✳ US · NIST SP 800-30

SP 800-30: Guide for conducting risk assessments (not an RMF worksheet, not a do-it-yourself matrix)

An educational overview of NIST SP 800-30 Rev. 1 (Date Published September 2012, Final 2012-09-17) as guidance for conducting risk assessments of federal information systems and organizations. It amplifies SP 800-39 by name only. Not an RMF worksheet, not a FedRAMP package, not an SP 800-53 family dump, and not an Atlas Authorization to Operate.

US · NIST SP 800-30Publication explainerLast reviewed

What category of publication this is

NIST Special Publication 800-30 Revision 1 is Guide for Conducting Risk Assessments. The CSRC abstract says its purpose is guidance for conducting risk assessments of federal information systems and organizations, amplifying the guidance in Special Publication 800-39. Assessments at all three tiers in the risk management hierarchy are part of an overall risk management process. They give senior leaders information they need to choose a course of action in response to identified risks.

Who it commonly frames: readers leaving the Risk Management Framework page who still treat a risk assessment as a one-page form, and readers who think a risk register means that framework is finished. It is a publication. It is not a statute, and it is not a scoring product.

What security people most often confuse: they fold an assessment, the seven RMF steps, a FedRAMP package, and an SP 800-53 family list into one homework pile. This page keeps those objects apart. Beginner threat, vulnerability, and risk vocabulary stays on /learn/topics/threat-vulnerability-risk/. This explainer does not replace that lesson.

Edition pin

SP 800-30 Rev. 1, Date Published September 2012. Document history on the CSRC page stamps Final on 2012-09-17 (shown there as 09/17/12). DOI 10.6028/NIST.SP.800-30r1. The PDF is nistspecialpublication800-30r1 on nvlpubs. This Final supersedes SP 800-30 (07/01/2002).

Document history on that page ends at Final 2012-09-17. Rev. 1 is the current Final there as of this review (2026-09-26). If a newer Final appears, update this pin and treat the older claim as UNKNOWN.

Where this publication sits

SP 800-39, Managing Information Security Risk: Organization, Mission, and Information System View, is Final 2011-03-01 (CSRC history 03/01/11). SP 800-30 describes it as the publication that defines organization-wide information security risk management. The component themes named there are frame, assess, respond, and monitor. SP 800-39 is the management publication. SP 800-30 specializes the assess component. Atlas names SP 800-39 only. There is no SP 800-39 explainer. The official page is https://csrc.nist.gov/pubs/sp/800/39/final.

SP 800-37 Rev. 2 is the Risk Management Framework on /learn/explainers/sp-800-37/. The steps are Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor. Risk assessments inform those activities (Categorize, Select, and Authorize stay at slogan depth here). An assessment document is not the seven steps finished.

F2 (/learn/topics/threat-vulnerability-risk/) splits threat, vulnerability, likelihood, impact, and uncertainty. R1 (/learn/topics/write-the-risk-sentence/) is one risk, one owner, and one open question. Use those pages for the sentence. This page does not rewrite them. FISMA (/learn/explainers/fisma/) is the statutory backdrop for federal agency information security management. It is context, not this publication.

Four steps, literacy labels only

Chapter 3 of SP 800-30 Rev. 1 names four steps: prepare, conduct, communicate, and maintain. Prepare sets purpose, scope, assumptions, constraints, information sources, and the risk model. Conduct identifies threat sources and events, vulnerabilities and predisposing conditions, then likelihood, impact, and a risk determination. Communicate shares results with decision makers. Maintain revisits the assessment when systems, threats, missions, or environments change.

The publication says organizations have flexibility on formality, methods, and tools. It also says risk assessments are often not precise instruments. Uncertainty is normal. It does not mean the assessment failed. The strip below is literacy only. It does not assign scores, and it does not reprint appendices D through L. Those tables stay in the PDF. This page does not set an Atlas scoring scale.

Three tiers, slogan only

The same publication supports three altitudes. Tier 1 is the organization. Tier 2 is the mission or business process. Tier 3 is the information system. An assessment can be aimed at one of those tiers. The altitude changes the question. It does not turn the four steps into a different publication.

Tier 3 work can inform system-level Risk Management Framework tasks. This page does not open an SP 800-18 system security plan. SP 800-137 is the continuous monitoring companion at /learn/explainers/sp-800-137/. An ISCM strategy and program is not this assessment finished.

What SP 800-30 is not

Not a do-it-yourself heat map, and not a risk matrix used as the lesson. Not FedRAMP homework (/learn/explainers/fedramp/). Not an SP 800-53 family dump (/learn/explainers/sp-800-53/ and /reference/frameworks/nist-sp-800-53-r5/). Not an SP 800-137 ISCM program (/learn/explainers/sp-800-137/). Not an SP 800-18 page. Not an Atlas Authorization to Operate. Not a replacement for the F2 concept lesson.

The GRC evidence lab (/labs/grc-evidence-exception/) practices an evidence and exception habit on a synthetic control. That artifact is not a federal risk-assessment package. A risk register row is not permission to skip prepare, communicate, or maintain.

Whether a named agency holds an Authorization, and whether a private team must run federal 800-30 templates verbatim, is UNKNOWN on this page. The PDF says nongovernmental organizations may use the publication on a voluntary basis. Coverage questions escalate to counsel, the authorizing official, or the GRC owner. Do not paste a sensitive risk register into Atlas.

Rewrite the one-line claim

Replace "we are RMF, 800-30, FedRAMP, and NIST risk compliant" with a reading sentence. We use SP 800-30 Rev. 1 literacy for conducting risk assessments (prepare, conduct, communicate, maintain). That informs, and is not the same as, the RMF seven steps, a FedRAMP lane, or catalog selection.

For one system the team touches, privately name whether the live question is framing risk, assessing it, responding, or monitoring, and which lane (an agency RMF, or some other lane) actually applies. Do not paste a sensitive risk register into Atlas.

An assessment is not RMF finished, not FedRAMP, and not an Atlas Authorization

Teaching table only. It does not assign an Authorization to Operate, a FedRAMP package, a control selection, or a score.

Six phrases people fold into one risk badge. Not an Authorization, and not a matrix.
Phrase people sayLiteracy correction
We finished a risk assessment, so RMF is doneAn assessment informs RMF. The seven RMF steps are a broader process. Atlas card: /learn/explainers/sp-800-37/.
Risk assessment = FedRAMP packageFedRAMP is a cloud Authorization reuse lane. Related vocabulary, different object. Atlas card: /learn/explainers/fedramp/.
Risk assessment = dump every 800-53 familySP 800-53 is a control catalog. An assessment is not a family homework dump. Atlas card: /learn/explainers/sp-800-53/. Reference card: /reference/frameworks/nist-sp-800-53-r5/.
Atlas 800-30 lesson = ATOAtlas does not issue Authorizations. Completing a lesson is not Authorized.
GRC evidence lab artifact = 800-30 assessment completeThe shipped GRC lab practices an evidence and exception habit. It is not a federal risk-assessment package. Lab: /labs/grc-evidence-exception/.
Risk register exists, so we can skip prepare/communicate/maintainA register row is not the four-step assessment discipline. Prepare, communicate, and maintain still apply.

Claims to retire

A filled risk matrix, or a risk register, means RMF is complete.

An assessment informs the seven RMF steps. A matrix or a register row is not those steps finished, and it does not skip prepare, communicate, or maintain.

SP 800-30, SP 800-37, FedRAMP, and SP 800-53 are the same homework.

800-30 is assessment guidance. 800-37 is the RMF process. FedRAMP is a cloud Authorization lane. 800-53 is a control catalog. Related vocabulary, different objects.

Atlas can grant an Authorization to Operate after this lesson.

Atlas does not issue Authorizations. Completing this lesson is not Authorized.

Uncertainty means the assessment failed.

The publication says assessments are often not precise instruments. Uncertainty is normal. Record what you still do not know.

A private team must run federal 800-30 templates verbatim.

Do not invent that coverage. Nongovernmental use is voluntary in the PDF. Whether a named team must follow the templates is UNKNOWN here. Escalate to counsel, the authorizing official, or the GRC owner.

Prepare, conduct, communicate, maintain

Static strip from SP 800-30 Rev. 1, Chapter 3. Literacy labels only. It does not assign scores, and it does not copy appendices D through L.

Four process steps. Not a heat map.
StepOne-line literacyBoundary
PreparePurpose, scope, assumptions, constraints, information sources, and the risk model, before any scoring folkloreContext first. Not a score.
ConductIdentify threat sources and events, vulnerabilities and predisposing conditions, then likelihood, impact, and risk determination themesThemes only. The appendix tables stay in the PDF.
CommunicateShare results with decision makers. The assessment is for action, not a binder ornamentResults leave the file. Not a report template.
MaintainRevisit when systems, threats, missions, or environments change. One PDF is not foreverA register row does not close this step.

CHECK THE CATEGORY

Which sentence matches this page?

Glossary and nearby pages

Use the agency page in the sources for the authoritative text. This page has no figure.

Find your next idea.

Tip: press / to open search. Escape closes this window.