id: "PM-28" title: "Risk Framing" family: "PM" family_name: "Program Management" sort_id: "pm-28" priority: "P1" implementation_level: "organization"
Identify and document:
Assumptions affecting risk assessments, risk responses, and risk monitoring;
Constraints affecting risk assessments, risk responses, and risk monitoring;
Priorities and trade-offs considered by the organization for managing risk; and
Organizational risk tolerance;
Distribute the results of risk framing activities to {{ insert: param, pm-28_odp.01 }} ; and
Review and update risk framing considerations {{ insert: param, pm-28_odp.02 }}.
Guidance
Risk framing is most effective when conducted at the organization level and in consultation with stakeholders throughout the organization including mission, business, and system owners. The assumptions, constraints, risk tolerance, priorities, and trade-offs identified as part of the risk framing process inform the risk management strategy, which in turn informs the conduct of risk assessment, risk response, and risk monitoring activities. Risk framing results are shared with organizational personnel, including mission and business owners, information owners or stewards, system owners, authorizing officials, senior agency information security officer, senior agency official for privacy, and senior accountable official for risk management.
Assessment Objective: assumptions affecting risk assessments are identified and documented;
Assessment Objective: assumptions affecting risk responses are identified and documented;
Assessment Objective: assumptions affecting risk monitoring are identified and documented;
Assessment Objective: constraints affecting risk assessments are identified and documented;
Assessment Objective: constraints affecting risk responses are identified and documented;
Assessment Objective: constraints affecting risk monitoring are identified and documented;
Assessment Objective: priorities considered by the organization for managing risk are identified and documented;
Assessment Objective: trade-offs considered by the organization for managing risk are identified and documented;
Assessment Objective: organizational risk tolerance is identified and documented;
Assessment Objective: the results of risk framing activities are distributed to {{ insert: param, pm-28_odp.01 }};
Assessment Objective: risk framing considerations are reviewed and updated {{ insert: param, pm-28_odp.02 }}.
Information security program plan
privacy program plan
supply chain risk management strategy
documentation of risk framing activities
policies and procedures for risk framing activities
risk management strategy
Organizational personnel (including mission, business, and system owners or stewards
authorizing officials
senior agency information security officer
senior agency official for privacy
and senior accountable official for risk management)
Organizational procedures and practices for authorizing, conducting, managing, and reviewing personally identifiable information processing
organizational processes for risk framing
mechanisms supporting the development, review, update, and approval of risk framing