What is the NIST SP 800-37 Risk Management Framework (RMF)?
NIST SP 800-37 describes the Risk Management Framework (RMF), a disciplined, structured, and flexible process for managing security and privacy risks across information systems and the organizations that run them. Specifically, it gives senior leaders the information they need to make efficient, cost-effective, and risk-based decisions about the systems supporting their missions. Moreover, it integrates security and privacy directly into the system development life cycle (SDLC), so protection is built in rather than added after deployment.
In practice, the RMF is mandatory for U.S. federal agencies under FISMA and forms the operational backbone of FedRAMP, CMMC, and most federal system authorization programs. Furthermore, many private-sector organizations and federal contractors adopt it voluntarily as a mature, well-documented approach to risk-based security governance.
What are the key updates introduced in NIST SP 800-37 Revision 2?
Revision 2, published in December 2018, is the most significant overhaul of the RMF since its introduction. Specifically, it reflects a decade of lessons learned and the shift toward enterprise-wide cyber risk governance. As a result, organizations still operating under earlier versions should plan a transition, because regulators and auditors increasingly align to Rev. 2.
In practice, four major changes define Revision 2:
- New Prepare step: institutionalizes organization-level and system-level preparatory activities so teams arrive at categorization with the context they need
- Alignment with the NIST Cybersecurity Framework (CSF): makes it easier to map RMF outcomes to CSF functions for organizations using both frameworks
- Full integration of privacy risk management: treats privacy as an equal partner to security throughout every RMF step, rather than a downstream consideration
- Supply chain risk management (SCRM) concepts: addresses untrustworthy suppliers, counterfeits, and poor manufacturing practices across the SDLC, aligned with NIST SP 800-161
What are the seven steps of the NIST RMF?
The RMF operates as an ongoing cycle of seven steps. Moreover, each step produces specific outputs that feed the next, and the cycle loops back as systems and threats evolve. In fact, the Monitor step feeds directly back into Prepare whenever significant changes occur, making the RMF a continuous program rather than a one-time certification exercise.
Specifically, the seven steps are:
- Prepare: establish context, priorities, roles, and a common risk management strategy before starting the technical work
- Categorize: determine the adverse impact if the system or its information loses confidentiality, integrity, or availability, using FIPS 199 impact levels
- Select: choose and tailor an initial set of controls from NIST SP 800-53 Rev. 5 based on the system’s categorization
- Implement: deploy the selected controls and document exactly how they operate within the system and its environment
- Assess: determine whether controls are implemented correctly, operating as intended, and producing the desired outcomes
- Authorize: present the evidence to an Authorizing Official (AO), who formally accepts the residual risk and issues an Authority to Operate (ATO)
- Monitor: continuously track the system’s security and privacy posture and trigger reassessment when significant changes occur
How does the NIST RMF handle the relationship between security and privacy?
Revision 2 treats privacy as an equal partner to security rather than a downstream consideration. Specifically, the RMF requires close collaboration between information security and privacy programs throughout every step, because they have overlapping but distinct objectives. Moreover, NIST SP 800-53 Rev. 5 integrates privacy controls directly into the same catalog as security controls, so organizations do not manage two separate frameworks.
In practice, this integration means three things. First, systems handling personally identifiable information (PII) need a Senior Agency Official for Privacy involved from the Prepare step. Second, privacy controls appear in the same System Security Plan alongside security controls. Third, the RMF encourages combining security and privacy evidence into a single authorization package. As a result, the Authorizing Official makes a unified risk-based decision rather than reviewing parallel and potentially contradictory packages.
Why are continuous monitoring and automation critical in the NIST RMF?
Continuous monitoring transforms the RMF from a compliance exercise into an actual risk management program. In fact, without it, a system’s security posture on the day of authorization becomes increasingly disconnected from reality as code changes, vulnerabilities emerge, and threats evolve. Therefore, NIST SP 800-37 Rev. 2 strongly encourages maximizing automation throughout the Assess and Monitor steps.
In practice, mature continuous monitoring enables organizations to move from static, three-year point-in-time authorizations to an ongoing authorization model. Specifically, the Authorizing Official receives near real-time risk information and updates the authorization decision as significant changes occur. As a result, organizations reduce the cost of their security programs while keeping risk at an acceptable level. Moreover, this approach forms the technical foundation behind modernized programs like FedRAMP Continuous Monitoring and the federal push toward zero trust architectures.