0.2 NIST RMF 7-Step Lifecycle & GRC Architecture
Key Takeaways
- NIST SP 800-37 Rev. 2 transformed the Risk Management Framework by adding Step 0 (Prepare) and fully integrating privacy risk management across the entire life cycle.
- The RMF operates across a 3-tier risk hierarchy defined in NIST SP 800-39: Tier 1 (Organization), Tier 2 (Mission/Business Process), and Tier 3 (Information System).
- The 7 sequential RMF steps are: Prepare (Step 0), Categorize (Step 1), Select (Step 2), Implement (Step 3), Assess (Step 4), Authorize (Step 5), and Monitor (Step 6).
- The formal Authorization Package presented to the Authorizing Official (AO) consists of three foundational artifacts: the System Security and Privacy Plan (SSP/SSPP), the Security Assessment Report (SAR), and the Plan of Action and Milestones (POA&M).
- Security and privacy control baselines are established using FIPS 199 impact categorization and tailored via NIST SP 800-53 Rev. 5 parameters and scoping guidance.
NIST RMF 7-Step Lifecycle & GRC Architecture
The NIST Risk Management Framework (RMF), formalized in NIST Special Publication (SP) 800-37 Revision 2, provides a structured, disciplined, and repeatable process for integrating security, privacy, and supply chain risk management activities into the system development life cycle (SDLC). The RMF bridges the strategic objectives of enterprise leadership with the operational reality of technical systems, ensuring that organizational risk remains within acceptable thresholds.
Understanding the RMF architecture is central to the CGRC Common Body of Knowledge. Every phase of governance, engineering, audit, and authorization aligns directly to the RMF's seven sequential steps and its supporting suite of Federal Information Processing Standards (FIPS) and NIST Special Publications.
1. Evolution: SP 800-37 Rev. 1 vs. Rev. 2 & Privacy Integration
The transition from NIST SP 800-37 Rev. 1 to Rev. 2 represented a major architectural shift in federal and enterprise risk governance.
The Two Paradigm Shifts in Revision 2
- Creation of Step 0 (Prepare): In Rev. 1, the RMF began at Categorize (Step 1). Rev. 2 introduced Step 0: Prepare at both the organizational and system levels. Preparation establishes enterprise risk framing, assigns key roles, identifies common control catalogs, and develops continuous monitoring strategies before system-level engineering commences.
- Deep Integration of Privacy: Rev. 2 integrated privacy considerations alongside information security across all steps. Privacy is no longer treated as an isolated compliance checklist; rather, privacy risks arising from the processing of Personally Identifiable Information (PII) are assessed and managed holistically alongside security controls, incorporating the Senior Agency Official for Privacy (SAOP) and the NIST Privacy Framework.
Legacy RMF (SP 800-37 Rev. 1) - 6 Steps:
[Categorize] ➔ [Select] ➔ [Implement] ➔ [Assess] ➔ [Authorize] ➔ [Monitor]
Modern RMF (SP 800-37 Rev. 2) - 7 Steps with Security & Privacy:
[Prepare] ➔ [Categorize] ➔ [Select] ➔ [Implement] ➔ [Assess] ➔ [Authorize] ➔ [Monitor]
│ │ │ │ │ │ │
└──────────────┴────────────┴─────┬─────┴───────────┴───────────┴────────────┘
▼
Full Security & Privacy Integration (SAOP + CISO)
2. The Multi-Tier Risk Management Model (NIST SP 800-39)
NIST SP 800-39 (Managing Information Security Risk) defines a three-tier approach to risk management that ensures alignment between executive governance and technical operations.
┌─────────────────────────────────────────────────────────────┐
│ TIER 1: ORGANIZATION │
│ • Governance, Risk Framing & Enterprise Risk Tolerance │
│ • Strategic Resource Allocation & Executive Oversight │
│ • Key Roles: Head of Agency, CIO, CISO, SAOP, Risk Exec │
└──────────────────────────────┬──────────────────────────────┘
│ ▲ Strategic Guidance (Top-Down)
▼ │ Residual Risk Awareness (Bottom-Up)
┌─────────────────────────────────────────────────────────────┐
│ TIER 2: MISSION / BUSINESS PROCESS │
│ • Mission / Business Process Definition & Workflows │
│ • Information Flow Mapping & Architecture │
│ • Common Control Identification & Provider Allocation │
│ • Key Roles: Mission / Business Owners, Enterprise Arch. │
└──────────────────────────────┬──────────────────────────────┘
│ ▲ Common Controls & Scoping Rules
▼ │ System Risk & Impact Metrics
┌─────────────────────────────────────────────────────────────┐
│ TIER 3: INFORMATION SYSTEM │
│ • System Boundary Definition, Categorization & Tailoring │
│ • Control Implementation, Technical Assessment & ATO │
│ • Continuous Monitoring & Configuration Change Control │
│ • Key Roles: Authorizing Official (AO), ISSO, ISO, SCA │
└─────────────────────────────────────────────────────────────┘
The Three Tiers Explained
- Tier 1 (Organization Level): Addresses risk from the strategic enterprise perspective. It establishes the organizational risk management strategy, determines risk tolerance and risk appetite, defines acceptable risk response strategies (accept, avoid, mitigate, transfer/share), and provides overarching governance.
- Tier 2 (Mission / Business Process Level): Addresses risk from the mission and business process perspective. It prioritizes missions, defines information flows across organizational processes, establishes the enterprise architecture, and identifies Common Controls that can be inherited across multiple systems.
- Tier 3 (Information System Level): Addresses risk from the individual system perspective. It encompasses system categorization, allocation of hybrid/system-specific controls, control implementation in the System Security Plan (SSP), assessment testing, formal authorization, and continuous operational monitoring.
[!IMPORTANT] Bidirectional Risk Information Flow Risk management is not solely top-down or bottom-up. Top-down flow provides governance, risk appetite thresholds, and common control baselines. Bottom-up flow delivers real-time vulnerability reports, assessment findings, and residual risk data to executive leadership for informed decision-making.
3. The 7 Steps of the NIST RMF Life Cycle
Each step of the RMF consists of specific tasks, designated roles, and required artifact deliverables. Below is an exhaustive breakdown of the seven steps.
┌────────────────────────────────┐
│ STEP 0: PREPARE (P) │
│ Organization & System Context │
└───────────────┬────────────────┘
│
▼
┌────────────────────────────────┐
│ STEP 1: CATEGORIZE (C) │
│ FIPS 199 / SP 800-60 Impact │
└───────────────┬────────────────┘
│
▼
┌────────────────────────────────┐
│ STEP 2: SELECT (S) │
│ SP 800-53 Baseline & Tailoring │
└───────────────┬────────────────┘
│
▼
┌────────────────────────────────┐
│ STEP 3: IMPLEMENT (I) │
│ SSP & Control Engineering │
└───────────────┬────────────────┘
│
▼
┌────────────────────────────────┐
│ STEP 4: ASSESS (A) │
│ SP 800-53A Testing & SAR │
└───────────────┬────────────────┘
│
▼
┌────────────────────────────────┐
│ STEP 5: AUTHORIZE (AZ) │
│ Package Review & AO ATO Memo │
└───────────────┬────────────────┘
│
▼
┌────────────────────────────────┐
┌───────────┤ STEP 6: MONITOR (M) ├───────────┐
│ │ ISCM, SIA & Continual ATO │ │
│ └────────────────────────────────┘ │
│ │
└────── Event-Driven Reassessment & Ongoing Feedback ────┘
Step 0: Prepare
- Primary Purpose: Carry out essential organizational- and system-level activities to manage security and privacy risks before initiating system categorization.
- Key Tasks:
- Organization-level: Assign risk management roles; establish the enterprise risk management strategy and risk tolerance; conduct enterprise-wide risk assessment; identify common control providers (CCPs); establish an organization-wide Continuous Monitoring Strategy.
- System-level: Identify the Information System Owner (ISO), Information System Security Officer (ISSO), and Authorizing Official (AO); define system mission and stakeholder needs; identify system boundary and operational environment; register the system in the organizational asset/governance repository.
- Governing Guidelines: NIST SP 800-37 Rev. 2, NIST SP 800-39, NIST SP 800-160.
Step 1: Categorize
- Primary Purpose: Categorize the system and the information processed, stored, and transmitted based on an impact analysis of potential loss.
- Key Tasks:
- Document system characteristics and operational workflows.
- Identify all information types processed by the system using NIST SP 800-60 Volumes I & II.
- Determine the potential impact (Low, Moderate, High) for each information type across the three core security objectives: Confidentiality, Integrity, and Availability pursuant to FIPS 199.
- Apply the High-Water Mark principle to determine the overall system security categorization.
- Conduct privacy threshold analysis (PTA) and determine if a Privacy Impact Assessment (PIA) is required.
- Primary Deliverables: System Categorization Section in the SSP / FIPS 199 Categorization Document.
Step 2: Select
- Primary Purpose: Select, tailor, and document the baseline security and privacy controls necessary to protect the system based on its categorization and risk posture.
- Key Tasks:
- Select the initial control baseline from NIST SP 800-53 Rev. 5 (Low, Moderate, or High baseline) and the privacy baseline.
- Apply tailoring guidance: scoping considerations (e.g., public access, physical hosting), parameterization of Organization-Defined Parameters (ODPs), and compensating controls.
- Determine control allocation: designate controls as Common (Inherited), System-Specific, or Hybrid.
- Develop the system-level Continuous Monitoring Strategy.
- Obtain formal approval of the security control baseline from the Authorizing Official (AO) or designated representative.
- Primary Deliverables: Baseline Control Allocation List, Tailoring Rationale, Continuous Monitoring Strategy.
Step 3: Implement
- Primary Purpose: Implement the selected security and privacy controls and describe how they are employed within the system and its environment.
- Key Tasks:
- Implement the controls consistent with enterprise architecture and secure engineering principles (NIST SP 800-160).
- Author comprehensive Control Implementation Statements (CIS) detailing who, what, how, where, and when each control is satisfied.
- Fully document control implementations and inheritance in the System Security and Privacy Plan (SSP / SSPP).
- Primary Deliverables: Completed System Security and Privacy Plan (SSP).
Step 4: Assess
- Primary Purpose: Determine if the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting security and privacy requirements.
- Key Tasks:
- Select an independent Security Control Assessor (SCA).
- Develop the Security Assessment Plan (SAP) detailing assessment objectives, scope, and procedures per NIST SP 800-53A Rev. 5.
- Conduct assessment using the three core methods: Examine (specifications/policy), Interview (personnel), and Test (mechanisms/technical scanning).
- Document findings as Satisfied or Other Than Satisfied.
- Formulate the final Security Assessment Report (SAR) documenting vulnerabilities, potential impact, and assessor recommendations.
- Primary Deliverables: Security Assessment Plan (SAP), Security Assessment Report (SAR).
Step 5: Authorize
- Primary Purpose: Provide executive accountability by having the Authorizing Official (AO) explicitly accept the residual risk to organizational operations, assets, individuals, and other organizations.
- Key Tasks:
- Develop the Plan of Action and Milestones (POA&M) for all Other Than Satisfied findings identified in the SAR.
- Assemble the formal Authorization Package: (1) System Security Plan (SSP), (2) Security Assessment Report (SAR), and (3) Plan of Action and Milestones (POA&M).
- The AO conducts a risk determination balancing mission necessity against residual risk.
- The AO issues an explicit authorization decision document.
- Authorization Decisions:
- Authority to Operate (ATO): Formal approval to operate for a specified period or under continuous monitoring.
- ATO with Conditions: Temporary authorization requiring specific remediation milestones within strict deadlines.
- Interim Authority to Test (IATT): Time-limited approval to test in an operational environment.
- Denial of Authorization to Operate (DATO): Operation prohibited due to unacceptably high residual risk.
- Primary Deliverables: Plan of Action and Milestones (POA&M), Authorization Decision Document (ATO Memo).
Step 6: Monitor
- Primary Purpose: Maintain ongoing situational awareness of the security and privacy posture of the system to support ongoing risk management decisions.
- Key Tasks:
- Execute the Information Security Continuous Monitoring (ISCM) strategy (NIST SP 800-137).
- Monitor system and environmental changes; conduct Security Impact Analysis (SIA) prior to implementing proposed modifications (NIST SP 800-128).
- Perform ongoing automated vulnerability scans and periodic control re-assessments.
- Maintain and remediate items on the POA&M.
- Provide regular security and privacy status reports to the AO and executive leadership (supporting Continuous ATO).
- Implement secure system disposal and media sanitization upon decommissioning (NIST SP 800-88).
- Primary Deliverables: Updated SSP, Updated SAR, Updated POA&M, Security Impact Analysis Reports, Decommissioning Plan.
4. Core Authorization Package Artifacts & Lifecycle Matrix
The following matrix summarizes the critical artifacts generated across the RMF lifecycle, their governing standards, and the responsible organizational roles.
| RMF Step | Primary Output Artifact | Governing Standard | Primary Responsible Role |
|---|---|---|---|
| Step 0: Prepare | Enterprise Risk Management Strategy, Common Control Catalogs | NIST SP 800-39 / SP 800-37 | Head of Agency / CIO / CISO / SAOP |
| Step 1: Categorize | Security Categorization Report / FIPS 199 Document | FIPS 199 / NIST SP 800-60 | Information System Owner (ISO) / ISSO |
| Step 2: Select | Security Control Baseline & Continuous Monitoring Strategy | NIST SP 800-53 Rev. 5 | ISO / ISSO / Authorizing Official (AO) |
| Step 3: Implement | System Security and Privacy Plan (SSP / SSPP) | NIST SP 800-160 / SP 800-18 | Information System Owner (ISO) / ISSO |
| Step 4: Assess | Security Assessment Plan (SAP) & Security Assessment Report (SAR) | NIST SP 800-53A Rev. 5 | Security Control Assessor (SCA) |
| Step 5: Authorize | Plan of Action & Milestones (POA&M), Authorization Decision Memo | NIST SP 800-37 Rev. 2 | Authorizing Official (AO) / ISO |
| Step 6: Monitor | Updated POA&M, Security Impact Analyses, Decommissioning Records | NIST SP 800-137 / SP 800-128 / SP 800-88 | ISSO / ISO / SCA / AO |
What major architectural improvement was introduced in NIST SP 800-37 Revision 2 that distinguished it from Revision 1?
Under the NIST SP 800-39 multi-tier risk management framework, which tier is responsible for establishing enterprise risk framing, defining organizational risk tolerance, and setting overarching governance policies?
When an Information System Owner submits a system to the Authorizing Official (AO) for a formal authorization decision (Step 5: Authorize), which three core documents comprise the mandatory Authorization Package?