
Risk Management
In today’s highly connected world, organizations all face more diverse, sophisticated threats—cyber, physical, technological, or natural—that have cross-sector impacts. The evolving risk landscape necessitates an evolved response.
Risk Management is the process of identifying, analyzing, assessing, and communicating risk and accepting, avoiding, transferring, or mitigating it to an acceptable level considering associated costs and benefits of any actions taken. Effective risk management improves the quality of decision making. While risk cannot always be eliminated, actions can be taken to mitigate risk.
Since the nation’s critical infrastructure is largely owned and operated by the private sector, managing risk is shared priority.

National Risk Management Center
CISA’s National Risk Management Center (NRMC) works with government and industry to identify, analyze, prioritize, and manage the most significant strategic risks to the nation’s 16 critical infrastructure sectors.
Featured Content

Secure Tomorrow Series Toolkit
The Toolkit provides a powerful means of increasing risk awareness, identifying risk mitigation solutions, and encouraging systems-level thinking and long-term planning.

National Critical Functions
Functions of government and the private sector so vital to the U.S. that their disruption, corruption, or dysfunction would have a debilitating effect on security, national economic security, national public health or safety, or any combination the

Space Systems Initiative
CISA works with public and private sector partners to advance space system security and resilience by identifying and assessing risks and expanding industry and international partnerships to ensure the responsible use of space.
Space Systems Initiative
CISA works with public and private sector partners to advance space system security and resilience by identifying and assessing risks and expanding industry and international partnerships to ensure the responsible use of space.
Helpful Resources
View all publicationsSecure by Design Alert: Eliminating Buffer Overflow Vulnerabilities
Mobile Communications Best Practice Guidance
Safe Software Deployment: How Software Manufacturers Can Ensure Reliability for Customers
Connected Communities Guidance: Zero Trust to Protect Interconnected Systems
Contact Us
For questions or comments, email NRMC@hq.dhs.gov.