“NIST and Risk Governance and Risk Management” Please respond to the following:
- NIST provides many procedures and much guidance on IT and information security-related topics.
- Assess if NIST is too large and attempts to cover too many topics. Decide if NIST should separate into different entities for different major areas, such as IT governance, risk management, information security, and others.
- Assess if the various NIST documents covering risk management topics and concepts are too spread out and should be more consolidated to provide better guidance to organizations when they are establishing risk management programs.