Skip to main content
Category: Risk Management Framework

Tier 1/2/3 Risk Management

Also known as: Three-Tiered Risk Management Approach, Risk Management Levels, Organizational Risk Management Tiers
Simply put

Tier 1/2/3 Risk Management refers to a three-level model, defined in NIST SP 800-39, for organizing how an organization manages cybersecurity and related risk. The tiers move from the highest, organization-wide level down through the mission and business process level to the individual system level, so that risk decisions at the top inform activities further down. This layered structure is intended to help leadership align risk decisions across the whole organization rather than treating each system in isolation.

Formal definition

As defined in NIST SP 800-39, the three-tiered risk management approach establishes three organizational levels: Level (Tier) 1 is the organizational level, where senior leadership addresses risk from a governance and enterprise-wide perspective; Level (Tier) 2 is the mission/business process level, where risk is considered in the context of the processes that support the organization's mission; and Level (Tier) 3 is the information system level, where risk is managed for individual systems. The model is intended to be hierarchical and interrelated, with risk-related decisions and guidance flowing between tiers. Note that this NIST SP 800-39 tiering is distinct from other tiering schemes (for example, vendor or assessment tiering models) that use similar 'Tier 1/2/3' terminology; readers should confirm which framework is being referenced and verify the current authoritative text, as specific guidance may be updated across revisions.

Why it matters

Managing cybersecurity risk one system at a time tends to produce inconsistent decisions, duplicated effort, and blind spots at the enterprise level. The Tier 1/2/3 model in NIST SP 800-39 addresses this by connecting risk decisions across three organizational levels, so that governance priorities set by senior leadership flow down into how mission and business processes are structured and, ultimately, into how individual systems are secured. For defense and public sector organizations, this alignment matters because system-level authorization decisions should reflect an organization's broader risk tolerance and mission needs rather than being made in isolation.

The tiered approach also clarifies where accountability sits. When risk is treated purely as a system-level or technical concern, senior leadership can be disconnected from decisions that carry enterprise-wide consequences. By placing organization-wide governance at Tier 1, the model is intended to ensure that risk decisions are informed by leadership priorities and that guidance is communicated consistently across the mission/business process and system tiers.

A common point of confusion is that the phrase 'Tier 1/2/3' appears in several unrelated contexts, such as vendor or assessment tiering schemes. These use similar terminology but describe different concepts. Practitioners should confirm which framework a document is referencing before applying it, and should verify the current authoritative text, since NIST guidance may be updated across revisions.

Who it's relevant to

Senior Leadership and Authorizing Officials
Leadership operating at Tier 1 sets the enterprise-wide governance perspective and makes core risk decisions that shape how the organization tolerates and responds to risk. Their decisions are intended to inform activities at the mission/business process and system tiers, so understanding this model helps ensure risk direction is communicated consistently rather than left to individual system owners.
Mission and Business Process Owners
Those responsible for the processes that support the organization's mission operate at Tier 2, where risk is considered in the context of how those processes function. This tier serves as the link between enterprise-level governance and individual system risk management, translating leadership priorities into process-level considerations.
Information System Security Managers and System Owners
Practitioners managing risk for individual systems operate at Tier 3. Understanding the tiered model helps them recognize that system-level risk decisions should reflect direction from the organizational and mission/business process levels rather than being made in isolation.
Compliance Officers and Auditors
Those assessing an organization's risk management program benefit from understanding how NIST SP 800-39 structures risk across three interrelated levels. They should also be aware that similar 'Tier 1/2/3' terminology appears in unrelated frameworks, and confirm which model applies before drawing conclusions, verifying against the current authoritative text.

Inside Tier 1/2/3 Risk Management

Tier 1 - Organization Level
The highest tier of the multilevel risk management approach described in NIST SP 800-39, addressing risk from an organization-wide perspective. It generally encompasses the risk executive (function), organizational risk tolerance, governance structures, and the risk management strategy that informs decisions at lower tiers.
Tier 2 - Mission/Business Process Level
The middle tier that addresses risk in the context of mission and business processes. It generally includes defining the criticality and sensitivity of processes, establishing enterprise architecture and information security architecture considerations, and translating organizational risk direction into process-level requirements.
Tier 3 - Information System Level
The tier focused on individual information systems, where risk is typically managed through the Risk Management Framework (RMF) steps applied to specific systems. Decisions at this tier are generally guided and constrained by the risk context established at Tiers 1 and 2.
Risk Executive (Function)
An organizational role or capability, associated primarily with Tier 1, intended to provide consistent, enterprise-wide oversight of risk. It generally helps ensure that risk decisions across systems and processes align with organizational risk tolerance and strategy.
Governing Publication
The three-tier model is most directly anchored to NIST SP 800-39, which addresses managing information security risk at the organization, mission/business process, and information system levels. Readers should confirm the current revision and any related NIST guidance, as terminology and emphasis may evolve across revisions.

Common questions

Answers to the questions practitioners most commonly ask about Tier 1/2/3 Risk Management.

Are Tier 1, Tier 2, and Tier 3 the same as system impact levels like low, moderate, and high?
No. This is a common conflation that experts insist on correcting. The three-tier model in NIST's risk management guidance refers to organizational levels of risk management perspective, Tier 1 (organization), Tier 2 (mission/business process), and Tier 3 (information system), not to the categorization of a system's confidentiality, integrity, and availability impact. System impact levels (such as low, moderate, and high) come from a separate categorization process and are distinct from the tiered governance structure. You should verify the current authoritative text for the precise definitions applicable to your environment.
Does risk management happen only at the individual system level, or is the tiered model just paperwork for headquarters?
Neither framing is accurate. The tiered model is intended to be an integrated approach in which risk decisions flow between the organization level (Tier 1), the mission and business process level (Tier 2), and the information system level (Tier 3). Treating risk management as solely a system-level (Tier 3) activity generally misses the strategy, governance, and risk-tolerance context established at higher tiers, while dismissing the upper tiers as mere paperwork overlooks their role in shaping investment, architecture, and process decisions. The tiers are designed to inform one another rather than operate in isolation.
How do the three tiers typically relate to one another in practice?
In most implementations, the tiers are intended to communicate risk-related information bidirectionally. Tier 1 generally establishes organization-wide risk strategy, governance, and risk tolerance; Tier 2 addresses risk from the perspective of mission and business processes, including enterprise architecture and information flows; and Tier 3 focuses on individual information systems and their controls. Guidance and decisions from higher tiers inform lower tiers, while risk information identified at the system level feeds back upward. The specific mechanisms depend on organizational structure, and you should confirm details against the current authoritative publication and any agency-specific tailoring.
Where does the Risk Management Framework (RMF) fit within the tiered structure?
The RMF is most directly exercised at Tier 3, the information system level, where categorization, control selection, implementation, assessment, authorization, and continuous monitoring occur. However, the RMF is intended to operate within the context set by Tier 1 and Tier 2, organizational risk strategy and mission/business process considerations. It is worth noting that assessment and authorization are distinct activities, and that an Authority to Operate is time-bound and subject to continuous monitoring rather than permanent. Confirm the applicable RMF revision and any agency-specific guidance for precise process steps.
Who is generally responsible for activities at each tier?
Responsibility typically differs by tier and by organization. Tier 1 activities are generally associated with senior leadership and governance roles responsible for organization-wide risk strategy and tolerance. Tier 2 activities are commonly linked to mission and business process owners and enterprise architecture functions. Tier 3 activities involve roles closer to individual systems, such as system owners, information system security managers, and authorizing officials in defense RMF contexts. Exact role assignments are organization- and agency-specific, and you should verify them against your governance documentation and current authoritative sources.
How should an organization begin applying the tiered model without duplicating effort across tiers?
The model is intended to reduce, not duplicate, effort by ensuring that risk decisions made at one tier inform the others rather than being repeated independently. In most implementations, an organization establishes risk strategy and tolerance at Tier 1, translates those into mission and business process guidance at Tier 2, and applies that context to system-level control and authorization decisions at Tier 3. Because implementation, contractual, and agency-specific interpretations vary, and because this entry does not cover those specifics, you should confirm the appropriate approach against current official guidance and your organization's governance structure.

Common misconceptions

The three tiers are sequential, self-contained stages you complete one after another.
The tiers describe interrelated levels of risk management that inform one another, not a linear checklist. In most implementations, direction flows down from Tier 1 to Tier 3 while risk information and feedback flow back up, so the tiers operate as an interdependent structure rather than discrete phases.
Tier 3 (system-level) risk management, such as the RMF, is the whole of risk management for an organization.
System-level activity is only one tier. Organization-level (Tier 1) and mission/business process-level (Tier 2) risk decisions establish the context, tolerance, and priorities within which system-level risk is managed. Focusing only on individual systems generally leaves organization-wide risk unaddressed.
Achieving an Authority to Operate (ATO) at Tier 3 means organizational risk is fully managed and settled.
An ATO is time-bound and subject to continuous monitoring, and it reflects an acceptance of risk for a specific system rather than resolution of risk across the enterprise. Compliance and authorization at the system level are distinct from managing aggregated risk at Tiers 1 and 2, and should not be treated as equivalent to overall security.

Best practices

Anchor your program to the current revision of NIST SP 800-39 and confirm how related NIST guidance (such as the RMF at the system level) integrates with it, rather than relying on memory of prior revisions.
Establish and document organizational risk tolerance and a risk management strategy at Tier 1 before pushing requirements down, so that Tier 2 and Tier 3 decisions have a consistent basis.
Ensure risk information flows both directions: propagate organizational direction downward and feed system- and process-level risk findings back upward to inform enterprise decisions.
Maintain a functioning risk executive (function) or equivalent oversight capability to keep system-level risk decisions aligned with organization-wide tolerance and priorities.
Treat system-level authorizations as time-bound and subject to continuous monitoring, and reflect their ongoing status in Tier 1 and Tier 2 risk views rather than as one-time approvals.
Confirm scope-specific obligations (for example, defense systems under the RMF versus civilian systems under FISMA) against current official sources, since applicability and tailoring can differ by environment.