Beyond SOC 2
What is the NIST Risk Management Framework?
What is the NIST Risk Management Framework?
The NIST Risk Management Framework is a seven-step process for managing security and privacy risk in information systems, defined in SP 800-37. It is mandatory for US federal information systems and provides the process that wraps around the NIST 800-53 control catalogue: the RMF is how you decide what to do, and 800-53 is what you choose from.
The seven steps
| Step | What happens |
|---|---|
| 1. Prepare | Organisational and system-level groundwork: roles, risk tolerance, strategy |
| 2. Categorize | Classify the system and its information by impact level |
| 3. Select | Choose a control baseline from 800-53 and tailor it |
| 4. Implement | Deploy the controls and document how |
| 5. Assess | Test whether they are implemented correctly and operating as intended |
| 6. Authorize | A senior official accepts the residual risk and authorises operation |
| 7. Monitor | Continuous monitoring of controls, changes, and risk posture |
Prepare was added in Revision 2. The earlier six steps assumed the organisational groundwork already existed, and in practice it usually did not, which is why programmes stalled at Categorize.
RMF, 800-53, and CSF are three different things
This is the most common confusion in the NIST family.
| What it is | Who it is for | |
|---|---|---|
| RMF (SP 800-37) | A seven-step process | Federal systems, mandatory |
| 800-53 | A control catalogue | Federal systems, and voluntary crosswalk use |
| Cybersecurity Framework | Identify, Protect, Detect, Respond, Recover | Any organisation, voluntary |
If a commercial company says it "uses NIST", it almost always means the Cybersecurity Framework, not the RMF.
The step that matters most commercially
Step 6, Authorize. The RMF requires a named senior official to formally accept residual risk before a system operates. Most commercial programmes have no equivalent, and it is the step worth borrowing: a documented decision by someone with the authority to make it, recorded before the risk is live rather than after an incident.
That is the same principle as documented risk acceptance in a risk register, which is the commercial version of the same control.
Where Screenata sits
We use NIST 800-53 as a crosswalk hub, mapping SOC 2, HIPAA, ISO 27001, and ISO 42001 onto a shared control set so evidence collected once satisfies several frameworks. That is a use of the catalogue, not of the RMF. We do not support the RMF, FedRAMP, or FISMA authorisation processes, which require an authorisation boundary and an authorising official that a commercial compliance platform does not provide.