NIST Special Publication (SP) 800-37 Rev. 2 (Withdrawn), Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy (2024)

    Publications

NIST SP 800-37 Rev. 2 (Initial Public Draft)

Obsoleted on October 02, 2018 by SP 800-37 Rev. 2 (Final Public Draft)

Documentation Topics

Date Published: May 2018
Comments Due: June 22, 2018 (public comment period is CLOSED)
Email Questions to: sec-cert@nist.gov

Planning Note (05/25/2018): See the current publishing schedule.

Author(s)

Joint Task Force

Announcement

This update to NIST Special Publication 800-37 (Revision 2) responds to the call by the Defense Science Board, Executive Order 13800, and OMB Memorandum M-17-25 to develop the next-generation Risk Management Framework (RMF) for information systems, organizations, and individuals.

There are seven major objectives for this update:

  • Provide closer linkage and communication between the risk management processes and activities at the C-suite or governance level of the organization and the individuals, processes, and activities at the system and operational level of the organization;
  • Institutionalize critical organization-wide risk management preparatory activities to facilitate a more effective, efficient, and cost-effective execution of the RMF;
  • Demonstrate how the Cybersecurity Framework can be aligned with the RMF and implemented using established NIST risk management processes;
  • Integrate privacy risk management concepts and principles into the RMF and support the use of the consolidated security and privacy control catalog in NIST Special Publication 800-53Revision 5;
  • Promote the development of trustworthy secure software and systems by aligning life cycle-based systems engineering processes in NIST Special Publication 800-160 with the steps in the RMF;
  • Integrate supply chain risk management (SCRM) concepts into the RMF to protect against untrustworthy suppliers, insertion of counterfeits, tampering, unauthorized production, theft, insertion of malicious code, and poor manufacturing and development practices throughout the SDLC; and
  • Provide an alternative organization-generated control selection approach to complement the traditional baseline control selection approach.

A public comment period for this draft document is open until June 22, 2018.

Abstract

This publication provides guidelines for applying the Risk Management Framework (RMF) to information systems and organizations. The RMF includes a disciplined, structured, and flexible process for organizational asset valuation; control selection, implementation, and assessment; system and common control authorizations; and continuous monitoring. It also includes activities to help prepare organizations to execute the RMF at the information system level. The RMF promotes the concept of near real-time risk management and ongoing system and common control authorization through the implementation of continuous monitoring processes; provides senior leaders and executives with the necessary information to make efficient, cost-effective, risk management decisions about the systems supporting their missions and business functions; and integrates security and privacy into the system development life cycle. Executing the RMF tasks enterprise-wide helps to link essential risk management processes at the system level to risk management processes at the organization level. In addition, it establishes responsibility and accountability for the controls implemented in organizational information systems and inherited by those systems. The RMF incorporates concepts from the Framework for Improving Critical Infrastructure Cybersecurity that complement the well-established risk management processes mandated by the Office of Management and Budget and the Federal Information Security Modernization Act.

This publication provides guidelines for applying the Risk Management Framework (RMF) to information systems and organizations. The RMF includes a disciplined, structured, and flexible process for organizational asset valuation; control selection, implementation, and assessment; system and common... See full abstract

Keywords

assess; authorization to operate; common control authorization; authorization to use; authorizing official; categorize; common control; common control provider; continuous monitoring; control baseline; hybrid control; information owner or steward; monitor; ongoing authorization; plan of action and milestones; privacy assessment report; privacy control; privacy plan; privacy risk; profile; risk assessment; risk executive function; risk management; risk management framework; security assessment report; security control; security plan; security risk; senior agency official for privacy; senior agency information security officer; senior agency official for privacy; supply chain risk management; system development life cycle; system owner; system privacy officer; system security officer

Control Families

Assessment, Authorization and Monitoring; Configuration Management; Planning; Program Management; Risk Assessment

Documentation

Publication:
Draft SP 800-37 Rev. 2 (pdf)

Supplemental Material:
Draft, with line numbers (pdf)
Mark-up Copy of Draft SP 800-37 Rev. 2 (pdf)
Comment template (xlsx)
Presentation: RMF 2.0 (introduces the initial public draft) (pdf)
NIST Press Release

Related NIST Publications:
SP 800-53 Rev. 5 (Draft)

Document History:
09/28/17: SP 800-37 Rev. 2 (Draft)
05/09/18: SP 800-37 Rev. 2 (Draft)
10/02/18: SP 800-37 Rev. 2 (Draft)
12/20/18: SP 800-37 Rev. 2 (Final)

Topics

Security and Privacy

, continuous monitoring, controls, planning, risk assessment

Applications

cybersecurity framework

Laws and Regulations

Executive Order 13800, Federal Information Security Modernization Act, Homeland Security Presidential Directive 7, OMB Circular A-130

NIST Special Publication (SP) 800-37 Rev. 2 (Withdrawn), Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy (2024)

References

Top Articles
Quest Diagnostics Mt Morris Appointment
Novant Mychart Nhrmc
Huggies Size 4 Walgreens
Tiffany's Breakfast Portage
Fone Tech Cleveland Ms
NYC Drilled on Variant Response as Vaccine Limits Push State Appointments to Mid-April
Scoped Courses - Bruiser Industries
What Does Purge Mods Do In Vortex
Iowa Image Trend
Half Inning In Which The Home Team Bats Crossword
Craigslist Hoosick Falls
Uga Im Leagues
Hyb Urban Dictionary
Dtm Urban Dictionary
Volstate Portal
What’s Closing at Disney World? A Complete Guide
Tani Ahrefs
Cal Poly San Luis Obispo Catalog
Diabetes Care - Horizon Blue Cross Blue Shield of New Jersey
Jennifer Beals Bikini
Alamy Contributor Forum
Eurail Pass Review: Is It Worth the Price?
Dna Profiling Virtual Lab Answer Key
Pioneer Justice Court Case Lookup
Between Friends Comic Strip Today
Ansos Umm
Paul Mauro Bio
Withers Not In Sarcophagus
Waifu Fighter F95
Chihuahua Adoption in Las Vegas, NV: Chihuahua Puppies for Sale in Las Vegas, NV - Adoptapet.com
Paola Iezzi, chi è il compagno. L’uomo in comune con la sorella Chiara e le nozze 'congelate'
Tyrone Unblocked Games Bitlife
Charm City Kings 123Movies
Walgreens Pharmacy On Jennings Station Road
2010 Ford F-350 Super Duty XLT for sale - Wadena, MN - craigslist
Goodwill Southern California Store & Donation Center Montebello Photos
Mercy Baggot Street Mypay
Sloansmoans Many
No Hard Feelings Showtimes Near Pullman Village Centre Cinemas
Crandon Skyward
Melissa Bley Ken Griffin
Best Drugstore Bronzers
Call Of The Arbiter Code Chase Episode 3
水餃 家園
What Does the Bible Say About Christ In Me?
Fapello.ckm
Rubrankings Austin
World of Warcraft Battle for Azeroth: La Última Expansión de la Saga - EjemplosWeb
Craigslist Farm And Garden Lexington
Usps Passport Appointment Confirmation
Omgekeerd zoeken op telefoonnummer | Telefoonboek.nl
Milly Bobby Brown Nsfw
Latest Posts
Article information

Author: Merrill Bechtelar CPA

Last Updated:

Views: 6320

Rating: 5 / 5 (50 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Merrill Bechtelar CPA

Birthday: 1996-05-19

Address: Apt. 114 873 White Lodge, Libbyfurt, CA 93006

Phone: +5983010455207

Job: Legacy Representative

Hobby: Blacksmithing, Urban exploration, Sudoku, Slacklining, Creative writing, Community, Letterboxing

Introduction: My name is Merrill Bechtelar CPA, I am a clean, agreeable, glorious, magnificent, witty, enchanting, comfortable person who loves writing and wants to share my knowledge and understanding with you.