RESPOND TO THESE DISCUSSION POST BASED ON THE TOPIC “First, review the National Institute of Standards and Technology (NIST) website.
 Then, in your initial post, discuss the importance of the website to you as a cybersecurity risk assessor.” 

  In response to your peers, discuss different uses of the site to include tools and resources that can help you in your risk assessment efforts.

As a risk assessor, the National Institute of Standards and Technology (NIST) website is valuable.  The source of information, the Information Technology Laboratory, which is within NIST, is widely used in the field of IT risk management (Gibson, 2014).  A risk assessor uses a specific process to identify and evaluate risks based on an analysis of threats and vulnerabilities to assets.  The NIST website provides the framework necessary to perform a complete RA, and it’s available in the public domain according to Title 17 of the United States Code (NIST, 2018). 
Why is it important the NIST website is made available to the public?  Because, NIST attends and holds public workshops and conferences to gather input about what types of information would be useful to industry, Federal, and state governments.  The information they provide, e.g. the framework for risk assessors, is up-to-date, objective, clear, and accurate (NIST, 2016).  It is their quality of standards that that exalts their framework from others. 
In addition, they provide up-to-date vulnerability feeds keeping security professionals informed and ready to respond by mitigating or accepting impending high, medium, or low impact level threats.  Once a one-time import of the complete data set using the compressed XML vulnerability feeds is complete, the modified feeds can be updated without having to import the entire data set over again (NIST, 2017).  This saves a risk assessor valuable time and keeps them in a perpetual cycle of receiving fresh vulnerability information. 

As cybersecurity risk assessor the National Institute of Standards and Technology is an essential tool. After, the reviewing of the website it was discovered that valuable information was presented such as National Vulnerability Database News, automation of vulnerability management, security measurement, and compliance. National Vulnerability Database includes databases of security checklists, security related software flaws, misconfigurations, product names, Common Vulnerability Scoring System Calculator, and impact metrics (National Institute of Standards and Technology, 2017).
All the information above are important to an organization operation based on the security of its data.  Also, the National Institute of Standards and Technology compensate the basic three security controls used to develop a company’s security plan. By having updated information available on a day to day base will give the cybersecurity risk assessor and the company away to keeping its security plan in place. As well as the organization can maintain the security breaches to a minimum. 
