Date Published: December 2018
Supersedes:
SP 800-37 Rev. 1 (06/05/2014); White Paper (06/03/2014)
Assessment, Authorization and Monitoring; Configuration Management; Planning; Program Management; Risk Assessment
Publication:
SP 800-37 Rev. 2 (DOI)
Local Download
Supplemental Material:
None available
Related NIST Publications:
Document History:
09/28/17: SP 800-37 Rev. 2 (Draft)
05/09/18: SP 800-37 Rev. 2 (Draft)
10/02/18: SP 800-37 Rev. 2 (Draft)
12/20/18: SP 800-37 Rev. 2 (Final)
Security and Privacy
audit & accountability; continuous monitoring; controls; planning; risk assessment
Applications
cybersecurity framework
Laws and Regulations
Executive Order 13800; Federal Information Security Modernization Act; Homeland Security Presidential Directive 7; OMB Circular A-130