✳ US · NIST SP 800-37

SP 800-37: Risk Management Framework (process literacy, not a FISMA checklist)

An educational overview of NIST SP 800-37 Rev. 2 as the Risk Management Framework process for security and privacy risk. Not a FISMA checklist, not FedRAMP homework, and not an Atlas Authorization to Operate.

US · NIST SP 800-37Publication explainerLast reviewed

What category of process this is

NIST Special Publication 800-37 Revision 2 is Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy. It describes the Risk Management Framework (RMF) and guidelines for applying that framework to information systems and organizations.

The CSRC abstract calls the RMF a disciplined, structured, and flexible process for managing security and privacy risk. The process covers categorization; control selection, implementation, and assessment; system and common control authorizations; and continuous monitoring. It also includes organization-level prepare activities. Executing the tasks links system-level risk work to organization-level risk management.

Edition pin

SP 800-37 Rev. 2, Date Published December 2018, Final 20 December 2018 (2018-12-20). DOI 10.6028/NIST.SP.800-37r2. The PDF is NIST.SP.800-37r2 on nvlpubs. This Final supersedes SP 800-37 Rev. 1 (5 June 2014) and CSWP 3 (3 June 2014).

Document history on the CSRC page ends at Final 2018-12-20. Use that string when you name the publication. If a newer Final appears, update this pin and treat the older claim as UNKNOWN.

Why this page sits after FISMA

The FISMA explainer (/learn/explainers/fisma/) teaches the statutory and program backdrop for federal agency information security management. NIST states that the suite of risk management standards and guidelines is not a FISMA compliance checklist. Readers still ask how an agency frames the work.

RMF is the process-literacy answer. FISMA is the why and who backdrop. SP 800-37 is how the process is framed. Keep the lanes apart. This page does not merge them.

Seven steps, slogan literacy only

The NIST RMF project page names seven steps, in this order: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor. Rev. 2 emphasizes Prepare (organization-wide readiness before system-level work), privacy alongside security, continuous monitoring and ongoing authorization, and the system life cycle.

The strip below is the official order and the official one-line theme for each step. It is literacy only. It does not assign tasks, and it is not homework.

Authorize is a risk-based decision

Authorize means a senior official makes a risk-based decision to authorize the system (to operate). That decision is not a product SKU, and it is not "Atlas completed the lesson." Finishing the seven names once is not forever Authorized.

A FedRAMP Marketplace Authorization for a cloud offering is a different lane (/learn/explainers/fedramp/). FedRAMP standardizes reusable cloud product and service assessments and Authorizations for agency adoption. The customer still configures. An agency authorizing its own system under RMF is not the same object.

Select is not the entire catalog

Select means choose the set of NIST SP 800-53 controls to protect the system based on risk assessment(s). It is risk-based selection and tailoring from the catalog. It does not mean implement every control in the catalog. Baselines live in companion publications, not on this page.

The existing Reference card is /reference/frameworks/nist-sp-800-53-r5/. The SP 800-53 explainer (/learn/explainers/sp-800-53/) goes deeper on catalog literacy and where baselines and assessment procedures live. This explainer does not dump control families.

What SP 800-37 is not

Not a FISMA badge. Not FedRAMP homework. Not CMMC. Not SP 800-171. Not an Atlas Authorization to Operate. Not a seven-box weekend list.

A state or local agency does not automatically run federal RMF the same way an executive agency runs a FISMA program. That coverage question escalates to counsel, the authorizing official, or the contracting officer. This page does not invent who must run the process.

Rewrite the one-line claim

Replace "we are RMF, FISMA, and FedRAMP compliant" as one blob with two lanes. We use SP 800-37 Rev. 2 RMF process literacy for an agency system. That is different from a FedRAMP cloud offering lane.

At work, privately ask who the authorizing official (or equivalent owner) is for one system the team touches, and which lane applies. Do not paste sensitive system boundary diagrams into Atlas.

RMF is not a FISMA checklist, not FedRAMP homework, and not an Atlas Authorization

Teaching table only. It does not assign an Authorization to Operate, a FedRAMP Authorization, or a finding that a publication has been met.

Four phrases people fold into one badge. Not an RMF seal.
Phrase people sayLiteracy correction
We finished RMF, so FISMA is a checklist doneNIST: the suite is not a FISMA compliance checklist. RMF is a risk process. FISMA is the program and statutory backdrop. Atlas card: /learn/explainers/fisma/.
RMF equals a FedRAMP Authorization packageFedRAMP standardizes reusable cloud product and service assessments and Authorizations for agency adoption. RMF is the broader process agencies use for systems. Atlas card: /learn/explainers/fedramp/.
The Atlas RMF lesson is an Authorization to OperateAtlas does not issue Authorizations. Completing a lesson is not Authorized.
Select means implement every 800-53 controlSelect is risk-based selection and tailoring from the catalog. Baselines live in companions. Reference card: /reference/frameworks/nist-sp-800-53-r5/. No family dump here.

Claims to retire

RMF is a FISMA compliance checklist.

NIST says the risk-management suite is not a FISMA compliance checklist. RMF is a risk process. FISMA is the program and statutory backdrop.

Finishing the seven steps once means the system is forever Authorized.

Monitor is continuous. An authorization decision is not a one-time badge that never needs another look.

RMF and FedRAMP are the same Authorization homework.

FedRAMP is reusable cloud product and service Authorization. RMF is the broader process agencies use for systems. Related vocabulary, different object.

Atlas, or a vendor slide, can grant an Authorization to Operate.

Atlas does not issue Authorizations. Completing this lesson is not Authorized.

Select means implement the entire SP 800-53 catalog.

Select is risk-based selection from the catalog. The Reference card names the catalog. This page does not dump families.

A state or local agency must run federal RMF the same way an executive agency runs FISMA.

Do not invent that coverage. Escalate to counsel, the authorizing official, or the contracting officer.

Official RMF steps

Static strip from the NIST RMF project page. Slogan literacy only. It does not assign tasks.

Seven steps in official order. Not a weekend list.
StepOfficial themeBoundary
PrepareEssential activities to prepare the organization to manage security and privacy risksOrganization-wide readiness before system-level work.
CategorizeCategorize the system and information processed, stored, and transmitted based on an impact analysisImpact literacy. Not a determination for a real system.
SelectSelect the set of NIST SP 800-53 controls to protect the system based on risk assessment(s)Risk-based selection from the catalog. Not every control. Card: /reference/frameworks/nist-sp-800-53-r5/.
ImplementImplement the controls and document how controls are deployedDeployment documentation theme. Not an implementation dump.
AssessAssess to determine if the controls are in place, operating as intended, and producing the desired resultsAssessment theme. Not an assessment-procedure catalog.
AuthorizeSenior official makes a risk-based decision to authorize the system (to operate)A senior-official decision. Not an Atlas Authorization.
MonitorContinuously monitor control implementation and risks to the systemOngoing. Finishing the list once is not forever Authorized.

CHECK THE CATEGORY

Which sentence matches this page?

Glossary and nearby pages

Use the agency page in the sources for the authoritative text. This page has no figure.

Find your next idea.

Tip: press / to open search. Escape closes this window.