DigiTrustAsia
Risk Management

ISO 31000 and NIST RMF: Mapping Two Risk Frameworks That Solve Different Problems

One is a management philosophy, the other an engineering process. Map them correctly and they reinforce each other; confuse them and your risk program speaks two languages at once.

Risk practitioners are routinely asked to "align with ISO 31000 and NIST" as though the two were interchangeable standards competing for the same job. They are not. ISO 31000 is a management philosophy — principles and a framework for any risk, in any organisation. The NIST Risk Management Framework (RMF) is an engineering process — a seven-step lifecycle for authorising and operating information systems. Once you see that difference, mapping them becomes straightforward, and using both stops feeling like duplication.

Two frameworks, two altitudes

ISO 31000 operates at the altitude of the enterprise. It defines risk as the effect of uncertainty on objectives — note: objectives, not systems — and offers principles (integrated, structured, customised, inclusive, dynamic), a framework built around leadership and commitment, and a process: scope and context, risk assessment (identification, analysis, evaluation), risk treatment, with communication, monitoring and recording wrapped around everything. It is deliberately non-certifiable and deliberately generic: the same document serves a hospital's clinical risk and a bank's credit risk.

NIST RMF operates at the altitude of the system. Born in US federal government practice (NIST SP 800-37) and built to work with the SP 800-53 control catalog, it walks a specific information system through seven steps — Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor — ending in an explicit, named-official decision to accept residual risk and authorise operation.

ISO 31000 tells the organisation how to think about risk. NIST RMF tells a system owner what to do on Tuesday.

The mapping that actually holds

ISO 31000 elementNIST RMF counterpartNotes
Leadership & commitment; frameworkPrepare (organisation level)RMF's Prepare step imported exactly this enterprise grounding
Scope, context, criteriaPrepare (system level) + CategorizeImpact categorisation is context-setting made formal
Risk identification & analysisCategorize + AssessRMF distributes assessment across steps rather than one phase
Risk evaluationAuthorizeThe authorising official's decision is evaluation against criteria
Risk treatmentSelect + ImplementControl selection and implementation are treatment, pre-catalogued
Monitoring & reviewMonitorContinuous monitoring is the RMF's strongest ISO echo
Communication & consultationWoven through all stepsRMF embeds it in roles, plans and authorisation packages

Two mapping mistakes to avoid. First, equating ISO's "risk treatment" only with RMF's Implement — selection of controls is itself a treatment decision, which is why both Select and Implement sit in that row. Second, treating Authorize as bureaucracy: it is the purest expression of ISO-style risk evaluation in any framework, because a named human compares residual risk to acceptance criteria and signs.

Using both without duplication

In a well-built program the division of labour is clean. ISO 31000 shapes the enterprise layer: risk appetite, governance structures, a common vocabulary that lets cyber risk sit in the same register as financial and operational risk. RMF (or an RMF-like lifecycle) runs the system layer: each significant system categorised, controlled, assessed and explicitly authorised, feeding its residual-risk picture upward into the enterprise view.

The interface between the layers is the part most organisations fumble: system-level residual risk must be expressed in the enterprise's ISO-style criteria, or the board receives engineering detail it cannot evaluate. A one-page translation — system, business objective at stake, residual risk against appetite, authorisation status — is usually all it takes.

Exam angles

Hold the altitude distinction and every alignment question — on the exam or in your steering committee — resolves the same way: philosophy above, process below, and a deliberate translation layer between them.

Put it into practice.

700+ exam-weighted questions, every one with a rationale. Your first practice exam is free.

Start free