NIST SP 800-37 Rev. 2 — Risk Management Framework (RMF)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
NIST SP 800-37 Revision 2, known as the Risk Management Framework (RMF), is a structured risk management approach that guides organizations in selecting, implementing, and continuously monitoring cybersecurity and privacy controls to manage system and organizational risks. The framework establishes a process for integrating security and privacy into the system development life cycle, supporting compliance and risk decision-making.
Published by the National Institute of Standards and Technology (NIST), the RMF is widely used by U.S. federal agencies, contractors, and organizations seeking to align with government cybersecurity requirements. It covers risk assessment, security control selection, implementation, assessment, authorization, and continuous monitoring to enhance the protection of information systems and data.
Organizations typically adopt the NIST RMF by incorporating its steps into their cybersecurity programs, mapping controls to NIST SP 800-53 or other standards, and supporting audit readiness. The framework enables consistent risk-informed decisions, effective compliance management, and integration with broader regulatory, security, and privacy ecosystems such as FISMA and FedRAMP.
Why it Matters
The NIST Risk Management Framework equips organizations with a systematic process to integrate security and privacy throughout the system lifecycle.
Key benefits include:
- Strengthen risk-based decision-making
Enable more consistent, informed risk management choices aligned with organizational priorities and operational requirements.
- Enhance compliance support
Support adherence to government and industry regulations by establishing a defensible, repeatable approach to cybersecurity and privacy controls.
- Promote continuous monitoring
Facilitate ongoing assessment and mitigation of evolving threats by embedding monitoring practices in daily operations.
- Increase audit readiness
Document security activities and controls in a structured way that simplifies audits and demonstrates due diligence to stakeholders.
- Improve protection of sensitive data
Reduce the likelihood and impact of data breaches by applying controls tailored to protect critical assets and information.
How it Works
NIST SP 800-37 Rev. 2 establishes the Risk Management Framework (RMF) as a structured, iterative lifecycle process. The RMF integrates a set of steps—categorize information systems, select security controls, implement controls, assess effectiveness, authorize operations, and monitor controls—creating a continuous cycle for managing organizational risk. This framework directly references control catalogs, such as those in NIST SP 800-53, to support effective risk management and governance.
In practice, organizations apply the RMF by first classifying their assets and determining appropriate security controls based on risk assessments. Teams implement and document these controls, conduct security assessments to evaluate control effectiveness, and maintain compliance through ongoing authorization and monitoring activities. The RMF also facilitates alignment with broader governance programs and regulatory requirements by providing a repeatable structure for compliance assessments and ongoing oversight of security practices.
Organizations can operationalize the RMF using SmartSuite by leveraging integrated control libraries, maintaining dynamic risk registers, and automating policy governance processes. SmartSuite enables streamlined evidence collection, compliance tracking, and remediation workflows, supporting audit readiness and continuous monitoring. Reporting dashboards further allow security and compliance teams to evaluate risk management practices and monitor organizational security posture over time.
Key Elements
- System Development Life Cycle Integration
Establishes alignment of security and privacy risk processes within the organization’s system development methodology.
- Risk Assessment and Categorization
Describes categorization of information systems based on potential impact levels and initial risk analysis.
- Security and Privacy Control Selection
Specifies the process for identifying, tailoring, and documenting safeguards from established control baselines.
- Control Implementation Architecture
Outlines structured deployment and configuration of approved security and privacy measures within environments.
- Assessment and Validation Activities
Details mechanisms for evaluating control effectiveness through testing, review, and analysis.
- Authorization Process Structure
Defines formal procedures for system authorization based on assessed risks and compliance evidence.
- Continuous Monitoring Framework
Describes ongoing monitoring and reporting requirements to manage changes in risk posture over time.
Framework Scope
NIST SP 800-37 Rev. 2 — Risk Management Framework is implemented by federal agencies, government contractors, and organizations managing sensitive or regulated information systems. The framework governs risk management processes for IT systems and cloud environments, typically during regulatory compliance, system development, or when enhancing security governance and supporting assurance programs.
Framework Objectives
NIST SP 800-37 Rev. 2 Risk Management Framework (RMF) provides a comprehensive process for managing cybersecurity and privacy risks across information systems.
Enhance risk management practices to address evolving cybersecurity and privacy threats
Establish effective security controls to protect critical data and organizational assets
Strengthen governance and oversight of security and privacy program operations
Promote regulatory compliance through integration with federal and industry requirements
Improve operational resilience by enabling continuous monitoring and timely risk response
Support audit readiness with documented control assessment and risk management actions
Framework in Context
NIST SP 800-37 Rev. 2 (RMF) provides a risk-based authorization process that maps to controls in NIST SP 800-53 Rev. 5 and supports FedRAMP authorizations, while aligning with the NIST Cybersecurity Framework and ISO/IEC 27001 for governance. Organizations apply RMF for federal accreditation, regulatory compliance, risk governance, and operational security improvements.
Common Framework Mappings
Organizations map NIST SP 800-37 Rev. 2 to complementary standards and controls to streamline risk management, demonstrate compliance, and align security controls across governance, auditing, and cloud authorization programs.
Mapped frameworks include:
CIS Critical Security Controls
FedRAMP
ISO/IEC 27001
ISO/IEC 27002
ISO/IEC 27701
NIST Cybersecurity Framework
NIST SP 800-30
NIST SP 800-53 Rev. 5
- ClassificationCategoryRisk ManagementDomainRisk ManagementFramework FamilyNIST Special Publications
- Regulatory ContextTypeStandardLegal InstrumentFrameworkSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionNorth AmericaRegion DetailUnited StatesPublisherNational Institute of Standards and Technology (NIST)
- VersioningVersionNIST SP 800-37 Revision 2Effective DateDecember 2018Issue DateDecember 2018
- AdoptionAdoption ModelRisk ManagementImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
NIST SP 800-37 is published by the National Institute of Standards and Technology and is publicly available through official NIST publications.
How SmartSuite Supports NIST 800-37 rev 2
Centralize controls, evidence, and audit workflows to stay continuously SOC 2–ready.
RMF Step Library
Run Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor as connected work.
System Boundary and Scope Management
Define system scope, assets, and dependencies with clear traceability.
SSP and Control Implementation Statements
Maintain SSP content and evidence tied directly to control requirements.
Assessments and POA&Ms
Track findings, remediation actions, owners, retesting, and closure evidence.
Continuous Monitoring Cadence
Schedule recurring monitoring tasks and maintain repeatable evidence over time.
Authorization and Governance Reporting
Produce leadership-ready status reporting for ATO decisions and ongoing oversight.
Related frameworks

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

FedRAMP standardizes security requirements to assess, authorize, and continuously monitor cloud services that handle U.S. federal data.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

ISO/IEC 27701 extends ISO/IEC 27001 to help organizations manage privacy and protect personally identifiable information.
Frequently Asked Questions For NIST SP 800-37 Rev. 2 (Risk Management Framework)
The NIST SP 800-37 RMF provides a structured methodology for organizations to manage risks to their information systems by selecting, implementing, and monitoring cybersecurity and privacy controls. It supports organizations in making informed risk decisions and helps align security practices with organizational objectives and regulatory requirements.
The RMF applies to all federal information systems, including those operated by contractors on behalf of agencies, and can be adapted by non-federal organizations. Its scope covers categorizing systems, selecting and implementing controls, assessing their effectiveness, authorizing systems for operation, and maintaining continuous oversight.
Key concepts of the RMF include system categorization, control selection, implementation, assessment, authorization, and continuous monitoring. Required artifacts typically include system security plans, risk assessments, security assessment reports, plans of action and milestones (POA&Ms), and authorization packages.
Organizations integrate the RMF into their system development lifecycle by classifying systems, conducting risk assessments, mapping applicable controls (often from NIST SP 800-53), and documenting implementation. Regular assessments are conducted to evaluate control effectiveness, with ongoing monitoring to ensure sustained compliance and risk mitigation.
NIST SP 800-37 RMF aligns closely with frameworks such as NIST SP 800-53 (control catalog), FISMA (regulatory requirement), and FedRAMP (cloud authorization). It can also be mapped to broader governance programs and privacy regulations, supporting harmonization of security practices across multiple compliance obligations.
Ongoing RMF compliance requires continuous monitoring of controls, regular risk assessments, timely remediation of identified weaknesses, and maintenance of up-to-date security documentation. Organizations must provide evidence of ongoing oversight and take corrective actions to address new risks or changes in their threat landscape.
SmartSuite supports RMF management by centralizing risk tracking, facilitating control selection and implementation, and enabling streamlined evidence collection for compliance assessments. The platform provides automated compliance tracking, audit readiness workflows, and reporting dashboards to monitor risk posture and demonstrate ongoing adherence to RMF requirements.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.
