Skip to main content
Category: Risk Management

NIST SP 800-37

Also known as: RMF, NIST Special Publication 800-37, SP 800-37 Rev. 2, Risk Management Framework for Information Systems and Organizations, Risk Management Framework
Simply put

NIST SP 800-37 is a U.S. government publication that describes the Risk Management Framework (RMF), a structured process for identifying, assessing, and managing security and privacy risk in information systems throughout their life cycle. Rather than being a ready-made checklist, it provides a methodology that an organization applies to build and operate its own risk management program. Its current version, Revision 2, takes a system life cycle approach and incorporates both security and privacy considerations.

Formal definition

NIST Special Publication 800-37, Revision 2, titled "Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach," defines the Risk Management Framework (RMF) as a disciplined, structured, and repeatable process for applying risk management activities to information systems and organizations. It provides guidelines for executing RMF steps and tasks across the system development life cycle, integrating security and privacy risk management, and aligning system planning with those steps and tasks. Revision 2 broadens the scope of system planning and emphasizes the use of machine-readable data to support automation. As a methodology rather than a prescriptive control set, it directs how an organization structures its risk management program; the framework itself does not constitute a completed program, and its effective application depends on organizational adoption, tailoring, and supporting NIST publications for controls and assessment.

Why it matters

NIST SP 800-37 matters because it establishes a common, disciplined methodology for how organizations structure risk management around their information systems rather than leaving each team to improvise its own approach. For federal agencies and the contractors that serve them, the Risk Management Framework it describes is a foundational reference point, and its influence extends into private-sector programs that adopt NIST guidance voluntarily. Because it takes a system life cycle approach and integrates both security and privacy risk, it gives leaders a repeatable process to follow from system planning through ongoing operation, which supports consistency and defensibility in how risk decisions are made.

Its significance also lies in what it deliberately is not. As the evidence indicates, SP 800-37 is a methodology for building a risk management program, not a ready-made program or a checklist an organization can simply complete and set aside. This distinction is often where value is gained or lost: adopting the RMF requires organizational commitment, tailoring to the specific system context, and reliance on supporting NIST publications for the actual controls and assessment procedures. A security leader who treats the framework as a finished deliverable rather than a structure to be applied will typically find the effort produces documentation without meaningfully reducing risk.

For organizations weighing security leadership options, understanding SP 800-37 clarifies where advisory work ends and organizational accountability begins. A virtual or fractional CISO can direct how the RMF is adopted, tailored, and integrated into a program, but the decisions the framework surfaces about accepting or mitigating risk generally remain the accountability of the client organization and its officers. The framework structures those decisions; it does not make them or absorb the responsibility for them.

Who it's relevant to

Federal agencies and government contractors
SP 800-37 was authored as U.S. government guidance and is a primary reference for structuring risk management around information systems in federal and federally aligned environments. Organizations operating in this space typically encounter the RMF as the expected methodology for organizing their security and privacy risk processes across the system life cycle.
Virtual and fractional CISOs advising on program structure
A virtual or fractional CISO can use SP 800-37 to help a client establish, tailor, and integrate a risk management program that follows the RMF's steps and tasks. The advisory role centers on directing how the methodology is adopted and applied; the underlying risk acceptance and mitigation decisions the framework surfaces generally remain the accountability of the client organization and its officers rather than the advisor.
Security and privacy leaders integrating both disciplines
Because Revision 2 integrates security and privacy risk management and takes a system life cycle approach, leaders responsible for both areas can use it as a common structure. It is most useful where the organization is prepared to adopt the methodology fully, tailor it to its systems, and rely on supporting NIST publications for the actual controls and assessments.
Organizations planning or modernizing systems
Revision 2 broadens the scope of system planning and aligns plan development with the RMF's steps and tasks, so teams standing up or updating information systems can use it to structure risk considerations from the planning stage forward. Its emphasis on machine-readable data also makes it relevant to organizations pursuing automation in their risk management processes.

Inside RMF

Prepare step
Activities carried out at both the organization and system level to establish context, roles, risk tolerance, and priorities before applying the rest of the framework. This step was emphasized to improve the effectiveness and efficiency of subsequent RMF activities.
Categorize step
Determining the impact level of an information system based on the potential effect on confidentiality, integrity, and availability, typically drawing on standards such as FIPS 199. This informs how rigorous the safeguards need to be.
Select step
Choosing an appropriate set of security and privacy controls, commonly referencing the control catalog in NIST SP 800-53, and tailoring them to the system and organizational risk context.
Implement step
Putting the selected controls into place and documenting how they are deployed. This step involves hands-on technical work that typically falls outside a virtual CISO's advisory scope unless explicitly contracted.
Assess step
Evaluating whether implemented controls are operating as intended and producing the desired outcomes, often using assessment procedures aligned with NIST SP 800-53A.
Authorize step
A senior official (the authorizing official) formally accepting the residual risk and granting permission for a system to operate. This decision reflects organizational accountability that generally remains with client officers rather than an external advisor.
Monitor step
Continuously tracking the security and privacy posture of the system, the effectiveness of controls, and changes in the risk environment to support ongoing, informed authorization decisions.
Integration with related publications
SP 800-37 does not operate in isolation; it works alongside companion documents such as FIPS 199/200, SP 800-53, and SP 800-53A to provide categorization, control selection, and assessment guidance.

Common questions

Answers to the questions practitioners most commonly ask about RMF.

Does adopting NIST SP 800-37 mean my organization is automatically compliant or certified?
No. NIST SP 800-37 describes a Risk Management Framework (RMF) process for authorizing and continuously monitoring information systems; it is a process guide, not a certification. Following it can support a structured approach to risk decisions, but it does not by itself confer compliance with any regulation or produce a certification. Compliance and any attestation still depend on the applicable authority, the completeness of implementation, and independent assessment where required.
Can a virtual CISO simply run NIST SP 800-37 and take on accountability for our authorization decisions?
Generally no. A virtual CISO can advise on and help structure the RMF steps, guide preparation, and support the roles the framework describes, but the authorization decision and the associated organizational and legal accountability typically remain with the client's designated officials, such as an authorizing official within the client organization. Accountability shifts to a vCISO only if a specific contract explicitly assigns it, which is uncommon.
Where does a virtual CISO typically add value within a NIST SP 800-37 effort, and what usually stays out of scope?
In many engagements a vCISO provides governance direction, helps define roles and risk tolerance, oversees the overall RMF approach, and advises on prioritization and stakeholder alignment. Hands-on operational tasks such as configuring controls, running scans, or performing continuous monitoring tooling are often out of scope unless explicitly contracted. The division of labor should be defined in the engagement scope.
How does organizational maturity affect an RMF implementation supported by a vCISO?
Engagement value often depends heavily on maturity. Organizations with defined system inventories, documented processes, and available stakeholders can typically move through the RMF steps more efficiently. Where inventories, ownership, or data are incomplete, more foundational work is usually needed first, and progress depends on client cooperation and access to the people who own the systems and risk decisions.
What stakeholder access does a vCISO typically need to advance an RMF process effectively?
Effective support generally requires access to system owners, technical teams, risk and compliance staff, and the officials who make authorization decisions. Because the RMF process involves categorizing systems, selecting and assessing controls, and making risk-based authorization decisions, limited access to these stakeholders often constrains the depth and accuracy of the work.
How can a vCISO help maintain the continuous monitoring aspect of the RMF over time?
A vCISO can advise on establishing ongoing monitoring expectations, cadence for reassessing risk, and processes for reporting changes to authorizing officials. Whether the vCISO also oversees execution or leaves operational monitoring to internal teams or other providers varies by engagement and should be specified in scope. The continuous nature of the framework means sustained client involvement is typically required rather than a one-time effort.

Common misconceptions

Following NIST SP 800-37 automatically makes an organization compliant or certified.
SP 800-37 is a risk management process framework, not a certification. Applying it can support readiness and structured risk decisions, but it does not by itself guarantee compliance with any specific regulation or produce a certification. A virtual CISO can help an organization use it to support readiness while accountability for outcomes remains with the client.
SP 800-37 is only relevant to U.S. federal agencies.
While it originated in and is closely associated with the U.S. federal authorization-to-operate process, its underlying risk-based, lifecycle principles are also referenced by private-sector organizations that want a structured approach to managing security and privacy risk.
A virtual CISO who references SP 800-37 will execute all seven steps hands-on and take on authorization accountability.
A virtual CISO typically provides strategy, governance, and guidance on applying the framework. Hands-on implementation and the formal authorization decision usually remain client responsibilities; legal and organizational accountability generally stays with the client organization and its officers unless a contract specifies otherwise.

Best practices

Treat the Prepare step as foundational, establishing organizational risk tolerance, roles, and priorities before attempting to categorize systems or select controls, since the value of later steps often depends on this groundwork.
Use the Categorize step to align the rigor of controls with actual system impact, avoiding both over-engineering low-impact systems and under-protecting critical ones.
Clearly document who holds the authorizing official role and the associated accountability, and confirm in engagement scope that a virtual CISO advises on rather than assumes this decision.
Coordinate control selection and assessment with companion NIST publications such as SP 800-53 and SP 800-53A rather than treating SP 800-37 as a standalone control list.
Define in the engagement contract which RMF steps are advisory versus which involve hands-on implementation, since implementation tasks typically fall outside a virtual CISO's default scope.
Invest in the Monitor step so that authorization decisions reflect current conditions, recognizing that the framework's effectiveness depends on continued client cooperation and stakeholder access over time.