id: "PM-28" title: "Risk Framing" family: "PM" family_name: "Program Management" sort_id: "pm-28" priority: "P1" implementation_level: "organization"


Identify and document:

Assumptions affecting risk assessments, risk responses, and risk monitoring;

Constraints affecting risk assessments, risk responses, and risk monitoring;

Priorities and trade-offs considered by the organization for managing risk; and

Organizational risk tolerance;

Distribute the results of risk framing activities to {{ insert: param, pm-28_odp.01 }} ; and

Review and update risk framing considerations {{ insert: param, pm-28_odp.02 }}.

Guidance

Risk framing is most effective when conducted at the organization level and in consultation with stakeholders throughout the organization including mission, business, and system owners. The assumptions, constraints, risk tolerance, priorities, and trade-offs identified as part of the risk framing process inform the risk management strategy, which in turn informs the conduct of risk assessment, risk response, and risk monitoring activities. Risk framing results are shared with organizational personnel, including mission and business owners, information owners or stewards, system owners, authorizing officials, senior agency information security officer, senior agency official for privacy, and senior accountable official for risk management.

Assessment Objective: assumptions affecting risk assessments are identified and documented;

Assessment Objective: assumptions affecting risk responses are identified and documented;

Assessment Objective: assumptions affecting risk monitoring are identified and documented;

Assessment Objective: constraints affecting risk assessments are identified and documented;

Assessment Objective: constraints affecting risk responses are identified and documented;

Assessment Objective: constraints affecting risk monitoring are identified and documented;

Assessment Objective: priorities considered by the organization for managing risk are identified and documented;

Assessment Objective: trade-offs considered by the organization for managing risk are identified and documented;

Assessment Objective: organizational risk tolerance is identified and documented;

Assessment Objective: the results of risk framing activities are distributed to {{ insert: param, pm-28_odp.01 }};

Assessment Objective: risk framing considerations are reviewed and updated {{ insert: param, pm-28_odp.02 }}.

Information security program plan

privacy program plan

supply chain risk management strategy

documentation of risk framing activities

policies and procedures for risk framing activities

risk management strategy

Organizational personnel (including mission, business, and system owners or stewards

authorizing officials

senior agency information security officer

senior agency official for privacy

and senior accountable official for risk management)

Organizational procedures and practices for authorizing, conducting, managing, and reviewing personally identifiable information processing

organizational processes for risk framing

mechanisms supporting the development, review, update, and approval of risk framing