Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NIST SP 800-30 risk assessment methodology and its three tiers

NIST SP 800-30: The Three Tiers of Risk Assessment

NIST SP 800-30 is the risk assessment methodology that most organisations quote and few actually run as written — because it asks for something harder than a spreadsheet of system vulnerabilities.

It asks you to assess risk at three levels of the organisation, and to produce something a senior executive can act on. Skip either and you get a register nobody reads.

What NIST SP 800-30 is

Guide for Conducting Risk Assessments, Revision 1, was published in September 2012 by the Joint Task Force Transformation Initiative, superseding the 2002 original.

Fourteen years on it has not been revised, and that is worth reading correctly. This is not a neglected document — it is a stable one. The methodology it describes has not needed reworking, which is more than can be said for most risk guidance of the same vintage.

Its stated purpose is precise: to provide guidance for conducting risk assessments, amplifying the guidance in SP 800-39. That relationship matters. SP 800-39 describes managing information security risk across an organisation; SP 800-30 is the assessment component within it. Reading 800-30 alone gives you a method without the frame it was designed to sit in.

The three tiers of NIST SP 800-30

The three tiers of the NIST SP 800-30 risk management hierarchy

The single most important line in the publication is that risk assessments are carried out at all three tiers in the risk management hierarchy, as part of an overall risk management process, to give senior leaders and executives the information they need to determine appropriate courses of action.

Almost every failed risk programme fails at this point, and it is the clearest sign a team has read NIST SP 800-30 without running it. The assessment happens at Tier 3 — this system, these vulnerabilities, this patch level — and the output is a technical list. It is accurate, it is diligent, and it cannot answer a question a board actually asks, because board questions live at Tier 1.

Running the assessment at Tier 1 and Tier 2 as well is what turns a vulnerability list into a decision-support document. It is also the part that requires talking to people outside the security team.

The NIST SP 800-30 four-step process

The NIST SP 800-30 method itself is deliberately simple, and the value is in the discipline rather than the complexity:

  1. Prepare — establish the purpose, scope, assumptions, constraints, information sources and the risk model and analytic approach you will use. Doing this explicitly is what makes assessments comparable to each other later.
  2. Conduct — identify threat sources and threat events, identify vulnerabilities and predisposing conditions, determine likelihood and impact, and determine risk.
  3. Communicate — share the results with the people who make decisions, in terms they use.
  4. Maintain — keep the assessment current as the environment changes.

Two of the four are routinely skipped. Prepare gets skipped because it feels like paperwork before the real work, and its absence is why two assessments in the same organisation cannot be compared. Maintain gets skipped because nothing forces it, and an assessment that is eighteen months stale describes a system that no longer exists.

Threat sources, threat events and predisposing conditions

NIST SP 800-30 separates concepts that most risk registers merge, and the separation is the analytical value.

A threat source is who or what initiates — an adversary with capability and intent, but also human error, a structural failure or a natural event. A threat event is what happens. A vulnerability is the weakness exploited. A predisposing condition is a property of the organisation that makes an event more likely to have an adverse effect, regardless of any specific weakness.

Keeping those apart lets you see that one predisposing condition — a flat network, a single supplier, an unclear ownership model — sits underneath a dozen apparently unrelated risks. Merging them into a single “risk” line loses that entirely.

How NIST SP 800-30 relates to other frameworks

Framework Relationship
NIST CSF CSF tells you which outcomes to pursue; SP 800-30 tells you how to work out which ones matter most here. They are commonly run together
SP 800-53 The control catalog you select from once the assessment has told you what you are treating
ISO 31000 The international general risk management standard. ISO 31000 is broader and sector-neutral; SP 800-30 is deeper and specific to information security risk. If you run both, use ISO 31000 for criteria and governance and 800-30 for the assessment method
ISO 27001 Clause 6.1.2 requires a risk assessment process without mandating one. SP 800-30 is a defensible answer, particularly for organisations with a US federal footprint

Where to start with NIST SP 800-30

  1. Write the Prepare step down. Purpose, scope, assumptions, constraints, risk model, analytic approach. One page, before any analysis.
  2. Assess at Tier 2 at least once. If you have only ever done Tier 3, this is where the surprises are.
  3. Separate threat sources from events, vulnerabilities and predisposing conditions in the register structure, not just in the narrative.
  4. Write the output for the reader — senior leaders determining courses of action, per the standard’s own framing.
  5. Set a maintenance trigger, not just an annual date, so material change forces a refresh.
  6. Read SP 800-39 alongside it, because 800-30 was written to amplify it.

This guide reflects csrc.nist.gov at 15 August 2026, on which SP 800-30 Rev. 1 remains the current revision.

The NIST Cyber Risk Management Toolkit provides 50+ editable files covering the risk assessment methodology, the threat and vulnerability catalogues, the risk register and treatment records, and the reporting artefacts that carry results to the people who decide.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.