Date Published: October 2018
Comments Due: October 31, 2018 (public comment period is CLOSED)
Email Questions to: sec-cert@nist.gov
Planning Note (10/2/2018):
See the current publishing schedule.
NIST announces the final public draft of Special Publication 800-37, Revision 2, Risk Management Framework for Information Systems and Organizations--A System Life Cycle Approach for Security and Privacy .
There are seven major objectives for this update:
The addition of the Prepare step is one of the key changes to the RMF—incorporated to achieve more effective, efficient, and cost-effective security and privacy risk management processes.
In addition to seeking your comments on this final public draft, we are specifically seeking feedback on a new RMF Task P-13, Information Life Cycle. The life cycle describes the stages through which information passes, typically characterized as creation or collection, processing, dissemination, use, storage, and disposition, to include destruction and deletion. Identifying and understanding all stages of the information life cycle have significant implications for security and privacy. We are seeking comment on how organizations would executive this task and how we might provide the most helpful discussion to assist organizations in the execution.
Assessment, Authorization and Monitoring; Configuration Management; Planning; Program Management; Risk Assessment
Publication:
Draft SP 800-37 Rev. 2
Supplemental Material:
Draft, with line numbers (pdf)
Comment template (xls)
Related NIST Publications:
Document History:
09/28/17: SP 800-37 Rev. 2 (Draft)
05/09/18: SP 800-37 Rev. 2 (Draft)
10/02/18: SP 800-37 Rev. 2 (Draft)
12/20/18: SP 800-37 Rev. 2 (Final)
Security and Privacy
audit & accountability; continuous monitoring; controls; planning; risk assessment
Applications
cybersecurity framework
Laws and Regulations
Executive Order 13800; Federal Information Security Modernization Act; Homeland Security Presidential Directive 7; OMB Circular A-130