Free sample • Members library
NIST SP 800-30 Rev 1: Guide for Conducting Risk Assessments
This is the most useful publicly available document on how to actually structure an information security risk assessment, not just how to score one. It sets out an explicit risk model, three assessment approaches and three analysis approaches, and a full threat and vulnerability taxonomy.
Read it for the method, not the compliance apparatus around it.
What this is, for readers outside the US federal system
NIST SP 800-30 is a US federal guidance document, developed under the Federal Information Security Modernization Act (FISMA) for civilian agencies, but it carries no US-only content. It is a general-purpose method for conducting an information security risk assessment: how to prepare for one, how to conduct it, how to communicate the results, and how to keep it current. It sits one level below NIST SP 800-39 and is the document the Risk Management Framework (SP 800-37) points to whenever a risk assessment task needs doing.
Non-US members should not be put off by the FISMA framing. Strip the compliance layer and what remains is a rigorous, reusable risk assessment methodology that predates and outlasted the mandate that funded it.
Analytic approach to information security
The document's real contribution is methodological discipline, not a checklist. It requires an organisation to make explicit, before assessing anything, four choices most commercial risk assessments leave implicit: a risk model (threat, vulnerability, impact, likelihood, predisposing condition, and how they relate); an assessment approach (quantitative, qualitative, or semi-quantitative); an analysis approach (threat-oriented, asset/impact-oriented, or vulnerability-oriented); and a risk assessment process to combine the above into a defensible result.
It also formalises two concepts rarely made explicit elsewhere: threat shifting, an adversary’s response to countermeasures across time, target, resource or method domains, and risk aggregation, rolling discrete risks into an organisation-level picture. Both are directly transferable to physical security and travel risk practice, not just information systems.
Threat assessment architecture
Appendices D through I give a complete, reusable threat and vulnerability taxonomy: threat sources, threat events, vulnerabilities and predisposing conditions, likelihood-of-occurrence scales, impact scales, and risk determination tables. The likelihood determination is explicitly two-stage, a distinction most commercial 5x5 matrices collapse into one number and lose.
Evolution over time
SP 800-30 began in 2002 as a freestanding risk assessment guide. Revision 1 (2012) nested it inside the three-tier risk management hierarchy introduced by SP 800-39, developed by the same interagency working group that later produced the unified Risk Management Framework in SP 800-37 Rev 2. The direction of travel is consistent: one common information security risk language across defence, intelligence and civilian government.
Relationship to other jurisdictions and ISO/IEC standards
SP 800-30 occupies the same conceptual space as IEC 31010 (Risk assessment techniques), the companion standard to ISO 31000, but purpose-built for information security. An organisation running an ISO 31000-aligned enterprise risk framework, as most Australian and UK entities do, can use SP 800-30 as the information-security-specific technique layer underneath it.
Reference
National Institute of Standards and Technology. Guide for Conducting Risk Assessments, NIST Special Publication 800-30, Revision 1. Gaithersburg, MD: US Department of Commerce, September 2012.
Full text, free of charge, direct from NIST: csrc.nist.gov, SP 800-30 Rev 1.
Members get the full library of in-depth articles across risk science, standards, governance and security, plus practical working tools in PDF and editable Word, with new pieces added regularly.
View membership and join →