NIST Risk Management Framework
Also known as: NIST RMF; NIST 800-37
Seven-step process for integrating security, privacy, and risk management into the system development lifecycle.
The NIST Risk Management Framework (RMF) is the process framework articulated in NIST Special Publication 800-37, providing the procedural basis for selecting, implementing, assessing, authorizing, and monitoring security controls (typically drawn from NIST 800-53) in federal information systems. Originally a six-step framework, NIST 800-37 Revision 2 (December 2018) expanded to seven steps: (1) Prepare — establish context for risk management at organization and system levels (added in Rev 2); (2) Categorize — categorize the system based on impact level (FIPS 199, NIST 800-60); (3) Select — select appropriate baseline of controls and tailor; (4) Implement — implement the controls and document; (5) Assess — assess control effectiveness through Security Control Assessor; (6) Authorize — risk-based decision by Authorizing Official whether to operate the system (Authorization to Operate or ATO); (7) Monitor — continuously monitor controls and risk posture, with reauthorization decisions over time. RMF replaced the earlier Certification and Accreditation (C&A) process. The framework is mandated for federal systems by FISMA and is used (sometimes adapted) by defense, intelligence, and increasingly state and local government. The 'authorize' step is operationally critical — federal systems cannot operate without an ATO, making RMF the gatekeeper for federal cybersecurity. RMF integrates with broader NIST publications (Cybersecurity Framework for governance, 800-53 for controls, 800-30 for risk assessments) into a comprehensive cybersecurity approach.
Core components
- Seven-step process: Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor
- FIPS 199 system categorization (Low/Moderate/High)
- Authorization to Operate (ATO) as gating decision
- Authorizing Official role
- Security Control Assessor role
- Continuous monitoring
- Connection to NIST 800-53 controls catalog
- Integration with NIST Cybersecurity Framework
- Distinction from earlier Certification and Accreditation (C&A)
- FISMA mandate for federal systems
- Reauthorization cadence
Primary use case
Authorization process for US federal information systems; foundation for federal cybersecurity governance; reference framework in defense, intelligence, and state/local government; basis for substantial federal-cybersecurity consulting practice; foundation for ATO decisions and risk-based system management; integration with FedRAMP for cloud authorizations; pedagogical reference in cybersecurity governance education; influence on private-sector risk management programs.
Common criticisms
- Process-heavy and time-consuming — full RMF cycle for new federal systems can take 12-18 months or more, creating substantial delays in deploying needed capabilities
- Authorization to Operate decisions can become bureaucratic gates rather than substantive risk decisions
- assessment quality varies enormously across Security Control Assessors and contractors
- tendency toward checklist compliance — controls implemented and documented but not necessarily operationally effective
- integration with agile, DevOps, and continuous-deployment practices has improved through Rev 2 but remains tension-filled (continuous ATO efforts, RMF Knowledge Service, etc.)
- the 'authorize' decision is risk-based but Authorizing Officials often lack risk-assessment expertise to make genuinely informed decisions
- commercial GRC platforms automate documentation but can obscure substantive security
- cost of RMF compliance is substantial and creates barriers for smaller agencies and contractors
- reauthorization cadence (typically 3 years) doesn't match contemporary threat-environment change rates
- cross-agency variation in RMF implementation creates duplicative effort for vendors operating across multiple federal customers.
Lineage
- Siblings
- NIST 800-53, FedRAMP