Skip to main content
Category: Risk Management

NIST SP 800-39

Also known as: SP 800-39, NIST Special Publication 800-39, Managing Information Security Risk: Organization, Mission, and Information System
Simply put

NIST SP 800-39 is a U.S. government publication that provides guidance for managing information security risk across an entire organization rather than treating it as a purely technical or system-by-system concern. It describes how to build an organization-wide risk management program that connects leadership decisions, business processes, and individual systems. It offers a structured approach rather than a certification or a mandatory checklist.

Formal definition

NIST Special Publication 800-39, titled 'Managing Information Security Risk: Organization, Mission, and Information System,' provides guidance for an integrated, organization-wide program for managing information security risk. It structures risk management across three interconnected tiers: the Organization tier, the Mission/Business Process tier, and the Information System tier. Within the broader NIST Risk Management Framework (RMF) publication set, it addresses establishing the context for risk-related activities and managing risks to organizational operations. In a virtual CISO engagement, SP 800-39 typically informs governance and risk-program strategy; the vCISO advises on and helps structure such a program, while accountability for adopting and enforcing risk decisions remains with the client organization and its officers. It is guidance rather than a compliance mandate or certifiable standard, and its practical value depends on organizational maturity, stakeholder access, and defined engagement scope.

Why it matters

Many organizations treat information security risk as a collection of technical problems to be solved one system at a time, patching vulnerabilities and configuring tools without connecting those efforts to broader business objectives. NIST SP 800-39 matters because it reframes risk management as an organization-wide discipline that links leadership decisions, mission and business processes, and individual systems into a single coherent program. This shift is central to the way security leadership is practiced: it treats security as a governance and business risk function rather than a purely technical one.

For a virtual CISO engagement, SP 800-39 provides a structured vocabulary and model for helping a client organization establish the context for its risk-related activities. Rather than presenting security decisions as isolated technical judgments, it encourages leaders to consider how risk decisions at the top of the organization shape and constrain choices made at the mission and system levels. This helps executives understand why risk tolerance, resource allocation, and governance structures belong on the leadership agenda and not solely with technical staff.

It is important to be clear about what SP 800-39 does and does not do. It is guidance, not a certification, a mandatory checklist, or a certifiable standard, so adopting it does not by itself demonstrate compliance with any particular regulation or guarantee any security outcome. Its practical value depends heavily on organizational maturity, access to stakeholders, and a clearly defined engagement scope. A vCISO can advise on and help structure a risk management program informed by SP 800-39, but accountability for adopting and enforcing the resulting risk decisions remains with the client organization and its officers.

Who it's relevant to

Executives and Officers Accountable for Risk
Senior leaders who bear organizational and legal accountability for security decisions benefit from SP 800-39's emphasis on the Organization tier, where risk strategy and governance are set. It helps them see how their decisions establish the context that shapes risk at the mission and system levels. A vCISO can advise on structuring this governance, but accountability for adopting and enforcing risk decisions remains with these officers.
Virtual and Fractional CISOs
A vCISO or fractional CISO can use SP 800-39 as a reference model when developing an organization-wide risk management program, connecting leadership decisions, business processes, and systems. Because these engagements focus on strategy, governance, and program development rather than hands-on operational tasks, the tiered structure gives them a way to frame risk conversations across the organization. Its usefulness in any engagement depends on organizational maturity, stakeholder access, and defined scope.
Mission and Business Process Owners
Leaders responsible for specific missions or business processes sit at the middle tier of the model, where organizational risk decisions are translated into operational context. SP 800-39 helps them understand how risk tolerance set at the top affects the systems and processes they own, encouraging risk to be treated as a business concern rather than an isolated technical one.
Organizations Maturing Their Risk Programs
Organizations that currently manage security on a system-by-system basis can use SP 800-39 as a structured approach to build a more integrated, organization-wide program. It is guidance rather than a compliance mandate or certifiable standard, so it is best suited to organizations seeking a coherent framework for connecting governance to systems, with the understanding that adopting it does not by itself assert compliance or certification.

Inside SP 800-39

Organization-Wide Risk Management Focus
NIST SP 800-39, titled 'Managing Information Security Risk,' provides guidance for an integrated, organization-wide approach to managing information security risk. It is oriented toward governance and strategy rather than prescribing specific technical controls.
Three-Tiered Risk Management Approach
The publication describes managing risk across three tiers: the organization level (Tier 1), the mission and business process level (Tier 2), and the information system level (Tier 3). This structure helps connect executive-level risk decisions to operational systems.
Risk Management Process Components
It outlines a risk management process typically comprising framing risk, assessing risk, responding to risk, and monitoring risk. These components are intended to be continuous and iterative rather than a one-time exercise.
Risk Framing and Risk Tolerance
The document emphasizes establishing a risk context, including assumptions, constraints, priorities, and organizational risk tolerance, which informs how risk decisions are made throughout the organization.
Relationship to Broader NIST Guidance
SP 800-39 is often positioned as a foundational risk management document that complements other NIST publications, such as those addressing risk assessment and security control frameworks. It provides context rather than a certification or audit standard.

Common questions

Answers to the questions practitioners most commonly ask about SP 800-39.

Does NIST SP 800-39 apply only to federal agencies, or can private organizations use it?
While NIST SP 800-39 was developed within the federal risk management context, its guidance on managing information security risk at the organizational, mission/business process, and information system levels is often adopted by private-sector organizations as well. A common mistake is treating it as strictly a government-only document; in practice, many enterprises and their advisors reference its multi-tiered approach to structure risk management programs. That said, organizations outside federal contexts typically adapt rather than adopt it wholesale, since its language and assumptions are oriented toward federal environments.
Is NIST SP 800-39 a compliance checklist or certification standard?
No. NIST SP 800-39 is a guidance document describing an organization-wide approach to managing information security risk; it is not a certification standard and does not produce a certifiable outcome the way ISO 27001 certification or a SOC 2 attestation can. Treating it as a checklist misrepresents its purpose. It provides a conceptual and structural framework for how risk decisions flow across organizational tiers, and following it supports a disciplined risk management program rather than proving compliance. Any assertion that an engagement 'certifies' against 800-39 would be inaccurate.
How does a virtual CISO typically use NIST SP 800-39 in an engagement?
In many engagements, a virtual CISO uses NIST SP 800-39 as a reference model to help structure risk management conversations across the organizational, mission/business process, and system tiers. This is generally strategy and governance work: framing risk, establishing risk tolerance, and aligning security decisions with business objectives. It typically does not include hands-on operational tasks. The value of applying it often depends on organizational maturity, access to leadership stakeholders, and a clearly defined engagement scope.
Who holds accountability for the risk decisions informed by NIST SP 800-39?
A virtual CISO may advise on and help design the risk management approach described in 800-39, but legal and organizational accountability for accepting, transferring, mitigating, or avoiding risk generally remains with the client organization and its officers. The document itself emphasizes that risk decisions belong to organizational leadership. Unless a contract explicitly states otherwise, engaging a vCISO to apply this framework does not transfer accountability or liability for those decisions to the advisor.
How does NIST SP 800-39 relate to other frameworks a vCISO might reference, such as NIST CSF or the NIST SP 800-37 Risk Management Framework?
NIST SP 800-39 provides the organization-wide, multi-tiered context for managing information security risk, while related NIST publications address more specific processes. In practice, a virtual CISO may position 800-39 as the higher-level risk management perspective and reference other documents for their respective purposes. How these are combined varies by provider and by client needs. The key is not to conflate a broad risk management approach with the narrower control-selection or process-level activities addressed elsewhere.
What organizational conditions make applying NIST SP 800-39 effective?
Applying NIST SP 800-39 tends to be more effective when the organization has, or is building, sufficient maturity to support tiered risk decision-making, when leadership stakeholders are accessible and engaged, and when risk tolerance can be meaningfully defined at the business level. Its guidance treats security as a governance and business risk function rather than a purely technical one, so client cooperation across executive, business-process, and technical levels is often a limiting factor. Where these conditions are weak, the framework's value may be limited until foundational governance is in place.

Common misconceptions

NIST SP 800-39 is a prescriptive checklist of technical security controls to implement.
SP 800-39 is primarily a governance and risk management guidance document focused on framing, assessing, responding to, and monitoring risk at an organizational level. It does not itself enumerate specific technical controls; that role is typically served by other publications in the NIST family.
Following NIST SP 800-39 guarantees compliance or certification against a regulatory requirement.
SP 800-39 is guidance for managing risk and is not itself a certification standard. Adopting its approach may support a stronger risk management posture and readiness, but it does not assert or guarantee compliance with any particular regulation or produce a certification outcome.
A virtual or fractional CISO who references SP 800-39 assumes accountability for the organization's risk decisions.
A vCISO or fractional CISO typically advises on and helps operationalize a risk management approach informed by SP 800-39, but legal and organizational accountability for accepting, transferring, or mitigating risk generally remains with the client organization and its officers unless a contract specifies otherwise.

Best practices

Use the three-tiered model (organization, mission/business process, information system) to ensure executive risk decisions are explicitly connected to operational systems, rather than treating risk as a purely technical concern.
Begin engagements by helping the organization frame risk, documenting assumptions, constraints, priorities, and risk tolerance, so subsequent risk responses align with business context.
Treat the framing, assessing, responding, and monitoring components as a continuous, iterative cycle rather than a one-time project deliverable.
Clarify in the engagement scope that applying SP 800-39 guidance supports risk management maturity and readiness but does not by itself deliver compliance or certification.
Coordinate SP 800-39's organizational risk guidance with complementary NIST publications for risk assessment and control selection, since SP 800-39 provides context rather than specific control detail.
Confirm that accountability for accepting or mitigating risk remains defined within the client organization, documenting the advisory boundary of any virtual or fractional CISO role.