Management Systems

NIST RMF

Risk Management Framework (SP 800-37)

Formal standard US NIST Since 2010

The seven-step process (prepare, categorise, select, implement, assess, authorise, monitor) that US federal systems follow to select and authorise security controls from SP 800-53.

It is a process standard, not a control catalogue. Outside the US federal supply chain, the categorise-select-assess loop is worth borrowing even if the authorisation ceremony is not.

At a glance

Category
Management Systems
Jurisdiction
US
Governance
NIST
Status
Revision 2 (2018)
First released
2010

Links

Related frameworks

Other entries under Management Systems.

See NIST RMF in context

Open the interactive Data Landscape for Regulation to compare NIST RMF against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.