Risk Management
DETAIL

NIST SP 800-37 Rev. 2 — Risk Management Framework (RMF)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

arrow_back
arrow_forward

Overview

NIST SP 800-37 Revision 2, known as the Risk Management Framework (RMF), is a structured risk management approach that guides organizations in selecting, implementing, and continuously monitoring cybersecurity and privacy controls to manage system and organizational risks. The framework establishes a process for integrating security and privacy into the system development life cycle, supporting compliance and risk decision-making.

Published by the National Institute of Standards and Technology (NIST), the RMF is widely used by U.S. federal agencies, contractors, and organizations seeking to align with government cybersecurity requirements. It covers risk assessment, security control selection, implementation, assessment, authorization, and continuous monitoring to enhance the protection of information systems and data.

Organizations typically adopt the NIST RMF by incorporating its steps into their cybersecurity programs, mapping controls to NIST SP 800-53 or other standards, and supporting audit readiness. The framework enables consistent risk-informed decisions, effective compliance management, and integration with broader regulatory, security, and privacy ecosystems such as FISMA and FedRAMP.

Why it Matters

The NIST Risk Management Framework equips organizations with a systematic process to integrate security and privacy throughout the system lifecycle.

Key benefits include:

  • Strengthen risk-based decision-making

Enable more consistent, informed risk management choices aligned with organizational priorities and operational requirements.

  • Enhance compliance support

Support adherence to government and industry regulations by establishing a defensible, repeatable approach to cybersecurity and privacy controls.

  • Promote continuous monitoring

Facilitate ongoing assessment and mitigation of evolving threats by embedding monitoring practices in daily operations.

  • Increase audit readiness

Document security activities and controls in a structured way that simplifies audits and demonstrates due diligence to stakeholders.

  • Improve protection of sensitive data

Reduce the likelihood and impact of data breaches by applying controls tailored to protect critical assets and information.

How it Works

NIST SP 800-37 Rev. 2 establishes the Risk Management Framework (RMF) as a structured, iterative lifecycle process. The RMF integrates a set of steps—categorize information systems, select security controls, implement controls, assess effectiveness, authorize operations, and monitor controls—creating a continuous cycle for managing organizational risk. This framework directly references control catalogs, such as those in NIST SP 800-53, to support effective risk management and governance.

In practice, organizations apply the RMF by first classifying their assets and determining appropriate security controls based on risk assessments. Teams implement and document these controls, conduct security assessments to evaluate control effectiveness, and maintain compliance through ongoing authorization and monitoring activities. The RMF also facilitates alignment with broader governance programs and regulatory requirements by providing a repeatable structure for compliance assessments and ongoing oversight of security practices.

Organizations can operationalize the RMF using SmartSuite by leveraging integrated control libraries, maintaining dynamic risk registers, and automating policy governance processes. SmartSuite enables streamlined evidence collection, compliance tracking, and remediation workflows, supporting audit readiness and continuous monitoring. Reporting dashboards further allow security and compliance teams to evaluate risk management practices and monitor organizational security posture over time.

Key Elements

  • System Development Life Cycle Integration

Establishes alignment of security and privacy risk processes within the organization’s system development methodology.

  • Risk Assessment and Categorization

Describes categorization of information systems based on potential impact levels and initial risk analysis.

  • Security and Privacy Control Selection

Specifies the process for identifying, tailoring, and documenting safeguards from established control baselines.

  • Control Implementation Architecture

Outlines structured deployment and configuration of approved security and privacy measures within environments.

  • Assessment and Validation Activities

Details mechanisms for evaluating control effectiveness through testing, review, and analysis.

  • Authorization Process Structure

Defines formal procedures for system authorization based on assessed risks and compliance evidence.

  • Continuous Monitoring Framework

Describes ongoing monitoring and reporting requirements to manage changes in risk posture over time.

Framework Scope

NIST SP 800-37 Rev. 2 — Risk Management Framework is implemented by federal agencies, government contractors, and organizations managing sensitive or regulated information systems. The framework governs risk management processes for IT systems and cloud environments, typically during regulatory compliance, system development, or when enhancing security governance and supporting assurance programs.

Framework Objectives

NIST SP 800-37 Rev. 2 Risk Management Framework (RMF) provides a comprehensive process for managing cybersecurity and privacy risks across information systems.

Enhance risk management practices to address evolving cybersecurity and privacy threats

Establish effective security controls to protect critical data and organizational assets

Strengthen governance and oversight of security and privacy program operations

Promote regulatory compliance through integration with federal and industry requirements

Improve operational resilience by enabling continuous monitoring and timely risk response

Support audit readiness with documented control assessment and risk management actions

Framework in Context

NIST SP 800-37 Rev. 2 (RMF) provides a risk-based authorization process that maps to controls in NIST SP 800-53 Rev. 5 and supports FedRAMP authorizations, while aligning with the NIST Cybersecurity Framework and ISO/IEC 27001 for governance. Organizations apply RMF for federal accreditation, regulatory compliance, risk governance, and operational security improvements.

Common Framework Mappings

Organizations map NIST SP 800-37 Rev. 2 to complementary standards and controls to streamline risk management, demonstrate compliance, and align security controls across governance, auditing, and cloud authorization programs.

Mapped frameworks include:

CIS Critical Security Controls

FedRAMP

ISO/IEC 27001

ISO/IEC 27002

ISO/IEC 27701

NIST Cybersecurity Framework

NIST SP 800-30

NIST SP 800-53 Rev. 5

At a Glance
NIST SP 800-37 Rev.2 – RMF
  • checklist
    Classification
    Category
    info
    Risk Management
    Domain
    info
    Risk Management
    Framework Family
    info
    NIST Special Publications
  • info
    Regulatory Context
    Type
    info
    Standard
    Legal Instrument
    info
    Framework
    Sector
    info
    Cross-Sector
    Industry
    info
    Cross-Industry
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    North America
    Region Detail
    info
    United States
    Publisher
    info
    National Institute of Standards and Technology (NIST)
  • published_with_changes
    Versioning
    Version
    info
    NIST SP 800-37 Revision 2
    Effective Date
    info
    December 2018
    Issue Date
    info
    December 2018
  • graph_3
    Adoption
    Adoption Model
    info
    Risk Management
    Implementation Complexity
    info
    High
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

NIST SP 800-37 is published by the National Institute of Standards and Technology and is publicly available through official NIST publications.

Official Resources
NIST Special Publication 800-37 Revision 2
Defines the Risk Management Framework for selecting and implementing cybersecurity controls.
chevron_forward
NIST Risk Management Framework Overview
Outlines the integration of security and privacy into the system development life cycle.
chevron_forward
NIST RMF Quick Start Guide
Provides guidance on starting with the Risk Management Framework implementation.
chevron_forward
NIST SP 800-53 Security Controls
Describes the security and privacy controls for federal information systems and organizations.
chevron_forward
SMARTSUITE

How SmartSuite Supports NIST 800-37 rev 2

Centralize controls, evidence, and audit workflows to stay continuously SOC 2–ready.

RMF Step Library

Run Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor as connected work.

System Boundary and Scope Management

Define system scope, assets, and dependencies with clear traceability.

SSP and Control Implementation Statements

Maintain SSP content and evidence tied directly to control requirements.

Assessments and POA&Ms

Track findings, remediation actions, owners, retesting, and closure evidence.

Continuous Monitoring Cadence

Schedule recurring monitoring tasks and maintain repeatable evidence over time.

Authorization and Governance Reporting

Produce leadership-ready status reporting for ATO decisions and ongoing oversight.

Related frameworks

CIS Controls v8.1

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

Learn More
arrow_forward
FedRAMP Rev. 5

FedRAMP standardizes security requirements to assess, authorize, and continuously monitor cloud services that handle U.S. federal data.

Learn More
arrow_forward
ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

Learn More
arrow_forward
ISO 27002:2022

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

Learn More
arrow_forward
ISO 27701

ISO/IEC 27701 extends ISO/IEC 27001 to help organizations manage privacy and protect personally identifiable information.

Learn More
arrow_forward
NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

Learn More
arrow_forward
NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For NIST SP 800-37 Rev. 2 (Risk Management Framework)

What is the NIST SP 800-37 Risk Management Framework (RMF) used for?

The NIST SP 800-37 RMF provides a structured methodology for organizations to manage risks to their information systems by selecting, implementing, and monitoring cybersecurity and privacy controls. It supports organizations in making informed risk decisions and helps align security practices with organizational objectives and regulatory requirements.

What is the scope of NIST SP 800-37 RMF in practice?

The RMF applies to all federal information systems, including those operated by contractors on behalf of agencies, and can be adapted by non-federal organizations. Its scope covers categorizing systems, selecting and implementing controls, assessing their effectiveness, authorizing systems for operation, and maintaining continuous oversight.

What are the key concepts and required artifacts of the RMF process?

Key concepts of the RMF include system categorization, control selection, implementation, assessment, authorization, and continuous monitoring. Required artifacts typically include system security plans, risk assessments, security assessment reports, plans of action and milestones (POA&Ms), and authorization packages.

How is the NIST SP 800-37 RMF implemented in organizations?

Organizations integrate the RMF into their system development lifecycle by classifying systems, conducting risk assessments, mapping applicable controls (often from NIST SP 800-53), and documenting implementation. Regular assessments are conducted to evaluate control effectiveness, with ongoing monitoring to ensure sustained compliance and risk mitigation.

How does NIST SP 800-37 RMF relate to other cybersecurity frameworks or regulations?

NIST SP 800-37 RMF aligns closely with frameworks such as NIST SP 800-53 (control catalog), FISMA (regulatory requirement), and FedRAMP (cloud authorization). It can also be mapped to broader governance programs and privacy regulations, supporting harmonization of security practices across multiple compliance obligations.

What are the ongoing compliance requirements under the RMF?

Ongoing RMF compliance requires continuous monitoring of controls, regular risk assessments, timely remediation of identified weaknesses, and maintenance of up-to-date security documentation. Organizations must provide evidence of ongoing oversight and take corrective actions to address new risks or changes in their threat landscape.

How would SmartSuite support NIST SP 800-37 RMF?

SmartSuite supports RMF management by centralizing risk tracking, facilitating control selection and implementation, and enabling streamlined evidence collection for compliance assessments. The platform provides automated compliance tracking, audit readiness workflows, and reporting dashboards to monitor risk posture and demonstrate ongoing adherence to RMF requirements.

Operationalize NIST 800-37 Rev.2 with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

Schedule a Demo
chevron_forward
Demo Library
chevron_forward