Back to library
Cybersecurity · Issued by National Institute of Standards and Technology

NIST RMF

NIST Risk Management Framework (SP 800-37)

NISTCyberFederalControls
Compare NIST RMF with

Seven-step process for managing information security and privacy risk for federal systems — and the cyber lingua-franca for everyone else.

Prepare → Categorize → Select → Implement → Assess → Authorize → Monitor. Pairs directly with NIST SP 800-53 controls and the NIST CSF. The default cyber risk framework for US federal agencies and contractors.

At a glance

Complexity
High
Certification
FedRAMP / ATO
Time to implement
6–18 months
Issued by
National Institute of Standards and Technology

Fits

Industries
itgovernmenthealthcarebankingaviation
Risk types
cybercomplianceoperational
Frequently asked

Questions risk leaders ask

A seven-step lifecycle process (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor) for managing cybersecurity and privacy risk in federal information systems and organizations.
Related on RiskPedia

Frameworks & regulations frequently referenced together

See if it fits you

Run the Finder to get a personalised match score for NIST RMF.

Made with Emergent