1.5 Comparing ISO 31000 with COSO ERM, NIST RMF, and Sector Frameworks

Key Takeaways

  • COSO ERM 2017 is organized into 5 components and 20 principles and is oriented toward integrating risk with strategy and performance.
  • The NIST Risk Management Framework (SP 800-37 Rev. 2) has 7 steps and embeds security, privacy, and cyber supply chain risk management into every phase of the system development life cycle.
  • OCTAVE is a self-directed, asset-driven information security risk assessment methodology developed at the CERT Division of Carnegie Mellon's Software Engineering Institute.
  • ISO 31000 is deliberately generic and non-certifiable, whereas ISO/IEC 27005 applies the same logic specifically to information security risk inside an ISO/IEC 27001 ISMS.
  • Frameworks are complementary: many organizations use ISO 31000 for enterprise risk methodology and COSO ERM for governance and board-level reporting.
Last updated: July 2026

1.5 Comparing ISO 31000 with COSO ERM, NIST RMF, and Sector Frameworks

Domain 1 requires the ability to recognize relevant standards and regulatory frameworks regarding risk management — not only ISO 31000. PECB's own published sample questions include a framework-discrimination item, so candidates must be able to identify a framework from a one-line description of its distinguishing feature. This section supplies those discriminators.


COSO ERM 2017: Integrating with Strategy and Performance

COSO (the Committee of Sponsoring Organizations of the Treadway Commission) published Enterprise Risk Management — Integrating with Strategy and Performance in 2017, replacing its 2004 ERM cube. It is a US-originated governance framework strongly associated with financial reporting, internal control, and board oversight.

COSO ERM 2017 is structured as five interrelated components supported by 20 principles:

  1. Governance and Culture — board risk oversight, operating structures, desired culture, core values, and attracting/retaining capable people.
  2. Strategy and Objective-Setting — analyzing business context, defining risk appetite, evaluating alternative strategies, and formulating business objectives.
  3. Performance — identifying risk, assessing severity, prioritizing risks, implementing responses, and developing a portfolio view.
  4. Review and Revision — assessing substantial change, reviewing risk and performance, and pursuing improvement.
  5. Information, Communication, and Reporting — leveraging information systems, communicating risk information, and reporting on risk, culture, and performance.

COSO's centre of gravity is strategy-setting and performance; ISO 31000's is integration into all activities and decisions. COSO is prescriptive in its principle set and heavily used for audit and regulatory reporting in US-listed entities; ISO 31000 is deliberately short, generic, and international.


The NIST Risk Management Framework (SP 800-37 Rev. 2)

The NIST Risk Management Framework, defined in NIST Special Publication 800-37 Revision 2, is a US federal framework for managing security and privacy risk in information systems. Its defining characteristic — and the one PECB tests — is that it embeds security, privacy, and cyber supply chain risk management into every phase of the system development life cycle.

RMF Revision 2 has seven steps:

StepPurpose
PrepareEstablish context and priorities for managing security and privacy risk (added in Rev. 2)
CategorizeCategorize the system and the information processed, stored, and transmitted, by impact
SelectSelect the SP 800-53 control baseline and tailor it
ImplementImplement the controls and document the implementation
AssessDetermine whether controls are implemented correctly and producing the desired outcome
AuthorizeMake a senior-official, risk-based decision to authorize system operation
MonitorContinuously monitor controls, system changes, and the risk posture

Exam Tip: If a question describes a framework that integrates security, privacy, and cyber supply chain risk management into every SDLC phase, the answer is the NIST RMF — not COSO ERM (strategy and performance) and not OCTAVE (self-directed asset-based assessment).


OCTAVE, ISO/IEC 27005, and FAIR

  • OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation) was developed at the CERT Division of the Software Engineering Institute at Carnegie Mellon University. It is self-directed — run by the organization's own staff rather than external consultants — and asset-driven, starting from critical information assets and working outward to threats and vulnerabilities. OCTAVE Allegro is the streamlined variant.
  • ISO/IEC 27005 provides guidance on information security risk management and is the natural companion to ISO/IEC 27001. It applies the ISO 31000 process shape specifically to information security, including the primary/supporting asset distinction.
  • FAIR (Factor Analysis of Information Risk) is a quantitative model that decomposes risk into loss event frequency and loss magnitude, expressing cyber risk in monetary terms. It complements rather than replaces ISO 31000.
  • Basel operational risk rules and Solvency II impose sector-specific quantification and capital requirements on banks and insurers respectively; ISO 31000 supplies the underlying methodology those regimes assume.

Comparative Summary

FrameworkOriginScopeDistinguishing featureCertifiable for organizations?
ISO 31000:2018ISO (international)All risk, all sectors8 principles, leadership-centred 6-component framework, generic guidanceNo
COSO ERM 2017COSO (US)Enterprise risk, governance5 components, 20 principles, integrated with strategy and performanceNo
NIST RMFNIST (US federal)Information system security and privacy7 steps embedded across the whole SDLCNo
OCTAVECERT/SEI (US)Information securitySelf-directed, asset-driven evaluation run by internal staffNo
ISO/IEC 27005ISO/IECInformation security riskApplies risk process to an ISO/IEC 27001 ISMSNo (27001 is)
FAIRThe Open GroupCyber and operational riskQuantitative decomposition into frequency and magnitudeNo

Using Frameworks Together

These frameworks are complementary, not mutually exclusive. A common enterprise pattern is:

  • ISO 31000 supplies the principles, framework, and process language used enterprise-wide.
  • COSO ERM supplies the governance vocabulary the audit committee and external auditors expect.
  • ISO/IEC 27005 or NIST RMF supplies the depth for technology and information security risk.
  • FAIR supplies monetary quantification when the board demands a currency figure rather than a heat-map colour.

The ISO 31000 Customized principle explicitly supports this: the framework must be tailored to the organization's context and objectives, which frequently means harmonizing an inherited COSO or NIST vocabulary rather than discarding it.


Real-World Example: Harmonizing Two Frameworks

A US-listed medical device manufacturer with EU operations already ran a COSO ERM programme for Sarbanes-Oxley internal control reporting. When it adopted ISO 31000, the risk manager did not replace COSO. Instead, the team mapped COSO's five components onto the ISO 31000 framework clauses, retained COSO terminology in audit committee papers, and adopted ISO 31000 process language for operational risk workshops. Risk appetite was defined once and consumed by both. The result satisfied the auditors without forcing operational teams to learn two competing risk vocabularies.

Test Your Knowledge

Which risk management framework embeds security, privacy, and cyber supply chain risk management into every phase of the system development life cycle?

A
B
C
D
Test Your Knowledge

How is COSO ERM 2017 structured, and how does its emphasis differ from ISO 31000:2018?

A
B
C
D
Test Your Knowledge

An organization already reports risk to its audit committee using COSO ERM language and now wishes to adopt ISO 31000. Consistent with the ISO 31000 principles, what is the most appropriate approach?

A
B
C
D