What category of process this is
NIST Special Publication 800-37 Revision 2 is Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy. It describes the Risk Management Framework (RMF) and guidelines for applying that framework to information systems and organizations.
The CSRC abstract calls the RMF a disciplined, structured, and flexible process for managing security and privacy risk. The process covers categorization; control selection, implementation, and assessment; system and common control authorizations; and continuous monitoring. It also includes organization-level prepare activities. Executing the tasks links system-level risk work to organization-level risk management.
Edition pin
SP 800-37 Rev. 2, Date Published December 2018, Final 20 December 2018 (2018-12-20). DOI 10.6028/NIST.SP.800-37r2. The PDF is NIST.SP.800-37r2 on nvlpubs. This Final supersedes SP 800-37 Rev. 1 (5 June 2014) and CSWP 3 (3 June 2014).
Document history on the CSRC page ends at Final 2018-12-20. Use that string when you name the publication. If a newer Final appears, update this pin and treat the older claim as UNKNOWN.
Why this page sits after FISMA
The FISMA explainer (/learn/explainers/fisma/) teaches the statutory and program backdrop for federal agency information security management. NIST states that the suite of risk management standards and guidelines is not a FISMA compliance checklist. Readers still ask how an agency frames the work.
RMF is the process-literacy answer. FISMA is the why and who backdrop. SP 800-37 is how the process is framed. Keep the lanes apart. This page does not merge them.
Seven steps, slogan literacy only
The NIST RMF project page names seven steps, in this order: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor. Rev. 2 emphasizes Prepare (organization-wide readiness before system-level work), privacy alongside security, continuous monitoring and ongoing authorization, and the system life cycle.
The strip below is the official order and the official one-line theme for each step. It is literacy only. It does not assign tasks, and it is not homework.
Select is not the entire catalog
Select means choose the set of NIST SP 800-53 controls to protect the system based on risk assessment(s). It is risk-based selection and tailoring from the catalog. It does not mean implement every control in the catalog. Baselines live in companion publications, not on this page.
The existing Reference card is /reference/frameworks/nist-sp-800-53-r5/. The SP 800-53 explainer (/learn/explainers/sp-800-53/) goes deeper on catalog literacy and where baselines and assessment procedures live. This explainer does not dump control families.
What SP 800-37 is not
Not a FISMA badge. Not FedRAMP homework. Not CMMC. Not SP 800-171. Not an Atlas Authorization to Operate. Not a seven-box weekend list.
A state or local agency does not automatically run federal RMF the same way an executive agency runs a FISMA program. That coverage question escalates to counsel, the authorizing official, or the contracting officer. This page does not invent who must run the process.
Rewrite the one-line claim
Replace "we are RMF, FISMA, and FedRAMP compliant" as one blob with two lanes. We use SP 800-37 Rev. 2 RMF process literacy for an agency system. That is different from a FedRAMP cloud offering lane.
At work, privately ask who the authorizing official (or equivalent owner) is for one system the team touches, and which lane applies. Do not paste sensitive system boundary diagrams into Atlas.
RMF is not a FISMA checklist, not FedRAMP homework, and not an Atlas Authorization
Teaching table only. It does not assign an Authorization to Operate, a FedRAMP Authorization, or a finding that a publication has been met.
| Phrase people say | Literacy correction |
|---|---|
| We finished RMF, so FISMA is a checklist done | NIST: the suite is not a FISMA compliance checklist. RMF is a risk process. FISMA is the program and statutory backdrop. Atlas card: /learn/explainers/fisma/. |
| RMF equals a FedRAMP Authorization package | FedRAMP standardizes reusable cloud product and service assessments and Authorizations for agency adoption. RMF is the broader process agencies use for systems. Atlas card: /learn/explainers/fedramp/. |
| The Atlas RMF lesson is an Authorization to Operate | Atlas does not issue Authorizations. Completing a lesson is not Authorized. |
| Select means implement every 800-53 control | Select is risk-based selection and tailoring from the catalog. Baselines live in companions. Reference card: /reference/frameworks/nist-sp-800-53-r5/. No family dump here. |
Claims to retire
RMF is a FISMA compliance checklist.
NIST says the risk-management suite is not a FISMA compliance checklist. RMF is a risk process. FISMA is the program and statutory backdrop.
Finishing the seven steps once means the system is forever Authorized.
Monitor is continuous. An authorization decision is not a one-time badge that never needs another look.
RMF and FedRAMP are the same Authorization homework.
FedRAMP is reusable cloud product and service Authorization. RMF is the broader process agencies use for systems. Related vocabulary, different object.
Atlas, or a vendor slide, can grant an Authorization to Operate.
Atlas does not issue Authorizations. Completing this lesson is not Authorized.
Select means implement the entire SP 800-53 catalog.
Select is risk-based selection from the catalog. The Reference card names the catalog. This page does not dump families.
A state or local agency must run federal RMF the same way an executive agency runs FISMA.
Do not invent that coverage. Escalate to counsel, the authorizing official, or the contracting officer.
Official RMF steps
Static strip from the NIST RMF project page. Slogan literacy only. It does not assign tasks.
| Step | Official theme | Boundary |
|---|---|---|
| Prepare | Essential activities to prepare the organization to manage security and privacy risks | Organization-wide readiness before system-level work. |
| Categorize | Categorize the system and information processed, stored, and transmitted based on an impact analysis | Impact literacy. Not a determination for a real system. |
| Select | Select the set of NIST SP 800-53 controls to protect the system based on risk assessment(s) | Risk-based selection from the catalog. Not every control. Card: /reference/frameworks/nist-sp-800-53-r5/. |
| Implement | Implement the controls and document how controls are deployed | Deployment documentation theme. Not an implementation dump. |
| Assess | Assess to determine if the controls are in place, operating as intended, and producing the desired results | Assessment theme. Not an assessment-procedure catalog. |
| Authorize | Senior official makes a risk-based decision to authorize the system (to operate) | A senior-official decision. Not an Atlas Authorization. |
| Monitor | Continuously monitor control implementation and risks to the system | Ongoing. Finishing the list once is not forever Authorized. |
CHECK THE CATEGORY
Which sentence matches this page?
Glossary and nearby pages
- FISMA explainer (statutory backdrop, different page)
- FedRAMP explainer (cloud Authorization, different lane)
- Public sector industry path
- NIST CSF 2.0 (related outcomes language)
- NIST SP 800-53 catalog (Reference card, not this page)
- SP 800-53 explainer (catalog literacy for the Select step)
- From principles to frameworks and product categories
- Privacy is not a CIA checkbox
Use the agency page in the sources for the authoritative text. This page has no figure.