NIST SP 800-37
NIST SP 800-37 (RMF)
- "The Risk Management Framework (RMF) provides a process that integrates security, privacy, and cyber supply chain risk management activities into the system development life cycle."[1]
Gerald Auger Definitive Guide to RMF (2021)
Definitive Guide to RMF (Actionable plan for FISMA Compliance) - YouTube
- Video Overview
- Duration - 15:40
- First two minutes are purely introduction - skip to 2:39
- Focus is on NIST SP 800-37
- Duration - 15:40
- The RMF is a
6-step7-step continuous cycle to understand and provide a uniform approach to securing information systems- These are the steps:
- Prepare (not discussed in Gerald's video)
- Categorize
- Select
- Implement
- Assess (Audit)
- Authorize
- Monitor
- These are the steps:
- RMF Step Guide
- Prepare:[2] Setup the organization for success
- Identify systems and stakeholders in the business and assign role for executing the RMF
- Conduct risk assessments and get a baseline of current risk and security practices
- Max note: Without any practical experience myself, I feel like Gerald combined the Prepare and Categorize tasks, and I think that omission would likely make subsequent steps more difficult.
- Categorize: Identifying potential impact
- FIPS 199 and FIPS 200 are used to identify potential impact of a system
- Describes the importance of a system and steps required to secure it
- Impact ratings are chosen between High, Moderate, and Low
- 80-90% of systems are Moderate impact systems
- High ratings are reserved for national security or classified systems
- Low ratings are also rare, non-business critical
- NIST SP 800-60 provides guidelines on the impact you should assign to certain systems
- FIPS 199 and FIPS 200 are used to identify potential impact of a system
- Select: Select controls to implement from 800-53R5
- Basically a big dictionary with hundreds of controls
- We're just baselining, so able to pick and choose as needed
- Implement: Implement the controls, the lions-share of the work
- Make a "System Security Plan"
- This is the book/plan for the documentation of your system
- Network diagram, who owns the system, what kind of data is stored, etc.
- All the controls to secure the systems and how they are implemented
- May be more or less complicated, depending on the size of the organization
- Gerald specifically mentions the NIST SP 800-15, but it was withdrawn in September of the year he published his video
- This is the book/plan for the documentation of your system
- If you have any challenges implementing controls, NIST has implementation guides for most systems
- Offer tons of instructions and things you can do
- Make a "System Security Plan"
- Assess: Bring in an independent auditor to inspect your controls
- For FISMA or anything else, you will need an external auditor
- If this is purely internal, can do it yourself, but it's better to have someone else verify
- For FISMA or anything else, you will need an external auditor
- Authorize: Authorize the system
- Basically just a memo from the person responsible authorizing the system to operate
- Usually just a page or so with their signature
- What's missing in this (as of 2021) is a risk assessment
- Use NIST 800-30 to asses risk
- Residual risk for controls not implemented, etc.
- Use NIST 800-30 to asses risk
- This grants an Authorization to Operate for 1-3 years, depending on the requirements
- Basically just a memo from the person responsible authorizing the system to operate
- Monitor: Monitor the controls
- Systems are monitored and brought re-audited at regular intervals
- Often the audits are often scheduled to be tested in a kind of sequence to prevent infrequent massive effort
- Prepare:[2] Setup the organization for success
Resources
Official
- SP 800-37 Rev. 2, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy | CSRC
- Direct link to the PDF: nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
- 183 pages
Supplemental
Articles
- NIST Risk Management Framework - by Aron Lange
- Super short and has a great graphic which details every step and task of the RMF
Videos
- Definitive Guide to RMF (Actionable plan for FISMA Compliance) - YouTube
- 15 minute long video
- Older, includes references to documents that have been withdrawn and doesn't include the "Prepare" phase
- NIST RMF FULLY EXPLAINED (IN PLAIN ENGLISH) - YouTube
- 1h12m video long
- I love and hate Gerald Auger; his content is great and helpful, but his style is super distracting and maddening.
Not discussed in Gerald's video, but detailed here for reference ↩︎