

|
Prepare Essential activities to prepare the organization to manage security and privacy risks. |
Implement the controls and document how controls are deployed. |
|
Categorize the system and information processed, stored, and transmitted based on impact analysis. |
Assess to determine if the controls are in place, operating as intended, and producing the desired results. |
|
Select the set of NIST SP 800-53 controls to protect the system based on risk assessment(s) |
Authorize: Senior official makes a risk-based decision to authorize the system (to operate). |
|
Monitor: Continuously monitor control implementation and risks to the system. |
|
| Table 1: RMF Steps Including Resources for Implementers and Supporting NIST Publications *Read More at Risk Management Framework (RMF) Overview - Risk Management | CSRC | |
|
Identify – Develop an organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities. The activities in the Identify Function are foundational for effective use of the Framework. Understanding the business context, the resources that support critical functions, and the related cybersecurity risks enables an organization to focus and prioritize its efforts, consistent with its risk management strategy and business needs. Examples of outcome Categories within this Function include Asset Management; Business Environment; Governance; Risk Assessment; and Risk Management Strategy. Protect – Develop and implement appropriate safeguards to ensure delivery of critical services. The Protect Function supports the ability to limit or contain the impact of a potential cybersecurity event. Examples of outcome Categories within this Function include Identity Management and Access Control; Awareness and Training; Data Security; Information Protection Processes and Procedures; Maintenance; and Protective Technology. Detect – Develop and implement appropriate activities to identify the occurrence of a cybersecurity event. The Detect Function enables the timely discovery of cybersecurity events. Examples of outcome Categories within this Function include Anomalies and Events; Security Continuous Monitoring; and Detection Processes. |
Respond – Develop and implement appropriate activities to take action regarding a detected cybersecurity incident. The Respond Function supports the ability to contain the impact of a potential cybersecurity incident. Examples of outcome Categories within this Function include Response Planning; Communications; Analysis; Mitigation; and Improvements. Recover – Develop and implement appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to a cybersecurity incident. The Recover Function supports timely recovery to normal operations to reduce the impact of a cybersecurity incident. Examples of outcome Categories within this Function include Recovery Planning; Improvements; and Communications. |
| Main Menu |
|---|
| FIPS PUB 200 Minimum Security Requirements - Visit FIPS 200, Minimum Security Requirements for Federal Info and Info Systems | CSRC (nist.gov) | |
|
|
| Standards.gov | NIST |
| Documentary Standards can specify the definition of terms; classifications of components; delineation of procedures; specification of dimensions, materials, processes, products, systems, services, or practices; test methods and sampling procedures; or descriptions of fit and measurements of size or strength. Under the National Technology Transfer and Advancement Act (NTTAA), NIST is assigned the responsibility to coordinate federal, state, and local documentary standards and conformity assessment activities. |
| Standards.gov | Federal Use of Standards | Standards Incorporated by Reference (SIBR) | Industry Standards | International Standards | Military Standards | Standards Issued or Adopted by Federal Agencies | Standards Search Engines | Voluntary Product Standards |
Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics you need to know. (The Perils of Mount Must Read™ Confessions of a Cliff Note Junky) These resources go onto the "Mountain of Must Read". If you don't recognize the standard reference, you've missed critical understanding. As of 2022, this is the minimum NIST alphabet. All of these documents are found at https://csrc.nist.gov/publications/ Be very careful about static content. Look at links before you launch them. Never use alternate sites for the Computer Security Resource Center. Get the full list here <NIST Reading Extended>