1.5 Comparing ISO 31000 with COSO ERM, NIST RMF, and Sector Frameworks
Key Takeaways
- COSO ERM 2017 is organized into 5 components and 20 principles and is oriented toward integrating risk with strategy and performance.
- The NIST Risk Management Framework (SP 800-37 Rev. 2) has 7 steps and embeds security, privacy, and cyber supply chain risk management into every phase of the system development life cycle.
- OCTAVE is a self-directed, asset-driven information security risk assessment methodology developed at the CERT Division of Carnegie Mellon's Software Engineering Institute.
- ISO 31000 is deliberately generic and non-certifiable, whereas ISO/IEC 27005 applies the same logic specifically to information security risk inside an ISO/IEC 27001 ISMS.
- Frameworks are complementary: many organizations use ISO 31000 for enterprise risk methodology and COSO ERM for governance and board-level reporting.
1.5 Comparing ISO 31000 with COSO ERM, NIST RMF, and Sector Frameworks
Domain 1 requires the ability to recognize relevant standards and regulatory frameworks regarding risk management — not only ISO 31000. PECB's own published sample questions include a framework-discrimination item, so candidates must be able to identify a framework from a one-line description of its distinguishing feature. This section supplies those discriminators.
COSO ERM 2017: Integrating with Strategy and Performance
COSO (the Committee of Sponsoring Organizations of the Treadway Commission) published Enterprise Risk Management — Integrating with Strategy and Performance in 2017, replacing its 2004 ERM cube. It is a US-originated governance framework strongly associated with financial reporting, internal control, and board oversight.
COSO ERM 2017 is structured as five interrelated components supported by 20 principles:
- Governance and Culture — board risk oversight, operating structures, desired culture, core values, and attracting/retaining capable people.
- Strategy and Objective-Setting — analyzing business context, defining risk appetite, evaluating alternative strategies, and formulating business objectives.
- Performance — identifying risk, assessing severity, prioritizing risks, implementing responses, and developing a portfolio view.
- Review and Revision — assessing substantial change, reviewing risk and performance, and pursuing improvement.
- Information, Communication, and Reporting — leveraging information systems, communicating risk information, and reporting on risk, culture, and performance.
COSO's centre of gravity is strategy-setting and performance; ISO 31000's is integration into all activities and decisions. COSO is prescriptive in its principle set and heavily used for audit and regulatory reporting in US-listed entities; ISO 31000 is deliberately short, generic, and international.
The NIST Risk Management Framework (SP 800-37 Rev. 2)
The NIST Risk Management Framework, defined in NIST Special Publication 800-37 Revision 2, is a US federal framework for managing security and privacy risk in information systems. Its defining characteristic — and the one PECB tests — is that it embeds security, privacy, and cyber supply chain risk management into every phase of the system development life cycle.
RMF Revision 2 has seven steps:
| Step | Purpose |
|---|---|
| Prepare | Establish context and priorities for managing security and privacy risk (added in Rev. 2) |
| Categorize | Categorize the system and the information processed, stored, and transmitted, by impact |
| Select | Select the SP 800-53 control baseline and tailor it |
| Implement | Implement the controls and document the implementation |
| Assess | Determine whether controls are implemented correctly and producing the desired outcome |
| Authorize | Make a senior-official, risk-based decision to authorize system operation |
| Monitor | Continuously monitor controls, system changes, and the risk posture |
Exam Tip: If a question describes a framework that integrates security, privacy, and cyber supply chain risk management into every SDLC phase, the answer is the NIST RMF — not COSO ERM (strategy and performance) and not OCTAVE (self-directed asset-based assessment).
OCTAVE, ISO/IEC 27005, and FAIR
- OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation) was developed at the CERT Division of the Software Engineering Institute at Carnegie Mellon University. It is self-directed — run by the organization's own staff rather than external consultants — and asset-driven, starting from critical information assets and working outward to threats and vulnerabilities. OCTAVE Allegro is the streamlined variant.
- ISO/IEC 27005 provides guidance on information security risk management and is the natural companion to ISO/IEC 27001. It applies the ISO 31000 process shape specifically to information security, including the primary/supporting asset distinction.
- FAIR (Factor Analysis of Information Risk) is a quantitative model that decomposes risk into loss event frequency and loss magnitude, expressing cyber risk in monetary terms. It complements rather than replaces ISO 31000.
- Basel operational risk rules and Solvency II impose sector-specific quantification and capital requirements on banks and insurers respectively; ISO 31000 supplies the underlying methodology those regimes assume.
Comparative Summary
| Framework | Origin | Scope | Distinguishing feature | Certifiable for organizations? |
|---|---|---|---|---|
| ISO 31000:2018 | ISO (international) | All risk, all sectors | 8 principles, leadership-centred 6-component framework, generic guidance | No |
| COSO ERM 2017 | COSO (US) | Enterprise risk, governance | 5 components, 20 principles, integrated with strategy and performance | No |
| NIST RMF | NIST (US federal) | Information system security and privacy | 7 steps embedded across the whole SDLC | No |
| OCTAVE | CERT/SEI (US) | Information security | Self-directed, asset-driven evaluation run by internal staff | No |
| ISO/IEC 27005 | ISO/IEC | Information security risk | Applies risk process to an ISO/IEC 27001 ISMS | No (27001 is) |
| FAIR | The Open Group | Cyber and operational risk | Quantitative decomposition into frequency and magnitude | No |
Using Frameworks Together
These frameworks are complementary, not mutually exclusive. A common enterprise pattern is:
- ISO 31000 supplies the principles, framework, and process language used enterprise-wide.
- COSO ERM supplies the governance vocabulary the audit committee and external auditors expect.
- ISO/IEC 27005 or NIST RMF supplies the depth for technology and information security risk.
- FAIR supplies monetary quantification when the board demands a currency figure rather than a heat-map colour.
The ISO 31000 Customized principle explicitly supports this: the framework must be tailored to the organization's context and objectives, which frequently means harmonizing an inherited COSO or NIST vocabulary rather than discarding it.
Real-World Example: Harmonizing Two Frameworks
A US-listed medical device manufacturer with EU operations already ran a COSO ERM programme for Sarbanes-Oxley internal control reporting. When it adopted ISO 31000, the risk manager did not replace COSO. Instead, the team mapped COSO's five components onto the ISO 31000 framework clauses, retained COSO terminology in audit committee papers, and adopted ISO 31000 process language for operational risk workshops. Risk appetite was defined once and consumed by both. The result satisfied the auditors without forcing operational teams to learn two competing risk vocabularies.
Which risk management framework embeds security, privacy, and cyber supply chain risk management into every phase of the system development life cycle?
How is COSO ERM 2017 structured, and how does its emphasis differ from ISO 31000:2018?
An organization already reports risk to its audit committee using COSO ERM language and now wishes to adopt ISO 31000. Consistent with the ISO 31000 principles, what is the most appropriate approach?