NIST SP 800-37

E532552

NIST SP 800-37 is a key NIST cybersecurity guideline that defines the Risk Management Framework (RMF) for managing information security and privacy risk in federal information systems.

All labels observed (7)

How this entity was disambiguated

Statements (46)

Predicate Object
instanceOf NIST Special Publication
cybersecurity guideline
risk management framework document
alignsWith FISMA requirements
NIST Cybersecurity Framework
NIST SP 800-53
alsoKnownAs RMF 2.0
appliesTo federal agencies
federal information systems
author National Institute of Standards and Technology
countryOfOrigin United States
defines Risk Management Framework
expandsScopeTo organizations
focusesOn managing information security risk
managing privacy risk
frameworkName Risk Management Framework
integrates cybersecurity risk management
privacy risk management
language English
objective improve information security posture of federal systems
integrate risk management into system life cycle
provides guidance for continuous monitoring
guidance for system authorization
publicationYear 2010
2018
publisher National Institute of Standards and Technology
relatedTo NIST SP 800-30
NIST SP 800-39
NIST SP 800-53A
linked to: NIST SP 800-53
replacedBy NIST SP 800-37 Revision 2
linked to: NIST SP 800-37
series NIST Special Publication 800-series
linked to: NIST SP 800 series
step Assess
Authorize
Categorize
Implement
Monitor
Prepare
Select
subject information security risk management
privacy risk management
title Guide for Applying the Risk Management Framework to Federal Information Systems
linked to: NIST SP 800-37

Guide for Applying the Risk Management Framework to Federal Information Systems and Organizations
linked to: NIST SP 800-37
usedBy U.S. federal agencies
usedFor authorization to operate decisions
version Revision 1
Revision 2

How these facts were elicited

Referenced by (15)

Full triples — surface form annotated when it differs from this entity's canonical label.

Special Publications hasPart NIST SP 800-37
Army cybersecurity operations policy alignedWith DoD Risk Management Framework
linked to: NIST SP 800-37
NIST SP 800 series includes NIST SP 800-37
NIST SP 800-30 relatedTo NIST SP 800-37
NIST SP 800-37 title Guide for Applying the Risk Management Framework to Federal Information Systems
linked to: NIST SP 800-37
NIST SP 800-37 Revision 1 replacedBy NIST SP 800-37 Revision 2
subject linked to: NIST SP 800-37
linked to: NIST SP 800-37
NIST SP 800-37 Revision 2 title Guide for Applying the Risk Management Framework to Federal Information Systems and Organizations
subject linked to: NIST SP 800-37
linked to: NIST SP 800-37
NIST SP 800-171 relatedTo NIST SP 800-37
NIST SP 800-115 relatedTo NIST SP 800-37
NIST SP 800-160 alignsWith NIST SP 800-37
NIST SP 800-39 relatedTo NIST SP 800-37
NIST SP 800-60 relatedTo NIST SP 800-37
NIST SP 800-190 relatedTo NIST SP 800-37
NIST Risk Management Framework definedIn NIST Special Publication 800-37 Revision 2
linked to: NIST SP 800-37
NIST Risk Management Framework previouslyDefinedIn NIST Special Publication 800-37 Revision 1
linked to: NIST SP 800-37