NIST Risk Management Framework

E700396

The NIST Risk Management Framework is a structured, step-by-step process for integrating security, privacy, and risk management activities into the system development life cycle for U.S. federal information systems and organizations.

All labels observed (5)

How this entity was disambiguated

Statements (51)

Predicate Object
instanceOf U.S. federal government standard
information security framework
privacy risk management framework
risk management framework
abbreviation NIST RMF
alignedWith NIST Cybersecurity Framework
NIST Special Publication 800-53
linked to: NIST SP 800-53

NIST Special Publication 800-53A
appliesTo U.S. federal agencies
U.S. federal information systems
federal contractors handling federal information
information systems
countryOfOrigin United States
definedIn NIST Special Publication 800-37 Revision 2
linked to: NIST SP 800-37
developedBy National Institute of Standards and Technology
emphasizes continuous improvement
organizational risk tolerance
senior leadership accountability
focusesOn information security risk management
organizational risk management
privacy risk management
includesStep Assess
Authorize
Categorize
Implement
Monitor
Prepare
Select
integrates privacy activities
risk management activities
security activities
integratesWith system development life cycle
objective improve information system resilience
integrate risk management into SDLC
manage information security risk
manage privacy risk
promote near real-time risk management
previouslyDefinedIn NIST Special Publication 800-37 Revision 1
linked to: NIST SP 800-37
replaced NIST Certification and Accreditation process
supports continuous monitoring
ongoing authorization
risk-based decision making
system authorization
targetAudience authorizing officials
federal agency risk executives
information security officers
information system owners
privacy officers
uses control baselines
privacy controls
security controls

How these facts were elicited

Referenced by (19)

Full triples — surface form annotated when it differs from this entity's canonical label.

NIST SP 800 series supportsFramework NIST Risk Management Framework
Federal Information Security Management Act of 2002 basisFor NIST Risk Management Framework
NIST SP 800-30 supports NIST Risk Management Framework
NIST SP 800-37 defines Risk Management Framework
linked to: NIST Risk Management Framework
NIST SP 800-37 frameworkName Risk Management Framework
linked to: NIST Risk Management Framework
NIST SP 800-53 relatedTo NIST Risk Management Framework
NIST SP 800-61 relatedTo NIST Risk Management Framework
NIST SP 800-115 relatedTo NIST Risk Management Framework
NIST SP 800-160 alignsWith NIST Risk Management Framework
NIST SP 800-39 title Managing Information Security Risk: Organization, Mission, and Information System View
linked to: NIST Risk Management Framework
NIST SP 800-39 relatedTo NIST Risk Management Framework
NIST Risk Management Framework abbreviation NIST RMF
linked to: NIST Risk Management Framework
NIST Risk Management Framework replaced NIST Certification and Accreditation process
linked to: NIST Risk Management Framework
NIST SP 800-137 relatedTo NIST Risk Management Framework
NIST SP 800-207 relatedTo NIST Risk Management Framework
3PAO relatedTo NIST Risk Management Framework
FedRAMP High impact level alignedWith NIST Risk Management Framework
FedRAMP security controls alignedWith NIST Risk Management Framework