NIST SP 800-37
NIST SP 800-37 is a publication from the National Institute of Standards and Technology (NIST) that describes the Risk Management Framework (RMF), a structured approach for managing security and privacy risk in information systems. It provides guidelines for applying the RMF across a system's life cycle rather than serving as a ready-made, off-the-shelf risk program. Organizations generally use it as a methodology to plan, assess, authorize, and monitor their systems.
NIST SP 800-37, currently in Revision 2 (2018), titled 'Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach,' is maintained by NIST and describes the RMF and guidelines for applying it to information systems and organizations. Revision 2 introduced comprehensive updates addressing both security and privacy, broadened the scope of system planning, aligned plan development with the RMF steps and tasks, and emphasized the use of machine-readable data. The RMF is a methodology for building a risk management program and is not itself a control catalog; practitioners typically pair it with related NIST guidance such as control baselines during implementation. Readers should verify the current revision and applicable agency tailoring against the official NIST source, as authorization under the RMF is generally time-bound and subject to continuous monitoring rather than permanent.
Why it matters
NIST SP 800-37 establishes the structured methodology that many federal agencies and their contractors use to manage security and privacy risk across a system's life cycle. Rather than functioning as a checklist or a control catalog, it defines how organizations plan, assess, authorize, and continuously monitor their information systems, giving disparate stakeholders a common process for making risk-based decisions. For defense and public sector practitioners, this matters because authorization decisions carry real accountability: an authorizing official accepts risk on behalf of the organization, and that decision must be grounded in a repeatable, documented process rather than ad hoc judgment.
A critical point that experts frequently emphasize is that authorization under the RMF is time-bound and subject to continuous monitoring, not a permanent status. Treating an Authority to Operate as a one-time achievement, or equating completion of the RMF process with being secure, misunderstands the framework's intent. The RMF is designed to sustain ongoing risk awareness across the system life cycle, so an organization that stops actively monitoring after authorization has effectively abandoned the methodology it claims to follow.
Revision 2, published in 2018, is significant because it broadened the framework's scope to integrate privacy risk alongside security risk, aligned system planning with the RMF steps and tasks, and emphasized the use of machine-readable data to support automation. Because control baselines, agency tailoring, and revisions change over time, practitioners should always confirm the current revision and any applicable agency-specific interpretations against the official NIST source before relying on it for compliance decisions.
Who it's relevant to
Inside RMF
Common questions
Answers to the questions practitioners most commonly ask about RMF.