business tiers explicitly inform and constrain decisions made at the information system tier, rather than treating each tier in isolation.
Establish and document a clear risk frame early, capturing organizational assumptions, constraints, and risk tolerance so that subsequent risk assessment, response, and monitoring activities remain consistent with leadership intent.
Treat the four process components (frame, assess, respond, monitor) as iterative and complementary, revisiting the risk frame as conditions, threats, or mission priorities change rather than executing them only once.
Use SP 800-39 for strategic, organization-wide governance, and pair it with the appropriate companion NIST publications for system-level authorization and control selection, confirming the current revision of each before relying on it.
Verify whether SP 800-39 guidance is binding in your specific context, federal system, contractual flow-down, or agency policy, since its applicability differs across federal, defense, and non-federal environments.
Ensure that risk monitoring is treated as an ongoing activity feeding back into risk decisions, reinforcing that managing information security risk is continuous rather than a one-time exercise.