NIST Risk Management Framework

Also known as: NIST RMF; NIST 800-37

framework · cybersecurity · regulatory-standard

Seven-step process for integrating security, privacy, and risk management into the system development lifecycle.

The NIST Risk Management Framework (RMF) is the process framework articulated in NIST Special Publication 800-37, providing the procedural basis for selecting, implementing, assessing, authorizing, and monitoring security controls (typically drawn from NIST 800-53) in federal information systems. Originally a six-step framework, NIST 800-37 Revision 2 (December 2018) expanded to seven steps: (1) Prepare — establish context for risk management at organization and system levels (added in Rev 2); (2) Categorize — categorize the system based on impact level (FIPS 199, NIST 800-60); (3) Select — select appropriate baseline of controls and tailor; (4) Implement — implement the controls and document; (5) Assess — assess control effectiveness through Security Control Assessor; (6) Authorize — risk-based decision by Authorizing Official whether to operate the system (Authorization to Operate or ATO); (7) Monitor — continuously monitor controls and risk posture, with reauthorization decisions over time. RMF replaced the earlier Certification and Accreditation (C&A) process. The framework is mandated for federal systems by FISMA and is used (sometimes adapted) by defense, intelligence, and increasingly state and local government. The 'authorize' step is operationally critical — federal systems cannot operate without an ATO, making RMF the gatekeeper for federal cybersecurity. RMF integrates with broader NIST publications (Cybersecurity Framework for governance, 800-53 for controls, 800-30 for risk assessments) into a comprehensive cybersecurity approach.

Originators

National Institute of Standards and Technology (NIST); Joint Task Force Transformation Initiative (interagency) high

Year / Decade

2010 (initial NIST 800-37 Rev 1); 2018 (Rev 2 with seven steps); ongoing high

Primary sources

NIST (2018). Special Publication 800-37 Revision 2: Risk Management Framework for Information Systems and Organizations, NIST (multiple). FIPS Publication 199: Standards for Security Categorization of Federal Information and Information Systems, FISMA (2002, 2014) high

Core components

Primary use case

Authorization process for US federal information systems; foundation for federal cybersecurity governance; reference framework in defense, intelligence, and state/local government; basis for substantial federal-cybersecurity consulting practice; foundation for ATO decisions and risk-based system management; integration with FedRAMP for cloud authorizations; pedagogical reference in cybersecurity governance education; influence on private-sector risk management programs.

Common criticisms

Lineage

Siblings
NIST 800-53, FedRAMP