PM-9: Risk Management Strategy

PM-09 requires your organization to build, implement, and maintain a unified strategy for managing both security and privacy risk across

Quick-reference card

FieldValue
Control IDPM-09
Control NameRisk Management Strategy
FrameworkNIST SP 800-53 Revision 5
Control FamilyProgram Management
BaselinesPRIVACY
RelevanceOrganization (First Party)
Risk SeverityMedium

What this control requires

PM-09 requires your organization to build, implement, and maintain a unified strategy for managing both security and privacy risk across every system and process you operate. This isn’t a single document exercise. It demands an articulated expression of risk tolerance, defined mitigation approaches, accepted assessment methodologies, and a mechanism for evaluating risk organization-wide against that tolerance.

In practice, this means the strategy must cover security risk to operations, assets, individuals, and other organizations, alongside privacy risk to individuals from the authorized processing of personally identifiable information (PII). These two dimensions often fall under different teams, but PM-09 treats them as parts of a single coherent program that your senior leadership owns.

The strategy also can’t sit static on a shelf. Your organization must apply it consistently across every business unit and review it on a defined cadence or whenever organizational changes demand an update. A risk management strategy that doesn’t evolve with your operating environment, threat landscape, and regulatory obligations quickly becomes a liability rather than a safeguard.

Why it matters

Most organizations treat risk management as a collection of disconnected assessments rather than a unified strategic function. PM-09 exists because fragmented approaches create blind spots, where security risk is evaluated by one team using one methodology while privacy risk is handled separately with different assumptions, different tolerances, and different reporting lines. The result is an organization that can’t accurately compare risks across domains or allocate resources where they matter most.

Failure to maintain this control introduces audit risk and may result in certification withdrawal or regulatory findings. Without a documented, consistently applied risk management framework, assessors have no basis to confirm that your organization understands its own risk posture. This gap is particularly visible in privacy-overlay audits where the absence of a unified strategy signals systemic governance weakness.

Where this breaks down further is at the operational level. When risk tolerance isn’t explicitly defined and communicated, individual teams make ad hoc risk acceptance decisions that conflict with organizational priorities. A development team might accept a vulnerability that a compliance team would flag as intolerable, and neither has a shared reference point to resolve the disagreement.

The risk isn’t limited to internal inconsistency. Regulators and auditors look for evidence that risk management decisions are traceable to a documented strategy. Without that traceability, your organization can’t demonstrate that it evaluated and accepted residual risk deliberately rather than through oversight.

What attackers exploit

  • Inconsistent risk assessment methodologies across business units, which create gaps where threats are underestimated or ignored entirely
  • Undefined risk tolerance thresholds that allow teams to accept risk without executive visibility or approval
  • Stale risk strategies that haven’t been updated to account for new threat vectors, acquisitions, or regulatory changes
  • Disconnected security and privacy risk programs that leave PII processing risks unaddressed by the security function
  • Lack of supply chain risk integration where third-party dependencies aren’t evaluated against the same risk framework applied to internal systems

How to implement

For your organization

The core implementation challenge with PM-09 is moving from a theoretical acknowledgment that risk management matters to a documented, consistently enforced strategy that leadership actually uses for decision-making. Many organizations stall at the documentation phase, producing a strategy document that satisfies an audit checkbox but doesn’t influence how risk decisions get made day-to-day.

Step 1: Define organizational risk tolerance. Establish explicit thresholds for acceptable security and privacy risk. These thresholds should be quantifiable where possible and approved by senior leadership. Document what level of residual risk the organization will accept, under what conditions, and who has authority to make risk acceptance decisions.

Step 2: Select and document risk assessment methodologies. Choose a consistent methodology for evaluating both security and privacy risk. NIST SP 800-30 is a common choice for security risk assessments, and privacy impact assessments (PIAs) address the privacy dimension. Document why you selected these methodologies and how they map to your risk tolerance framework.

Step 3: Assign senior accountability. Designate a risk executive function, typically a senior accountable official, who ensures the strategy aligns with strategic, operational, and budgetary planning processes. This role bridges the gap between security operations and executive decision-making.

Step 4: Implement consistent application mechanisms. Develop procedures that require every business unit and system owner to evaluate risk using the approved methodologies and against the defined tolerance thresholds. Standardized risk registers, scoring rubrics, and reporting templates help enforce consistency.

Step 5: Integrate cybersecurity risk management with privacy risk. Ensure security and privacy risk aren’t evaluated in silos. The strategy should define how PII processing risks are identified, assessed, and reported alongside traditional security risks.

Step 6: Establish a review and update cadence. Define a frequency for reviewing and updating the strategy. Tie updates to organizational triggers such as mergers, new regulatory requirements, significant incidents, or changes to the threat landscape.

Step 7: Produce and maintain evidence. Generate the artifacts assessors expect, including the risk management strategy document itself, supporting procedures, risk assessment results, and records showing that the strategy was reviewed and updated on schedule.

Common mistakes to avoid:

  • Writing a strategy document that restates NIST language without translating it into organization-specific risk tolerance and procedures
  • Failing to address privacy risk alongside security risk in a single integrated strategy
  • Assigning risk management responsibility without providing the authority or budget to enforce it
  • Treating the strategy review as a calendar task rather than linking it to real organizational changes

Evidence examples

Evidence TypeExample Artifact
Risk management strategyDocumented strategy defining organizational risk tolerance levels, accepted assessment methodologies, mitigation approaches, and monitoring procedures
Security and privacy program plansInformation security program plan and privacy program plan that reference and align with the risk management strategy
Risk assessment resultsCompleted risk assessments demonstrating application of the strategy’s approved methodology across organizational systems
Procedures for strategy lifecycleProcedures covering development, implementation, review, and update of the risk management strategy with defined roles and triggers
Supply chain risk management strategyDocumented approach for evaluating third-party and supply chain risk consistent with the overall risk management strategy (per PM family requirements)
Strategy review recordsRecords showing the risk management strategy was reviewed and updated at the defined frequency or in response to organizational changes

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20226.2 Terms and conditions of employmentPartial
  • AC-01 — Policy and Procedures: establishes the policy foundation that the risk management strategy informs and shapes across access control domains
  • AU-01 — Policy and Procedures: defines audit and accountability policies that must align with the risk tolerance thresholds set in the risk management strategy
  • AT-01 — Policy and Procedures: governs security awareness and training policies, which the risk management strategy should identify as a risk mitigation mechanism
  • CA-01 — Policy and Procedures: sets the policy framework for control assessments that evaluate whether the risk management strategy is effectively implemented
  • CA-02 — Control Assessments: provides the assessment process used to verify that the risk management strategy is applied consistently across systems
  • CA-05 — Plan of Action and Milestones: tracks remediation of weaknesses identified through risk assessments conducted under the risk management strategy
  • CA-06 — Authorization: ties system authorization decisions to the risk tolerance levels defined in the risk management strategy
  • CA-07 — Continuous Monitoring: provides the ongoing risk monitoring capability that the risk management strategy requires to remain current
  • CM-01 — Policy and Procedures: defines configuration management policies that must reflect the risk priorities established in the strategy
  • CP-01 — Policy and Procedures: establishes contingency planning policies informed by the risk scenarios and priorities identified in the risk management strategy

Frequently asked questions

What is NIST SP 800-53 PM-09

PM-09 requires organizations to develop, implement, and regularly update a comprehensive risk management strategy that covers both security risk to operations and assets and privacy risk from PII processing. The strategy must define organizational risk tolerance, approved assessment methodologies, and mitigation approaches. It requires a designated senior accountable official to ensure the strategy aligns with budgetary and operational planning. Unlike individual control assessments, PM-09 governs how your organization thinks about and evaluates risk at the program level.

What happens if PM-09 is not implemented

Without PM-09 implementation, your organization lacks a documented basis for risk acceptance decisions, which auditors will flag as a systemic governance gap. Individual teams will apply inconsistent risk assessment methodologies, making it impossible to compare or prioritize risks across the organization. Privacy risk from authorized PII processing may go entirely unaddressed by the security program. Regulatory bodies and certification auditors treat the absence of a unified risk management strategy as evidence that risk decisions are ad hoc rather than deliberate.

How do you audit PM-09

Auditing PM-09 starts with verifying that a documented risk management strategy exists and includes defined risk tolerance thresholds, approved risk assessment methodologies, and procedures for consistent application across the organization. Assessors review risk assessment results to confirm the approved methodology was actually used and check whether the strategy addresses both security risk and privacy risk from PII processing. They examine review and update records to verify the strategy was refreshed at the defined frequency or in response to organizational changes. Evidence of the risk executive function’s role in aligning the strategy with budgetary and strategic planning is also evaluated.

What should a risk management strategy include

A risk management strategy should include an explicit statement of organizational risk tolerance, defined risk mitigation approaches, approved risk assessment methodologies, and a process for evaluating risk across the organization against those tolerance thresholds. It should also address how security and privacy risk are integrated rather than managed separately, and how supply chain risk (as described in PM-30) feeds into the broader strategy. The strategy must define a monitoring approach for tracking risk over time and identify the senior accountable official responsible for aligning risk management with strategic and budgetary planning.

Experience superior visibility and a simpler approach to cyber risk management