Management Systems
NIST RMF
Risk Management Framework (SP 800-37)
Formal standard
US
NIST
Since 2010
The seven-step process (prepare, categorise, select, implement, assess, authorise, monitor) that US federal systems follow to select and authorise security controls from SP 800-53.
It is a process standard, not a control catalogue. Outside the US federal supply chain, the categorise-select-assess loop is worth borrowing even if the authorisation ceremony is not.
At a glance
- Category
- Management Systems
- Jurisdiction
- US
- Governance
- NIST
- Status
- Revision 2 (2018)
- First released
- 2010
Links
Related frameworks
Other entries under Management Systems.
- ISO/IEC 27001: Information Security Management Systems
- NIST CSF: Cybersecurity Framework 2.0
- Grundschutz: BSI IT-Grundschutz
See NIST RMF in context
Open the interactive Data Landscape for Regulation to compare NIST RMF against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.