Terminology Index
Glossary
1801 terms
Showing 1057-1088 of 1801 terms
NIST RMF
The NIST Risk Management Framework: a structured process (categorize, select, implement, assess, authorize, monitor) for managing security and privacy risk for systems, widely used in US federal government and influential more broadly.
The NIST RMF (SP 800-37) lays out a repeatable process for managing system-level risk: categorize the system and information, select controls (often from SP 800-53), implement them, assess their effectiveness, authorize the system to operate, and monitor continuously. It is mandatory in much US federal practice and widely referenced. As a risk-management framework, it offers an alternative to ISO 31000's generic process, focused on systems and controls, and it underpins related programs like FedRAMP authorization.
Introduced in: Risk Management Fundamentals
Examples
- Following categorize, select, implement, assess, authorize, monitor for a system.
- Selecting NIST 800-53 controls during the RMF select step.
- Authorizing a federal system to operate after RMF assessment.
No related terms linked yet.
