{
  "$TMF_VERSION": "1.4",
  "PublicationDateTime": "2021-04-26T00:00:00.000Z",
  "Description": "Profile of requirements corresponding to NIST Special Publication 800-53, r4, Security Control PM-9: Risk Management Strategy.",
  "Keywords": [
    "800-53",
    "NIST",
    "Program Management",
    "Risk Management Strategy",
    "Security"
  ],
  "Issuer": {
    "Identifier": "https://trustmarkinitiative.org/",
    "PrimaryContact": {
      "Email": "help@trustmarkinitiative.org",
      "Telephone": "555-555-5555",
      "Kind": "PRIMARY",
      "WebsiteURL": "https://trustmarkinitiative.org/",
      "Responder": ""
    },
    "Name": "TMI"
  },
  "Sources": [{
    "Identifier": "SP800-53R4",
    "Reference": "NIST Special Publication 800-53 Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, National Institute of Standards and Technology, April 2013 (Includes updates as of 01-15-2014). Available at <a href=\"http://dx.doi.org/10.6028/NIST.SP.800-53r4\">http://dx.doi.org/10.6028/NIST.SP.800-53r4<\/a>.",
    "$id": "source-2112165102"
  }],
  "Name": "NIST SP 800-53 r4 Security Control PM-9: Risk Management Strategy",
  "TrustExpression": "TD_ref1 and TD_ref2 and TD_ref3 and TD_ref4 and TD_ref5 and TD_ref6 and TD_ref7 and TD_ref8",
  "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tips/nist-sp-800-53-r4-security-control-pm-9_-risk-management-strategy/4/",
  "Version": "4",
  "References": {"TrustmarkDefinitionRequirements": [
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/risk-management-strategy---periodic-update/1.0/",
      "Description": "Defines conformance and assessment criteria for verifying that an organization reviews and updates the risk management strategy at an organization-defined frequency to address organizational changes.",
      "Number": 1,
      "Version": "1.0",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/risk-management-strategy---periodic-update/1.0/",
        "Description": "Defines conformance and assessment criteria for verifying that an organization reviews and updates the risk management strategy at an organization-defined frequency to address organizational changes.",
        "Number": 1,
        "Version": "1.0",
        "Name": "Risk Management Strategy - Periodic Update"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Risk Management Strategy - Periodic Update",
      "$id": "TD_ref1"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/risk-management-strategy---the-nation/1.0/",
      "Description": "Defines conformance and assessment criteria for verifying that an organization develops a comprehensive strategy to manage risk to the Nation associated with the operation and use of information systems.",
      "Number": 2,
      "Version": "1.0",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/risk-management-strategy---the-nation/1.0/",
        "Description": "Defines conformance and assessment criteria for verifying that an organization develops a comprehensive strategy to manage risk to the Nation associated with the operation and use of information systems.",
        "Number": 2,
        "Version": "1.0",
        "Name": "Risk Management Strategy - The Nation"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Risk Management Strategy - The Nation",
      "$id": "TD_ref2"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/risk-management-strategy---organizational-operations/1.0/",
      "Description": "Defines conformance and assessment criteria for verifying that an organization develops a comprehensive strategy to manage risk to organizational operations associated with the operation and use of information systems.",
      "Number": 3,
      "Version": "1.0",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/risk-management-strategy---organizational-operations/1.0/",
        "Description": "Defines conformance and assessment criteria for verifying that an organization develops a comprehensive strategy to manage risk to organizational operations associated with the operation and use of information systems.",
        "Number": 3,
        "Version": "1.0",
        "Name": "Risk Management Strategy - Organizational Operations"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Risk Management Strategy - Organizational Operations",
      "$id": "TD_ref3"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/risk-management-strategy---other-organizations/1.0/",
      "Description": "Defines conformance and assessment criteria for verifying that an organization develops a comprehensive strategy to manage risk to other organizations associated with the operation and use of information systems.",
      "Number": 4,
      "Version": "1.0",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/risk-management-strategy---other-organizations/1.0/",
        "Description": "Defines conformance and assessment criteria for verifying that an organization develops a comprehensive strategy to manage risk to other organizations associated with the operation and use of information systems.",
        "Number": 4,
        "Version": "1.0",
        "Name": "Risk Management Strategy - Other Organizations"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Risk Management Strategy - Other Organizations",
      "$id": "TD_ref4"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/risk-management-strategy---implementation/1.0/",
      "Description": "Defines conformance and assessment criteria for verifying that an organization implements its risk management strategy consistently across the organization.",
      "Number": 5,
      "Version": "1.0",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/risk-management-strategy---implementation/1.0/",
        "Description": "Defines conformance and assessment criteria for verifying that an organization implements its risk management strategy consistently across the organization.",
        "Number": 5,
        "Version": "1.0",
        "Name": "Risk Management Strategy - Implementation"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Risk Management Strategy - Implementation",
      "$id": "TD_ref5"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/risk-management-strategy---individuals/1.0/",
      "Description": "Defines conformance and assessment criteria for verifying that an organization develops a comprehensive strategy to manage risk to individuals associated with the operation and use of information systems.",
      "Number": 6,
      "Version": "1.0",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/risk-management-strategy---individuals/1.0/",
        "Description": "Defines conformance and assessment criteria for verifying that an organization develops a comprehensive strategy to manage risk to individuals associated with the operation and use of information systems.",
        "Number": 6,
        "Version": "1.0",
        "Name": "Risk Management Strategy - Individuals"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Risk Management Strategy - Individuals",
      "$id": "TD_ref6"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/risk-management-strategy---updates-as-required/1.0/",
      "Description": "Defines conformance and assessment criteria for verifying that an organization reviews and updates the risk management strategy as required, to address organizational changes.",
      "Number": 7,
      "Version": "1.0",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/risk-management-strategy---updates-as-required/1.0/",
        "Description": "Defines conformance and assessment criteria for verifying that an organization reviews and updates the risk management strategy as required, to address organizational changes.",
        "Number": 7,
        "Version": "1.0",
        "Name": "Risk Management Strategy - Updates As Required"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Risk Management Strategy - Updates As Required",
      "$id": "TD_ref7"
    },
    {
      "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/risk-management-strategy---organizational-assets/1.0/",
      "Description": "Defines conformance and assessment criteria for verifying that an organization develops a comprehensive strategy to manage risk to organizational assets associated with the operation and use of information systems.",
      "Number": 8,
      "Version": "1.0",
      "TrustmarkDefinitionReference": {
        "Identifier": "https://artifacts.trustmarkinitiative.org/lib/tds/risk-management-strategy---organizational-assets/1.0/",
        "Description": "Defines conformance and assessment criteria for verifying that an organization develops a comprehensive strategy to manage risk to organizational assets associated with the operation and use of information systems.",
        "Number": 8,
        "Version": "1.0",
        "Name": "Risk Management Strategy - Organizational Assets"
      },
      "$Type": "TrustmarkDefinitionRequirement",
      "Name": "Risk Management Strategy - Organizational Assets",
      "$id": "TD_ref8"
    }
  ]},
  "Primary": "false",
  "LegalNotice": "This document and the information contained herein is provided on an \"AS IS\" basis, and the Georgia Tech Research Institute disclaims all warranties, express or implied, including but not limited to any warranty that the use of the information herein will not infringe any rights or any implied warranties or merchantability or fitness for a particular purpose. In addition, the Georgia Tech Research Institute disclaims legal liability for any loss incurred as a result of the use or reliance on the document or the information contained herein.",
  "$Type": "TrustInteroperabilityProfile"
}