This is the second installment in a series about the Committee of Sponsoring Organizations of the Treadway Commission’s updated enterprise risk management framework. Be sure to read part 1 for the full story.

This past September, the Committee of Sponsoring Organizations (COSO) of the Treadway Commission issued an updated enterprise risk management (ERM) framework, titled “Enterprise Risk Management — Integrating with Strategy and Performance,” to help business leaders understand the risks their organizations face and evaluate their impact on business performance.

While the COSO ERM guidance is designed to simplify risk management at an enterprise level, organizations can derive even more value from the framework by coupling it with the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF), which is geared more toward day-to-day, ground-level risk management.

Comparing the COSO ERM and NIST CSF: Apples to Oranges

The two frameworks come from different organizations with differing viewpoints and guiding principles. The NIST CSF is a business-friendly framework that is currently only mandatory for entities in the critical infrastructure space. While the CSF is focused on cybersecurity, it is a departure from prior NIST efforts in that it is meant to span a wide range of levels within an organization. The CSF can be used down in the security trenches, guiding everyday decisions and the implementation of particular policies and practices. It can also be used by the chief information security officer (CISO) to provide a framework of items on which to report to the C-suite and board directors.

The COSO ERM, on the other hand, has been a staple of enterprise-level risk management. It takes a holistic view of risk across the entire enterprise, but its primary audience is the top leadership and board directors who are tasked with the management of risks, including cyber risks. For the board, it addresses oversight of management’s activities and decisions, such as alignment of resources, to ensure that positive risks are given proper consideration while negative risks are within board-approved risk appetite.

Not every cybersecurity issue will turn into a cyber risk — a potential negative impact on business objectives — that needs to involve top leadership. With its primary focus on cybersecurity, the NIST CSF is more tactically and operationally focused, while the COSO ERM helps business leaders link strategy, risks and performance to deliver value.

One of the biggest goals of the ERM is to improve executives’ understanding of the impact of risk on performance. Given the number of data breaches, exposed cloud storage units, instances of ransomware and other adverse cyber-related events that shook global economies in 2017, applying the benefit of the ERM to the cyber risk domain should be a top issue for boards and the C-suite.

There has never been a better time to understand the linkage between cyber risks, business strategy and performance, and to ensure that at all levels of the organizations are making the best decisions possible — for both today’s world and tomorrow’s cyber earthquakes.

Applying NIST CSF Functions to the COSO Enterprise Risk Management Framework

The NIST CSF includes a table that maps the framework core to various other standards. However, since we’ve yet to see a CSF-to-ERM mapping, below is an initial sketch of the mappings between the two frameworks. Let’s reiterate the list of NIST CSF functions and categories, since we’ll mention those later next to the COSO ERM principles:

The chart below shows an initial mapping of which areas of the NIST CSF are connected to the COSO ERM principles. Not surprisingly, the table shows that the CSF is rather light in its ability to ensure strong governance and culture as well as strategy and objective components, two areas in which adopting the ERM can provide significant benefits.

Linking Strategy and Performance to Cyber Risks

The NIST CSF and the COSO ERM are indeed apples and oranges, but that’s exactly what is needed to help organizations improve not only how they handle their cybersecurity operations, but also how they link strategy and performance to cyber risks. After a year full of high-profile data breaches and unprecedented ransomware attacks, these frameworks couldn’t have come at a better time.

Listen to the podcast series: Take Back Control of Your Cybersecurity Now

More from CISO

Do You Really Need a CISO?

2 min read - Cybersecurity has never been more challenging or vital. Every organization needs strong leadership on cybersecurity policy, procurement and execution — such as a CISO, or chief information security officer. A CISO is a senior executive in charge of an organization’s information, cyber and technology security. CISOs need a complete understanding of cybersecurity as well as the business, the board, the C-suite and how to speak in the language of senior leadership. It’s a changing role in a changing world. But…

2 min read

What “Beginner” Skills do Security Leaders Need to Refresh?

4 min read - The chief information security officer (CISO) was once a highly technical role primarily focused on security. But now, the role is evolving. Modern security leaders must work across divisions to secure technology and help meet business objectives. To stay relevant, the CISO must have a broad range of skills to maintain adequate security and collaborate with teams of varying technical expertise. Learning is essential to simply keep pace in security. In a CISO Series podcast, Skillsoft CISO Okey Obudulu recently said,…

4 min read

The Needs of a Modernized SOC for Hybrid Cloud

5 min read - Cybersecurity has made a lot of progress over the last ten years. Improved standards (e.g., MITRE), threat intelligence, processes and technology have significantly helped improve visibility, automate information gathering (SOAR) and many manual tasks. Additionally, new analytics (UEBA/SIEM) and endpoint (EDR) technologies can detect and often stop entire classes of threats. Now we are seeing the emergence of technologies such as attack surface management (ASM), which are starting to help organisations get more proactive and focus their efforts for maximum…

5 min read

How the Talent Shortage Impacts Cybersecurity Leadership

4 min read - The lack of a skilled cybersecurity workforce stalls the effectiveness of any organization’s security program. Yes, automated tools and technologies like artificial intelligence (AI) and machine learning (ML) offer a layer of support, and bringing in a managed security service provider (MSSP) provides expertise that isn’t available in-house. But it isn’t enough, especially for the medium-sized businesses that would most benefit from an internal security team. However, the talent shortage doesn’t just impact present-day security concerns. The lack of a…

4 min read