Date Published: May 2018
Comments Due: June 22, 2018 (public comment period is CLOSED)
Email Questions to: sec-cert@nist.gov
Planning Note (5/25/2018):
See the current publishing schedule.
This update to NIST Special Publication 800-37 (Revision 2) responds to the call by the Defense Science Board, Executive Order 13800, and OMB Memorandum M-17-25 to develop the next-generation Risk Management Framework (RMF) for information systems, organizations, and individuals.
There are seven major objectives for this update:
A public comment period for this draft document is open until June 22, 2018.
Assessment, Authorization and Monitoring; Configuration Management; Planning; Program Management; Risk Assessment
Publication:
Draft SP 800-37 Rev. 2
Supplemental Material:
Draft, with line numbers (pdf)
Mark-up Copy of Draft SP 800-37 Rev. 2 (pdf)
Comment template (xls)
Presentation: RMF 2.0 (introduces the initial public draft) (pdf)
NIST Press Release (other)
Related NIST Publications:
Document History:
09/28/17: SP 800-37 Rev. 2 (Draft)
05/09/18: SP 800-37 Rev. 2 (Draft)
10/02/18: SP 800-37 Rev. 2 (Draft)
12/20/18: SP 800-37 Rev. 2 (Final)
Security and Privacy
audit & accountability; continuous monitoring; controls; planning; risk assessment
Applications
cybersecurity framework
Laws and Regulations
Executive Order 13800; Federal Information Security Modernization Act; Homeland Security Presidential Directive 7; OMB Circular A-130