NIST veröffentlicht "Risk Management Guide for IT Systems"

February 4, 2002 -- NIST is pleased to announce the final publication of
NIST Special Publication 800-30, Risk Management Guide for Information
Technology Systems.  This publication provides an overview of the risk
management process, describes how it fits into the system development
cycle, and defines the roles of various personnel who support and use
process. It also describes a risk assessment methodology, the steps in
conducting an IT risk assessment, and a risk mitigation process.
Additionally, it outlines some factors that lead to a successful risk
management program.

URL to NIST Special Publications page:
<>, scroll down
you see SP 800-30 (6th publication from top) and is available in .pdf

