Glossary · Glossary
RMF
The NIST process U.S. federal systems follow to categorize risk, select and implement security controls, assess them, and authorize the system to operate, then monitor it continuously. It provides the structured path to an Authorization to Operate.
The NIST process U.S. federal systems follow to categorize risk, select and implement security controls, assess them, and authorize the system to operate, then monitor it continuously. It provides the structured path to an Authorization to Operate.
Why it matters
The Risk Management Framework is the process every federal system follows to earn and keep authorization to operate; for a program it is the compliance spine that connects security controls to fielding.
Standards & authorities
- NIST SP 800-37 Rev. 2 (Risk Management Framework)
Related in glossary
Frequently asked
What is RMF?
The NIST process U.S. federal systems follow to categorize risk, select and implement security controls, assess them, and authorize the system to operate, then monitor it continuously. It provides the structured path to an Authorization to Operate.
Why does RMF matter for defense and counter-UAS operators?
The Risk Management Framework is the process every federal system follows to earn and keep authorization to operate; for a program it is the compliance spine that connects security controls to fielding.
What standard or authority governs RMF?
RMF is defined or governed by NIST SP 800-37 Rev. 2 (Risk Management Framework).