Glossary · Glossary

RMF

The NIST process U.S. federal systems follow to categorize risk, select and implement security controls, assess them, and authorize the system to operate, then monitor it continuously. It provides the structured path to an Authorization to Operate.

Updated

The NIST process U.S. federal systems follow to categorize risk, select and implement security controls, assess them, and authorize the system to operate, then monitor it continuously. It provides the structured path to an Authorization to Operate.

Why it matters

The Risk Management Framework is the process every federal system follows to earn and keep authorization to operate; for a program it is the compliance spine that connects security controls to fielding.

Standards & authorities

  • NIST SP 800-37 Rev. 2 (Risk Management Framework)

Related in glossary

Frequently asked

What is RMF?

The NIST process U.S. federal systems follow to categorize risk, select and implement security controls, assess them, and authorize the system to operate, then monitor it continuously. It provides the structured path to an Authorization to Operate.

Why does RMF matter for defense and counter-UAS operators?

The Risk Management Framework is the process every federal system follows to earn and keep authorization to operate; for a program it is the compliance spine that connects security controls to fielding.

What standard or authority governs RMF?

RMF is defined or governed by NIST SP 800-37 Rev. 2 (Risk Management Framework).

More in glossary

← All glossary Library home