NIST SP 800-37
NIST SP 800-37 is a U.S. government publication that describes the Risk Management Framework (RMF), a structured process for identifying, assessing, and managing security and privacy risk in information systems throughout their life cycle. Rather than being a ready-made checklist, it provides a methodology that an organization applies to build and operate its own risk management program. Its current version, Revision 2, takes a system life cycle approach and incorporates both security and privacy considerations.
NIST Special Publication 800-37, Revision 2, titled "Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach," defines the Risk Management Framework (RMF) as a disciplined, structured, and repeatable process for applying risk management activities to information systems and organizations. It provides guidelines for executing RMF steps and tasks across the system development life cycle, integrating security and privacy risk management, and aligning system planning with those steps and tasks. Revision 2 broadens the scope of system planning and emphasizes the use of machine-readable data to support automation. As a methodology rather than a prescriptive control set, it directs how an organization structures its risk management program; the framework itself does not constitute a completed program, and its effective application depends on organizational adoption, tailoring, and supporting NIST publications for controls and assessment.
Why it matters
NIST SP 800-37 matters because it establishes a common, disciplined methodology for how organizations structure risk management around their information systems rather than leaving each team to improvise its own approach. For federal agencies and the contractors that serve them, the Risk Management Framework it describes is a foundational reference point, and its influence extends into private-sector programs that adopt NIST guidance voluntarily. Because it takes a system life cycle approach and integrates both security and privacy risk, it gives leaders a repeatable process to follow from system planning through ongoing operation, which supports consistency and defensibility in how risk decisions are made.
Its significance also lies in what it deliberately is not. As the evidence indicates, SP 800-37 is a methodology for building a risk management program, not a ready-made program or a checklist an organization can simply complete and set aside. This distinction is often where value is gained or lost: adopting the RMF requires organizational commitment, tailoring to the specific system context, and reliance on supporting NIST publications for the actual controls and assessment procedures. A security leader who treats the framework as a finished deliverable rather than a structure to be applied will typically find the effort produces documentation without meaningfully reducing risk.
For organizations weighing security leadership options, understanding SP 800-37 clarifies where advisory work ends and organizational accountability begins. A virtual or fractional CISO can direct how the RMF is adopted, tailored, and integrated into a program, but the decisions the framework surfaces about accepting or mitigating risk generally remain the accountability of the client organization and its officers. The framework structures those decisions; it does not make them or absorb the responsibility for them.
Who it's relevant to
Inside RMF
Common questions
Answers to the questions practitioners most commonly ask about RMF.