Screenata

Beyond SOC 2

What is the NIST Risk Management Framework?

August 18, 20262 min read

What is the NIST Risk Management Framework?

The NIST Risk Management Framework is a seven-step process for managing security and privacy risk in information systems, defined in SP 800-37. It is mandatory for US federal information systems and provides the process that wraps around the NIST 800-53 control catalogue: the RMF is how you decide what to do, and 800-53 is what you choose from.

The seven steps

StepWhat happens
1. PrepareOrganisational and system-level groundwork: roles, risk tolerance, strategy
2. CategorizeClassify the system and its information by impact level
3. SelectChoose a control baseline from 800-53 and tailor it
4. ImplementDeploy the controls and document how
5. AssessTest whether they are implemented correctly and operating as intended
6. AuthorizeA senior official accepts the residual risk and authorises operation
7. MonitorContinuous monitoring of controls, changes, and risk posture

Prepare was added in Revision 2. The earlier six steps assumed the organisational groundwork already existed, and in practice it usually did not, which is why programmes stalled at Categorize.

RMF, 800-53, and CSF are three different things

This is the most common confusion in the NIST family.

What it isWho it is for
RMF (SP 800-37)A seven-step processFederal systems, mandatory
800-53A control catalogueFederal systems, and voluntary crosswalk use
Cybersecurity FrameworkIdentify, Protect, Detect, Respond, RecoverAny organisation, voluntary

If a commercial company says it "uses NIST", it almost always means the Cybersecurity Framework, not the RMF.

The step that matters most commercially

Step 6, Authorize. The RMF requires a named senior official to formally accept residual risk before a system operates. Most commercial programmes have no equivalent, and it is the step worth borrowing: a documented decision by someone with the authority to make it, recorded before the risk is live rather than after an incident.

That is the same principle as documented risk acceptance in a risk register, which is the commercial version of the same control.

Where Screenata sits

We use NIST 800-53 as a crosswalk hub, mapping SOC 2, HIPAA, ISO 27001, and ISO 42001 onto a shared control set so evidence collected once satisfies several frameworks. That is a use of the catalogue, not of the RMF. We do not support the RMF, FedRAMP, or FISMA authorisation processes, which require an authorisation boundary and an authorising official that a commercial compliance platform does not provide.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.