Reference note
NIST SP 800-37
The Risk Management Framework and its role in integrating security and privacy into the system development life cycle.
Overview
NIST Special Publication 800-37 describes the process for integrating security and risk management into the system development life cycle. It was written for federal information systems, but the general approach can be applied more broadly.
Revision 2 added Prepare as an overall step and organizes the Risk Management Framework into Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor.
Prepare
Prepare covers organization-level and system-level work needed before the rest of the Risk Management Framework can be applied effectively. It establishes priorities, responsibilities, risk tolerance, stakeholders, system boundaries, information types, and other context used by later steps.
Categorize
Categorize defines the criticality and sensitivity of an information system according to the worst potential impact on the mission or business.
- Analyze the system boundary and its components.
- Identify the information types associated with those components.
- Describe each information type's function, type, name, and connections.
- Use the highest confidentiality, integrity, or availability impact as the system's overall impact level.
Select
Select establishes a baseline of security controls and supplemental controls, then tailors them to the organization using the completed risk assessment.
- Determine the baseline controls.
- Tailor the controls to the organization.
- Document the selected controls in the System Security Plan.
- Plan how the system will be monitored continuously.
Implement
Implement turns the selected controls into working safeguards and records how each control is deployed within the system.
- Coordinate responsibilities with team members who understand each control.
- Document the control implementation and its connection to the system in the System Security Plan.
Assess
Assess tests whether the implemented controls operate as intended and produce the outcome required by the security plan.
- Have an independent assessor review the controls.
- Address weaknesses and deficiencies found during assessment.
- Record findings and remediation timelines in the System Security Plan.
Authorize
Authorize presents the assessment results to the authorizing official, who decides whether the remaining risk is acceptable. Unfinished remediation work is recorded in a Plan of Action and Milestones with an expected timeline.
Monitor
Monitor is the continuous work of tracking vulnerabilities, configuration changes, new technology, and control performance so the organization's security and privacy posture remains effective.
- Monitor controls and update them when the system or environment changes.
- Report security status regularly.
- Remediate new weaknesses as they are found.
- Use automation where it helps provide near-real-time visibility.