NIST SP 800-39
NIST SP 800-39 is a U.S. government publication that provides guidance for managing information security risk across an entire organization rather than treating it as a purely technical or system-by-system concern. It describes how to build an organization-wide risk management program that connects leadership decisions, business processes, and individual systems. It offers a structured approach rather than a certification or a mandatory checklist.
NIST Special Publication 800-39, titled 'Managing Information Security Risk: Organization, Mission, and Information System,' provides guidance for an integrated, organization-wide program for managing information security risk. It structures risk management across three interconnected tiers: the Organization tier, the Mission/Business Process tier, and the Information System tier. Within the broader NIST Risk Management Framework (RMF) publication set, it addresses establishing the context for risk-related activities and managing risks to organizational operations. In a virtual CISO engagement, SP 800-39 typically informs governance and risk-program strategy; the vCISO advises on and helps structure such a program, while accountability for adopting and enforcing risk decisions remains with the client organization and its officers. It is guidance rather than a compliance mandate or certifiable standard, and its practical value depends on organizational maturity, stakeholder access, and defined engagement scope.
Why it matters
Many organizations treat information security risk as a collection of technical problems to be solved one system at a time, patching vulnerabilities and configuring tools without connecting those efforts to broader business objectives. NIST SP 800-39 matters because it reframes risk management as an organization-wide discipline that links leadership decisions, mission and business processes, and individual systems into a single coherent program. This shift is central to the way security leadership is practiced: it treats security as a governance and business risk function rather than a purely technical one.
For a virtual CISO engagement, SP 800-39 provides a structured vocabulary and model for helping a client organization establish the context for its risk-related activities. Rather than presenting security decisions as isolated technical judgments, it encourages leaders to consider how risk decisions at the top of the organization shape and constrain choices made at the mission and system levels. This helps executives understand why risk tolerance, resource allocation, and governance structures belong on the leadership agenda and not solely with technical staff.
It is important to be clear about what SP 800-39 does and does not do. It is guidance, not a certification, a mandatory checklist, or a certifiable standard, so adopting it does not by itself demonstrate compliance with any particular regulation or guarantee any security outcome. Its practical value depends heavily on organizational maturity, access to stakeholders, and a clearly defined engagement scope. A vCISO can advise on and help structure a risk management program informed by SP 800-39, but accountability for adopting and enforcing the resulting risk decisions remains with the client organization and its officers.
Who it's relevant to
Inside SP 800-39
Common questions
Answers to the questions practitioners most commonly ask about SP 800-39.