Risk Framing
Risk framing is the foundational step in managing risk where an organization defines the assumptions, constraints, risk tolerances, and priorities that will guide how it handles risk. It sets the ground rules and shared understanding before any specific risks are assessed or addressed. In practice, it is most effective when done at the organizational level with input from stakeholders across the business.
Per NIST, risk framing is the set of assumptions, constraints, risk tolerances, and priorities/trade-offs that shape an organization's approach for managing risk. It establishes the risk management context and produces a risk management strategy that governs subsequent risk assessment, response, and monitoring activities. NIST guidance (SP 800-53 PM-28) indicates risk framing is most effective when conducted at the organization level and in consultation with stakeholders throughout the organization, including mission and business owners. Note that the security-management sense of risk framing described here is distinct from the behavioral 'framing effect,' which concerns how the presentation or wording of information influences choices and perceptions.
Why it matters
Risk framing is the step that gives every subsequent risk activity its meaning. Without a shared set of assumptions, constraints, risk tolerances, and priorities, an organization's risk assessments become inconsistent, its risk responses become arbitrary, and its monitoring lacks a benchmark against which to judge whether risk is being kept within acceptable bounds. Framing establishes the ground rules and common understanding before specific risks are identified and evaluated, which is why NIST positions it as foundational to managing risk.
The value of risk framing depends heavily on organizational context and stakeholder cooperation. NIST guidance indicates that framing is most effective when conducted at the organization level and in consultation with stakeholders throughout the organization, including mission and business owners. When framing is done in a silo, or treated as a purely technical exercise, the resulting risk management strategy often fails to reflect actual business priorities and trade-offs, leaving security decisions disconnected from the organization's mission and appetite for risk.
It is worth noting that the security-management sense of risk framing is distinct from the behavioral framing effect, which concerns how the presentation or wording of information influences choices and perceptions. Conflating the two can lead to confusion; in the risk management context, framing refers to setting the strategic context for managing risk, not to how information is presented to influence a decision.
Who it's relevant to
Inside Risk Framing
Common questions
Answers to the questions practitioners most commonly ask about Risk Framing.