Multi-Tiered Risk Management
Multi-tiered risk management is an approach that addresses risk at several distinct organizational levels rather than treating it as a single, uniform problem. In the model defined by NIST, this typically means considering risk at the overall organization level, at the level of the missions or business processes an organization performs, and at the level of individual information systems. The intent is to ensure that risk decisions made at one level inform and align with the others.
Multi-tiered risk management, as articulated in NIST SP 800-39, structures risk management into three levels: Tier 1 (organization level), Tier 2 (mission/business process level), and Tier 3 (information system level). Tier 1 establishes organization-wide risk context, governance, and risk tolerance; Tier 2 enumerates, defines, and prioritizes the mission and business processes needed to fulfill the organization's mission and translates that context into process-level requirements; Tier 3 addresses risk at the individual system level. The tiers are intended to be interconnected so that risk-related information flows between levels and decisions remain aligned. As presented in the source evidence, this model is oriented toward information security and cybersecurity risk within an organization's own environment; it is not, in this formulation, a third-party or supply chain risk framework, and the evidence does not establish how (or whether) it extends across multiple supplier tiers or Nth-party relationships. Related frameworks (for example, the broader Risk Management Framework) reference similar multi-tiered concepts, but the specific three-tier structure described here derives from NIST SP 800-39.
Why it matters
Organizations frequently treat risk as a single, undifferentiated problem, addressing it primarily at the system level while leaving governance, risk tolerance, and mission priorities implicit or disconnected from technical decisions. Multi-tiered risk management, as articulated in NIST SP 800-39, counters this by explicitly separating organizational, mission/business process, and information system concerns so that a technically sound decision at the system level does not conflict with the organization's stated risk tolerance, and so that mission priorities actually shape the controls applied to individual systems.
Who it's relevant to
Inside Multi-Tiered Risk Management
Common questions
Answers to the questions practitioners most commonly ask about Multi-Tiered Risk Management.
