The NIST Cybersecurity Framework tells you what good security looks like. It does not tell you how to work out which risks matter most for your organisation. That is the job of NIST SP 800-30 — the guide to conducting information security risk assessments. This article walks through the method, the four steps, and the mistakes that make assessments unusable.
For the wider control framework this feeds into, see our NIST Cybersecurity Framework guide. The source document itself is freely available as NIST Special Publication 800-30 Revision 1.
What NIST SP 800-30 is — and is not
SP 800-30 is a methodology, not a control catalogue and not a certification. It was written for US federal agencies but is used far more widely, because it answers a question every security programme faces: given limited budget, which risks do we treat first?
It sits alongside its siblings. SP 800-37 defines the overall Risk Management Framework lifecycle, SP 800-53 supplies the controls, and 800-30 is the assessment engine in the middle.
The four steps
| Step | What it produces |
|---|---|
| 1. Prepare | Scope, assumptions, risk model and the rating scales you will use |
| 2. Conduct | Identified threat sources and events, vulnerabilities, likelihood, impact and resulting risk |
| 3. Communicate | A risk assessment report decision-makers can actually act on |
| 4. Maintain | Ongoing monitoring so the assessment does not go stale |
Step one is the step teams skip, and skipping it is why assessments end in argument. If you have not agreed what “high likelihood” means before you start scoring, every rating becomes a negotiation.
How the risk is actually calculated
SP 800-30 builds risk from a chain, not a single guess:
- Threat source — who or what initiates it (an adversary, an error, a failure, a natural event).
- Threat event — what they do.
- Vulnerability — the weakness that lets it succeed.
- Likelihood — split into likelihood of initiation and likelihood of impact if initiated.
- Impact — the harm to operations, assets, individuals or the wider mission.
Splitting likelihood in two is the part people miss. A highly capable adversary who has no reason to target you and an unmotivated one who could walk straight in are very different risks, and a single likelihood score hides that difference.
Turning the assessment into decisions
An assessment that ends in a spreadsheet has failed. The output should be a report naming the risks, the treatment chosen for each — mitigate, transfer, avoid or accept — the owner, and the date it will be reviewed. Accepted risks need a named accepter; risks accepted by nobody in particular tend to be accepted by the security team without anyone noticing.
If you are documenting this from scratch, our NIST Cyber Risk Management Toolkit covers the full cycle: an 800-30 risk assessment template and worked guide, a risk management framework, risk assessment report and treatment plan, a CSF 2.0 maturity assessment, a business impact analysis tool, and the supporting policy set the treatments reference.
Four mistakes that make assessments useless
- Assessing assets instead of risks. A list of servers with red and amber labels is an inventory, not an assessment.
- Scales with no definitions. If “medium impact” is undefined, scores drift by whoever is in the room.
- No reassessment trigger. Annual review is the minimum; material change should force one sooner.
- Treating the register as the deliverable. The deliverable is the set of decisions the register supports.
Where the NIST SP 800-30 risk assessment fits
A NIST SP 800-30 risk assessment is rarely run for its own sake. It feeds the authorisation decision in the wider Risk Management Framework, it justifies which controls from SP 800-53 you select, and it gives the risk committee something defensible to sign.
That is also the practical argument for keeping the assessment method stable between cycles. If the scales move each year, this year’s ratings cannot be compared with last year’s, and the trend — usually the most useful output — is lost.
Frequently asked questions
What is the difference between NIST SP 800-30 and SP 800-37?
SP 800-30 is the method for assessing risk. SP 800-37 defines the broader Risk Management Framework lifecycle — categorise, select, implement, assess, authorise and monitor — within which the 800-30 assessment sits.
Can you use NIST SP 800-30 alongside ISO 27001?
Yes. ISO 27001 requires a risk assessment process but does not prescribe one, so 800-30 is a legitimate choice of method. Our ISO 27001 risk assessment guide covers what the standard expects.
How often should a NIST 800-30 risk assessment be repeated?
At least annually, and whenever something material changes — a new system, a significant incident, a merger, or a shift in the threat landscape. The maintain step exists precisely so the assessment does not become a once-a-year document.