Risk Management Framework (RMF)
The Risk Management Framework is NIST's seven-step process for integrating security, privacy, and supply chain risk management into the system lifecycle. Defined in NIST SP 800-37 Rev 2. It is how federal systems get authorized to operate (ATO). FedRAMP is RMF applied to cloud services. The DoD system authorization process is RMF. If you work with federal systems or FedRAMP-authorized cloud services, you're seeing RMF in action.
- glossary
- The Seven Steps
The Seven Steps
- Prepare: Establish context and priorities at organization, mission, and system levels. Added in Rev 2 (Rev 1 had six steps).
- Categorize: Use FIPS 199 to determine whether the information system is Low, Moderate, or High impact.
- Select: Pick a baseline of NIST SP 800-53 controls (Low, Moderate, or High) and tailor for the system.
- Implement: Deploy the controls and document how they are integrated.
- Assess: Evaluate whether controls are implemented correctly and operating as intended. Done by an independent assessor (3PAO for FedRAMP).
- Authorize: The Authorizing Official (AO) reviews the risk assessment and decides to issue an ATO.
- Monitor: Continuously track security posture, incidents, changes, and control effectiveness.
RMF in FedRAMP
FedRAMP is RMF applied to cloud services with a few extras. The 3PAO runs the Assess step. The JAB or sponsoring agency AO runs the Authorize step. Continuous monitoring is formalized with monthly vulnerability scans, annual assessments, and significant change reviews. The output is a FedRAMP Authorization listed on the FedRAMP Marketplace.
RMF in DoD
DoD systems use RMF through the DoD Risk Management Framework (documented in DoDI 8510.01). Impact levels are extended with the DoD Cloud Computing SRG's Impact Levels 2, 4, 5, and 6. A DoD AO issues the ATO. The process is stricter than civilian agency RMF for most IL4+ systems.
How RMF Relates to CMMC and NIST 800-171
CMMC and NIST 800-171 are about contractor nonfederal systems. RMF is about federal systems (or cloud services providing services to federal agencies). The controls overlap (both draw from NIST 800-53), but the authorization pathway is different. A defense contractor can be compliant with CMMC Level 2 without ever obtaining an ATO, because CMMC does not require authorization by a federal AO. FedRAMP authorization of a cloud service the contractor uses is a separate matter.
Continuous Monitoring
Step 7 (Monitor) is where RMF differs most from older authorization models. The ATO is not a one-time event. Authorization requires an ongoing monitoring program: monthly vulnerability scans, annual assessments, significant change reviews, incident reporting, and deviations from the approved configuration tracked through POA&M. Losing the monitoring program means losing the ATO.