Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Free Cyber Services#protect2024Secure Our WorldShields UpReport A Cyber Issue

CISA logo image. America's Cyber Defense Agency, National Coordinator for Critical Infrastructure Security and Resilience
CISA Logo

Search

 

America's Cyber Defense Agency
 
  • Topics
    Cybersecurity Best Practices
    Cyber Threats and Advisories
    Critical Infrastructure Security and Resilience
    Election Security
    Emergency Communications
    Industrial Control Systems
    Information and Communications Technology Supply Chain Security
    Partnerships and Collaboration
    Physical Security
    Risk Management
    How can we help?
    GovernmentEducational InstitutionsIndustryState, Local, Tribal, and TerritorialIndividuals and FamiliesSmall and Medium BusinessesFind Help LocallyFaith-Based CommunityExecutivesHigh-Risk Communities
  • Spotlight
  • Resources & Tools
    All Resources & Tools
    Services
    Programs
    Resources
    Training
    Groups
  • News & Events
    News
    Events
    Cybersecurity Alerts & Advisories
    Directives
    Request a CISA Speaker
    Congressional Testimony
    CISA Conferences
    CISA Live!
  • Careers
    Benefits & Perks
    HireVue Applicant Reasonable Accommodations Process
    Hiring
    Resume & Application Tips
    Students & Recent Graduates
    Veteran and Military Spouses
    Work @ CISA
  • About
    Culture
    Divisions & Offices
    Regions
    Leadership
    Doing Business with CISA
    Site Links
    Reporting Employee and Contractor Misconduct
    CISA GitHub
    CISA Central
    2023 Year In Review
    Contact Us
    Subscribe

Free Cyber Services#protect2024Secure Our WorldShields UpReport A Cyber Issue

Breadcrumb
  1. Home
  2. Topics
Share:
virtual graphic of shield with check mark

Risk Management

Leveraging sector and stakeholder expertise to reduce the most significant risks to the nation.

Risk Management

  • Connected Communities
  • Electromagnetic Pulse
  • National Critical Functions
  • Positioning, Navigation, and Timing
  • Secure Tomorrow Series
  • Space Systems

Overview

In today’s highly connected world, organizations all face more diverse, sophisticated threats—cyber, physical, technological, or natural—that have cross-sector impacts. The evolving risk landscape necessitates an evolved response. 

Risk Management is the process of identifying, analyzing, assessing, and communicating risk and accepting, avoiding, transferring, or mitigating it to an acceptable level considering associated costs and benefits of any actions taken. Effective risk management improves the quality of decision making. While risk cannot always be eliminated, actions can be taken to mitigate risk.

graphic of city skyline and connected network icons

National Risk Management Center

The National Risk Management Center - A critical infrastructure community empowered by actionable risk analysis.

NRMC

CISA's Role

CISA’s National Risk Management Center (NRMC) works with government and industry to identify, analyze, prioritize, and manage the most significant strategic risks to the nation’s 16 critical infrastructure sectors. Since the nation’s critical infrastructure is largely owned and operated by the private sector, managing risk is shared priority. The NRMC facilitates collaboration, coordination and analysis across the private sector, government agencies, and key stakeholders to ensure critical infrastructure is secure and resilient now and in the future.

Featured Content

Secure Tomorrow Series Toolkit

The Toolkit provides a powerful means of increasing risk awareness, identifying risk mitigation solutions, and encouraging systems-level thinking and long-term planning.

National Critical Functions

Functions of government and the private sector so vital to the U.S. that their disruption, corruption, or dysfunction would have a debilitating effect on security, national economic security, national public health or safety, or any combination the

ICT Supply Chain Risk Management Task Force

A public-private partnership charged to identify and develop consensus risk management strategies to enhance global ICT supply chain security

Space Systems Initiative

CISA works with public and private sector partners to advance space system security and resilience by identifying and assessing risks and expanding industry and international partnerships to ensure the responsible use of space.

Related News

Discover the latest CISA news on risk management. 

CISA Releases New Resource to Help Small and Medium-Sized Businesses Develop Supply Chain Resilience Plans

The guide provides Information and Communications Technology (ICT) SMBs with a starting point develop and tailor a supply chain risk management (SCRM) plan that meets the needs of their business.

CISA Releases Hardware Bill of Materials Framework (HBOM) for Supply Chain Risk Management (SCRM)

The product provides a framework that includes a consistent naming methodology, a format for identifying and providing information about components types, and other guidance. 

Best Practices for Securing Election Systems

Organizations can implement these best practices, which harden enterprise networks and strengthen election infrastructure, at little or no cost.

Risk Management Resources

View all publications

Securing Small and Medium-Sized Business (SMB) Supply Chains: A Resource Handbook to Reduce Information and Communication Technology Risks

JAN 26, 2023 | PUBLICATION
This handbook provides an overview of the highest supply chain risk categories commonly faced by ICT small and medium-sized businesses (SMBs), including cyber risks, and resources that can assist SMBs.
View Files

Suite of Tools for the Analysis of Risk (STAR) Fact Sheet

JAN 05, 2024 | PUBLICATION
This fact sheet describes the Suite of Tools for the Analysis of Risk (STAR), an innovative engine for forward-looking, functional risk assessment of critical infrastructure (CI) at the national scale.
Download File (PDF, 393.94 KB)

Connected Communities Procurement and Implementation Guidance

DEC 01, 2023 | PUBLICATION
These Connected Communities Procurement and Implementation Guidance infographics assist state, local, tribal, and territorial (SLTT) government officials in mitigating risks in their supply chains when procuring smart and connected technologies.
View Files

Cyber Threats to Medical Technology and Communication Technology Protocols

FEB 23, 2024 | PUBLICATION
The Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) developed this infographic to show examples of cyber threats related to the expansion of the interoperable IT/OT environment in healthcare and the potential consequences.
Download File (PDF, 324.17 KB)
View all publications

Contact Us

For questions or comments, email NRMC@hq.dhs.gov.

Return to top
  • Topics
  • Spotlight
  • Resources & Tools
  • News & Events
  • Careers
  • About
Cybersecurity & Infrastructure Security Agency
  • Facebook
  • Twitter
  • LinkedIn
  • YouTube
  • Instagram
  • RSS
CISA Central 1-844-Say-CISA SayCISA@cisa.dhs.gov
DHS Seal
CISA.gov
An official website of the U.S. Department of Homeland Security
  • About CISA
  • Budget and Performance
  • DHS.gov
  • Equal Opportunity & Accessibility
  • FOIA Requests
  • No FEAR Act
  • Office of Inspector General
  • Privacy Policy
  • Subscribe
  • The White House
  • USA.gov
  • Website Feedback