# Risk Assessments Frameworks

* [NIST Risk Mangement Framework (RMF)](https://csrc.nist.gov/Projects/risk-management)
  * A structured and systematic process developed by the National Institute of Standards and Technology (NIST) for managing and mitigating cybersecurity risks in federal information systems
  * [NIST SP 800-37 Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy](https://csrc.nist.gov/pubs/sp/800/37/r2/final)
  * [NIST SP 800-39 Managing Information Security Risk](https://www.nist.gov/privacy-framework/nist-sp-800-39)
  * [NIST SP 800-30 Rev. 1 Guide for Conducting Risk Assessments](https://csrc.nist.gov/pubs/sp/800/30/r1/final)
  * [NIST IR 8286A Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management](https://csrc.nist.gov/pubs/ir/8286/a/final)
* [COSO Enterprise Risk Management (ERM) Framework](https://www.coso.org/erm-framework)
  * A framework that provides a structured approach for organizations to identify, assess, manage, and monitor risks to achieve their objectives. COSO ERM emphasizes integrating risk management into an organization's strategic and operational processes.
* [FAIR](https://www.fairinstitute.org)
  * A quantitative risk management framework developed by the Open Group. FAIR provides a structured methodology for organizations to analyze and quantify information security and operational risks.
* [ISO 31000 Risk Management](https://www.iso.org/iso-31000-risk-management.html)
  * An international standard for risk management that provides principles, framework, and guidelines for organizations to develop and implement effective risk management strategies.
  * [ISO 31000:2018 Risk Management Guidelines](https://www.iso.org/standard/65694.html)
  * [IEC 31010:2019 Risk Assessment Techniques](https://www.iso.org/standard/72140.html)
* [OCTAVE](https://insights.sei.cmu.edu/library/introducing-octave-allegro-improving-the-information-security-risk-assessment-process/)
  * A risk assessment methodology developed by the Software Engineering Institute (SEI) at Carnegie Mellon University. It is designed to help organizations identify and mitigate information security risks by focusing on critical assets and operational processes
* [Mozilla Rapid Risk Assessment](https://infosec.mozilla.org/guidelines/risk/rapid_risk_assessment.html)
  * A quick (30-60min) assessment to understand the value and impact of a service to the reputation, finances, productivity of the project or business. It is based on the data processed, stored or simply accessible by services.
* [OWASP Risk Rating Methodology](https://owasp.org/www-community/OWASP_Risk_Rating_Methodology)
  * A framework used for assessing and prioritizing security risks in software applications. The methodology considers factors such as the ease of exploitation, potential damage, affected users, and the overall risk environment to provide a comprehensive view of security risks in software applications.
