NIST RMF, ISO 27005, FAIR, and COSO ERM — Which Framework Is Right for Your Organization?
What Is an IT Risk Management Framework?
An IT risk management framework is a structured methodology that organizations use to identify, assess, quantify, and treat risks to their information technology systems and data. It provides repeatable processes for evaluating threats and vulnerabilities, determining risk tolerance, and implementing controls that reduce risk to acceptable levels .
IT risk management frameworks differ from general enterprise risk management (ERM) by focusing specifically on technology-related threats: cyberattacks, data breaches, system failures, vendor compromise, and regulatory non-compliance .
Major Frameworks Compared
|
Criteria |
NIST RMF |
ISO 27005:2022 |
FAIR v3.0 |
COSO ERM |
|
Primary Focus |
Federal IT security |
Information security risk |
Risk quantification ($) |
Enterprise-wide governance |
|
Approach |
7-step process |
5-step cycle |
Quantitative analysis model |
5 components, 20 principles |
|
Risk Measurement |
Qualitative |
Qualitative or quantitative |
Quantitative (dollar values) |
Qualitative with strategy integration |
|
Control Library |
1,000+ controls |
References ISO 27001 |
No controls |
20 integrated principles |
|
Best For |
Government, contractors |
ISO 27001 certification |
Board-level financial justification |
Cross-functional enterprise risk |
|
Complexity |
High |
Moderate |
Moderate |
High |
NIST Risk Management Framework (RMF)
The NIST RMF is the most comprehensive framework for organizations that need structured, repeatable processes with a deep control library. Its seven steps—Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor—map directly to federal requirements under FISMA but are widely adopted in the private sector .
When to use it: You need compliance with NIST SP 800-53 controls, are a government contractor, or want the most prescriptive implementation guidance available.
ISO 27005:2022
ISO 27005 provides a five-step risk management cycle (Context Establishment, Risk Identification, Risk Analysis, Risk Evaluation, Risk Treatment) with two distinct approaches: event-based assessment and asset-based assessment .
When to use it: You're pursuing ISO 27001 certification and need a risk assessment methodology that integrates with the broader ISO 27000 family of standards.
FAIR v3.0 (Factor Analysis of Information Risk)
FAIR is the only internationally recognized standard for quantifying information risk in financial terms. Updated in January 2025, FAIR v3.0 uses the formula: Risk = Threat Event Frequency × Vulnerability × Loss Magnitude .
When to use it: You need to justify security investments in financial terms, compare risk reduction ROI across projects, or communicate risk to non-technical stakeholders.
COSO ERM
COSO ERM takes a top-down approach, integrating risk management with organizational strategy and performance. Its five components—Governance and Culture, Strategy and Objective Setting, Performance, Review and Revision, Information and Communication—span the entire enterprise rather than focusing on IT alone .
When to use it: You need enterprise-wide risk governance that connects IT risk to business strategy, financial risk, operational risk, and compliance.
How to Choose the Right Framework
|
If Your Organization… |
Start With |
Consider Adding |
|
Is a government contractor or federal agency |
NIST RMF |
FAIR for quantification |
|
Needs ISO 27001 certification |
ISO 27005 |
NIST CSF for maturity benchmarking |
|
Needs to justify security budgets to the board |
FAIR |
NIST CSF for operational controls |
|
Manages risk across multiple business functions |
COSO ERM |
NIST RMF or ISO 27005 for IT specifics |
|
Is a mid-market company starting from scratch |
NIST CSF 2.0 |
ISO 27005 or FAIR as you mature |
Many mature organizations layer frameworks rather than choosing just one. A common approach is COSO ERM for enterprise governance, NIST CSF 2.0 for cybersecurity operations, and FAIR for quantifying risk when presenting to the board .
Action Items for Your Organization
- Assess your regulatory requirements
- Evaluate your risk maturity level
- Choose a primary framework based on your needs
- Consider layering frameworks for different purposes
- Map controls across frameworks to avoid duplication
7. The Five-Step IT Risk Management Lifecycle
Headline: From Identification to Monitoring — The Five Steps Every Organization Needs for Effective IT Risk Management
The Core Risk Management Lifecycle
The core risk management lifecycle follows a consistent pattern across all major frameworks, even though terminology varies. Every framework moves through some version of these phases .
Step 1: Establish Context and Scope
Define what's in scope (business units, systems, data types), your organization's risk appetite, and your risk tolerance .
Key activities:
- Identify business units, systems, and data types in scope
- Define risk appetite—the strategic level of risk you're willing to accept
- Establish risk tolerance—the acceptable deviation from risk appetite
- Document a formal risk appetite statement approved by the board
Risk Appetite vs. Risk Tolerance:
Risk appetite is a strategic, board-level decision about how much risk the organization is willing to pursue in achieving its objectives. Risk tolerance is the operational, business-unit-level acceptable variation around that appetite .
Step 2: Identify and Catalog Risks
Build a risk register by systematically identifying threats, vulnerabilities, and assets .
Key activities:
- Asset-based identification—what systems hold sensitive data?
- Threat-based identification—what attack vectors target our industry?
- Include third-party risks—49% of breaches now originate with vendors
- Include emerging risks from AI deployment
Step 3: Analyze and Quantify
Assess each risk's likelihood and potential impact .
Key activities:
- Start with qualitative ratings (Low/Medium/High/Critical) if you lack data
- Plan to move toward quantitative analysis as you mature
- Use risk quantification formulas and methods
Step 4: Treat and Prioritize
For each risk, select a treatment option based on a cost-benefit analysis :
|
Option |
Description |
Cost/Risk Reduction |
|
Remediate |
Eliminate the root cause permanently |
Highest cost, highest risk reduction |
|
Mitigate |
Reduce likelihood or impact through compensating controls |
Moderate cost, partial reduction |
|
Transfer |
Shift financial exposure through insurance or contractual terms |
Variable |
|
Accept |
Consciously tolerate residual risk within defined appetite |
No cost, risk remains |
|
Avoid |
Eliminate the activity or asset that creates the risk entirely |
Variable |
Remediation vs. Mitigation:
Remediation addresses root causes through permanent fixes—patching a vulnerability, replacing an insecure protocol, or decommissioning an unneeded system. Mitigation reduces consequences of a risk that still exists—adding monitoring, implementing compensating controls, or limiting blast radius .
Step 5: Monitor and Iterate
Risk management is continuous, not a one-time exercise .
Key activities:
- Establish Key Risk Indicators (KRIs)
- Define monitoring cadences
- Integrate risk reviews into existing governance processes
- Document residual risk acceptance
- Regularly update the risk register
Conclusion
Risk management is not a one-time project—it's a continuous cycle. Organizations that follow this five-step lifecycle will be better positioned to identify, assess, and mitigate IT risks effectively.
Action Items for Your Organization
- Document your risk appetite and tolerance
- Build a risk register
- Implement risk quantification
- Define risk treatment plans
- Establish Key Risk Indicators (KRIs)
- Review and update risk assessments regularly