Date Published: September 2017
No Comments Solicited
Email Questions to: sec-cert@nist.gov
Planning Note (2/9/2018):
See the current publication schedule proposed by NIST; it may be subject to change.
NIST announces the release of a discussion draft of Special Publication (SP) 800-37, Revision 2, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy. This update responds to the call by the Defense Science Board, the President’s Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure, and the Office of Management and Budget Memorandum M-17-25 (implementation guidance for the Cybersecurity Executive Order) to develop the next-generation Risk Management Framework (RMF) for systems and organizations.
There are four major objectives for this update—
The addition of the organizational preparation step is one of the key changes to the RMF—incorporated to achieve more effective, efficient, and cost-effective risk management processes. The primary objectives for institutionalizing organizational preparation are as follows:
Recognizing that organizational preparation for RMF execution may vary from organization to organization, achieving the objectives outlined above can significantly reduce the information technology footprint and attack surface of organizations, promote IT modernization objectives, conserve security resources, prioritize security activities to focus protection strategies on the most critical assets and systems, and promote privacy protections for individuals.
This draft is intended to promote discussion on the new organizational preparation step and the other innovations introduced in RMF 2.0—including how these changes work to achieve the primary objectives stated above.
Assessment, Authorization and Monitoring; Configuration Management; Planning; Program Management; Risk Assessment
Publication:
SP 800-37 Rev. 2 (Discussion Draft)
Supplemental Material:
SP 800-37 Rev. 2 (Discussion Draft) (word)
"Why Security and Privacy Matter in a Digital World" (blog post) (other)
Related NIST Publications:
Document History:
09/28/17: SP 800-37 Rev. 2 (Draft)
05/09/18: SP 800-37 Rev. 2 (Draft)
10/02/18: SP 800-37 Rev. 2 (Draft)
12/20/18: SP 800-37 Rev. 2 (Final)
Security and Privacy
audit & accountability; continuous monitoring; controls; planning; risk assessment
Applications
cybersecurity framework
Laws and Regulations
Federal Information Security Modernization Act; Homeland Security Presidential Directive 7; OMB Circular A-130