Date Published: October 2018
                    
                                            Comments Due: October 31, 2018 (public comment period is CLOSED)
                            Email Questions to: sec-cert@nist.gov
            
                    Planning Note (10/2/2018): 
                    
                    See the current publishing schedule.
                
NIST announces the final public draft of Special Publication 800-37, Revision 2, Risk Management Framework for Information Systems and Organizations--A System Life Cycle Approach for Security and Privacy .
There are seven major objectives for this update:
The addition of the Prepare step is one of the key changes to the RMF—incorporated to achieve more effective, efficient, and cost-effective security and privacy risk management processes.
In addition to seeking your comments on this final public draft, we are specifically seeking feedback on a new RMF Task P-13, Information Life Cycle. The life cycle describes the stages through which information passes, typically characterized as creation or collection, processing, dissemination, use, storage, and disposition, to include destruction and deletion. Identifying and understanding all stages of the information life cycle have significant implications for security and privacy. We are seeking comment on how organizations would executive this task and how we might provide the most helpful discussion to assist organizations in the execution.
Assessment, Authorization and Monitoring; Configuration Management; Planning; Program Management; Risk Assessment
                    Publication:
                         Draft SP 800-37 Rev. 2
                                    
                    Supplemental Material:
                        
                                 Draft, with line numbers (pdf)
                                
                                 Comment template (xls)
                                
                        
                
                        Related NIST Publications:
                        
                    
                        Document History:
                        
                                    09/28/17: SP  800-37 Rev. 2 (Draft)
                                    05/09/18: SP  800-37 Rev. 2 (Draft)
                                    10/02/18: SP  800-37 Rev. 2 (Draft)
                                    12/20/18: SP  800-37 Rev. 2 (Final)
                        
                    
                            Security and Privacy
                            
                                audit & accountability;                                 continuous monitoring;                                 controls;                                 planning;                                 risk assessment                            
                        
                            Applications
                            
                                cybersecurity framework                            
                        
                            Laws and Regulations
                            
                                Executive Order 13800;                                 Federal Information Security Modernization Act;                                 Homeland Security Presidential Directive 7;                                 OMB Circular A-130