Framework · Last verified
Risk Management Framework for Information Systems and Organizations
NIST's Risk Management Framework (SP 800-37) is a 7-step lifecycle process ending in an Authorization to Operate, not a control checklist. The steps run Prepare, Categorize, Select, Implement, Assess, Authorize and Monitor; a senior Authorizing Official grants the resulting ATO.
- Class
- Framework
- Owner
- National Institute of Standards and Technology (NIST), U.S. Department of Commerce
- Last verified
What it is
NIST SP 800-37 Rev. 2 is titled "Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy", published December 2018.
NIST's own RMF project page names the process in order: Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor.
The framework's output is an authorization decision, not a certificate: an Authorizing Official is defined (via CNSSI 4009-2022, through OMB Circular A-130) as "a senior Federal official or executive with the authority to authorize (i.e., assume responsibility for) the operation of an information system or the use of a designated set of common controls at an acceptable level of risk to agency operations..." — the decision, called Authorization to Operate (ATO), is made by the agency's own senior official, not by an independent accredited certification body.
Who owns it
SP 800-37 is published by the National Institute of Standards and Technology (NIST), an agency of the U.S. Department of Commerce.
RMF process steps
- Prepare
- Categorize
- Select
- Implement
- Assess
- Authorize
- Monitor
Who asks for it
Statutory (scoped). Statutory in one defined scope: FISMA (44 U.S.C. § 3554) requires the head of each U.S. federal agency to provide information security protections commensurate with risk, covering information and systems the agency collects, maintains or operates, including those operated on the agency's behalf by a contractor or other organization. Outside U.S. federal information systems this record documents no verified legal obligation.
FISMA (44 U.S.C. § 3554) requires "the head of each agency" to provide "information security protections commensurate with the risk and magnitude of the harm" for information and systems the agency collects, maintains or operates, including "information systems used or operated by an agency or by a contractor of an agency or other organization on behalf of an agency". The statute also requires each agency to delegate authority to its CIO, designate a senior information security officer, run an agency-wide information security program, and report annually to Congress.
FedRAMP's own authorization process page states: "A FedRAMP authorization follows the steps in NIST Special Publication (SP) 800-37, Risk Management Framework for Information Systems and Organizations" — FedRAMP authorizations for cloud services follow RMF's steps; FedRAMP does not describe itself as a separate cloud-specific variant of RMF, only as a process that follows its steps. Outside U.S. federal information systems, no obligation was identified in the sources reviewed as of 31 August 2026 — confirm against the relevant regulator or contracting authority.
Sources
- NIST CSRC — SP 800-37 Rev. 2 publication record ↗ — accessed
- NIST CSRC — About the RMF (7-step process) ↗ — accessed
- NIST CSRC Glossary — Authorizing Official ↗ — accessed
- NIST CSRC — Laws and Regulations: FISMA ↗ — accessed
- GovInfo — U.S. Code, 44 U.S.C. § 3554 (agency responsibilities) ↗ — accessed
- FedRAMP.gov — Authorization process (OMB M-24-15, Section IV) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.