Bidders Library Cybersecurity - NIST SP 800-37r2.pdf

PDF 2 MB Posted

Attached to
TEC II Services RFP Federal contract opportunity
Solicitation number
HC102821R0006
Issued by
Defense Information Systems Agency

About this file

This solicitation requests test, evaluation, and certification services for the Joint Interoperability Test Command. The Defense Information Systems Agency is seeking proposals to provide services such as testing and evaluating systems for interoperability, standards compliance, and information assurance. Proposals are due by September 30, 2021, with an anticipated award date of January 15, 2022. The single-award indefinite delivery, indefinite quantity contract has a five-year base period of performance and potential value of $950 million. The solicitation targets small businesses.

View the file

Other files for this federal contract opportunity

Other files attached to TEC II Services RFP, newest first.
File Type Posted
HC102821R0006 AMD 0007.pdf PDF
HC102821R00060001.pdf PDF
Bidders Library Instrumentation and Tools List 2021.xlsx XLSX spreadsheet
TEC II Bidders Library List.xlsx XLSX spreadsheet
Bidders Library Security - ICD 705.pdf PDF
Bidders Library Security - ICD 700.pdf PDF
Bidders Library Security - FHU Visitor Access Policy.pdf PDF
Bidders Library Security - DoD 5220 22.pdf PDF
Bidders Library Security - DISAI 240-115-10.pdf PDF
Bidders Library Security - DISAI 240-110-40.pdf PDF
Bidders Library Security - DISAI 100-50-16.pdf PDF
Bidders Library Operational Test and Evaluation - OTA Memo 5-31-2019.pdf PDF
Bidders Library Operational Test and Evaluation - DOTE Memo 9-25-2019.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 5-5-2010.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 01-06-2010.pdf PDF
Bidders Library Operational Test and Evaluation - DISAI 640-195-1.pdf PDF
Bidders Library JITC Instructions - JITCI 650-70-01.pdf PDF
Bidders Library JITC Instructions - JITCI 240-110-04.pdf PDF
Bidders Library JITC Instructions - JITCI 240-110-08.pdf PDF
Bidders Library JITC Instructions - JITCI 240-110-05.pdf PDF
Bidders Library JITC Instructions - JITCI 100-55-01.pdf PDF
Bidders Library Interoperability Test and Evaluation - UCR 2013.pdf PDF
Bidders Library Interoperability Test and Evaluation - JTC SOP.pdf PDF
Bidders Library Interoperability Test and Evaluation - JITC IPG.pdf PDF
Bidders Library Interoperability Test and Evaluation - JITC Notional Guide to TE Documentation.pdf PDF
Bidders Library Interoperability Test and Evaluation - DoDAF v2-02.pdf PDF
Bidders Library Interoperability Test and Evaluation - DoDI 8115 02.pdf PDF
Bidders Library Interoperability Test and Evaluation - Instructions for JIC With and Without Conditions.docx DOCX document
Bidders Library Interoperability Test and Evaluation - DoDI 8330 01.pdf PDF
Bidders Library Interoperability Test and Evaluation - DoDI 8410 02.pdf PDF
Bidders Library Interoperability Test and Evaluation - DoDI 8320 03.pdf PDF
Bidders Library Interoperability Test and Evaluation - DoDD 8115 01.pdf PDF
Bidders Library Interoperability Test and Evaluation - CJCSI 8410 02.pdf PDF
Bidders Library Interoperability Test and Evaluation - CJCSI 5128 01.pdf PDF
Bidders Library Interoperability Test and Evaluation - CJCSI 5705 01F.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoDI 5025 01.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoDD 7045 20.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoDI 1010 10.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoDD 5144 02.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoDD 3200 11.pdf PDF
Bidders Library DISA - Agency Snapshot Organization Chart.png PNG image
Bidders Library Cybersecurity - NIST SP 800-53Ar4.pdf PDF
Bidders Library Cybersecurity - DoDI 8530 01.pdf PDF
Bidders Library Security - DoDM 5200 01 Vol 3.pdf PDF
Bidders Library Security - DoDM 5200 02.pdf PDF
Bidders Library Security - DoDM 5200 01 Vol 2.pdf PDF
Bidders Library Security - DoDM 5200 48.pdf PDF
Bidders Library Security - DoDD 5230 20.pdf PDF
Bidders Library Security - DoDM 5105 21.pdf PDF
HC102821R0006.pdf PDF
Show all 50

TEC II Services RFP has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

NIST Special Publication 800-37

Revision 2

Risk Management Framework for

Information Systems and Organizations A System Life Cycle Approach for Security and Privacy

JOINT TASK FORCE

This publication is available free of charge from:

https://doi.org/10.6028/NIST.SP.800-37r2

This publication contains comprehensive updates to the Risk Management Framework. The updates include an alignment with the constructs in the NIST Cybersecurity Framework; the integration of privacy risk management processes; an alignment with system life cycle security engineering processes; and the incorporation of supply chain risk management processes. Organizations can use the frameworks and processes in a complementary manner within the RMF to effectively manage security and privacy risks to organizational operations and assets, individuals, other organizations, and the Nation.

Revision 2 includes a set of organization-wide RMF tasks that are designed to prepare information system owners to conduct system-level risk management activities. The intent is to increase the effectiveness, efficiency, and cost-effectiveness of the RMF by establishing a closer connection to the organization’s missions and business functions and improving the communications among senior leaders, managers, and operational personnel.

NIST Special Publication 800-37 Revision 2

Risk Management Framework for Information Systems and Organizations

JOINT TASK FORCE

December 2018

U.S. Department of Commerce Wilbur L. Ross, Jr., Secretary

National Institute of Standards and Technology

Walter Copan, NIST Director and Under Secretary of Commerce for Standards and Technology

NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

PAGE i

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

P

.800-37r2

Authority

This publication has been developed by NIST to further its statutory responsibilities under the Federal Information Security Modernization Act (FISMA), 44 U.S.C. § 3551 et seq., Public Law (P.L.) 113-283. NIST is responsible for developing information security standards and guidelines, including minimum requirements for federal information systems, but such standards and guidelines shall not apply to national security systems without the express approval of the appropriate federal officials exercising policy authority over such systems. This guideline is consistent with requirements of the Office of Management and Budget (OMB) Circular A-130.

Nothing in this publication should be taken to contradict the standards and guidelines made mandatory and binding on federal agencies by the Secretary of Commerce under statutory authority. Nor should these guidelines be interpreted as altering or superseding the existing authorities of the Secretary of Commerce, OMB Director, or any other federal official. This publication may be used by nongovernmental organizations on a voluntary basis and is not subject to copyright in the United States. Attribution would, however, be appreciated by NIST.

National Institute of Standards and Technology Special Publication 800-37, Revision 2 Natl. Inst. Stand. Technol. Spec. Publ. 800-37, Rev. 2, 183 pages (December 2018)

CODEN: NSPUE2

Comments on this publication may be submitted to:

National Institute of Standards and Technology Attn: Computer Security Division, Information Technology Laboratory

100 Bureau Drive (Mail Stop 8930) Gaithersburg, MD 20899-8930 Email: sec-cert@nist.gov

All comments are subject to release under the Freedom of Information Act (FOIA) [FOIA96].

Certain commercial entities, equipment, or materials may be identified in this document to describe an experimental procedure or concept adequately. Such identification is not intended to imply recommendation or endorsement by NIST, nor is it intended to imply that the entities, materials, or equipment are necessarily the best available for the purpose.

There may be references in this publication to other publications currently under development by NIST in accordance with its assigned statutory responsibilities. The information in this publication, including concepts, practices, and methodologies, may be used by federal agencies even before the completion of such companion publications. Thus, until each publication is completed, current requirements, guidelines, and procedures, where they exist, remain operative. For planning and transition purposes, federal agencies may wish to closely follow the development of these new publications by NIST.

Organizations are encouraged to review draft publications during the designated public comment periods and provide feedback to NIST. Many NIST publications, other than the ones noted above, are available at https://csrc.nist.gov/publications.

mailto:sec-cert@nist.gov https://csrc.nist.gov/publications

NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

PAGE ii

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

Reports on Computer Systems Technology

The National Institute of Standards and Technology (NIST) Information Technology Laboratory (ITL) promotes the U.S. economy and public welfare by providing technical leadership for the Nation’s measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof of concept implementations, and technical analyses to advance the development and productive use of information technology (IT). ITL’s responsibilities include the development of management, administrative, technical, and physical standards and guidelines for the cost-effective security of other than national security-related information in federal information systems. The Special Publication 800-series reports on ITL’s research, guidelines, and outreach efforts in information systems security and privacy and its collaborative activities with industry, government, and academic organizations.

Abstract

This publication describes the Risk Management Framework (RMF) and provides guidelines for applying the RMF to information systems and organizations. The RMF provides a disciplined, structured, and flexible process for managing security and privacy risk that includes information security categorization; control selection, implementation, and assessment; system and common control authorizations; and continuous monitoring. The RMF includes activities to prepare organizations to execute the framework at appropriate risk management levels. The RMF also promotes near real-time risk management and ongoing information system and common control authorization through the implementation of continuous monitoring processes; provides senior leaders and executives with the necessary information to make efficient, cost-effective, risk management decisions about the systems supporting their missions and business functions; and incorporates security and privacy into the system development life cycle. Executing the RMF tasks links essential risk management processes at the system level to risk management processes at the organization level. In addition, it establishes responsibility and accountability for the controls implemented within an organization’s information systems and inherited by those systems.

Keywords assess; authorization to operate; authorization to use; authorizing official; categorize; common control; common control authorization; common control provider; continuous monitoring;

control assessor; control baseline; cybersecurity framework profile; hybrid control; information owner or steward; information security; monitor; ongoing authorization; plan of action and milestones; privacy; privacy assessment report; privacy control; privacy plan; privacy risk; risk assessment; risk executive function; risk management; risk management framework; security;

security assessment report; security control; security engineering; security plan; security risk;

senior agency information security officer; senior agency official for privacy; supply chain risk management; system development life cycle; system owner; system privacy officer; system security officer; system-specific control.

NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

PAGE iii

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

Acknowledgements

This publication was developed by the Joint Task Force Interagency Working Group. The group includes representatives from the Civil, Defense, and Intelligence Communities. The National Institute of Standards and Technology wishes to acknowledge and thank the senior leaders from the Departments of Commerce and Defense, the Office of the Director of National Intelligence, the Committee on National Security Systems, and the members of the interagency working group whose dedicated efforts contributed significantly to the publication.

Department of Defense Office of the Director of National Intelligence

Dana Deasy John Sherman Chief Information Officer Chief Information Officer

Essye B. Miller Vacant Principal Deputy CIO and DoD Senior Information Deputy Chief Information Officer Security Officer

Thomas P. Michelli Susan Dorr Acting Deputy Chief Information Officer for Cybersecurity Director, Cybersecurity Division and Chief

Information Security Officer

Vicki Michetti Wallace Coggins Director, Cybersecurity Policy, Strategy, International, Director, Security Coordination Center and Defense Industrial Base Directorate

National Institute of Standards and Technology Committee on National Security Systems

Charles H. Romine Thomas Michelli Director, Information Technology Laboratory Chair—Defense Community

Donna Dodson Susan Dorr—Intelligence Community Cybersecurity Advisor, Information Technology Laboratory Co-Chair

Matt Scholl Vicki Michetti Chief, Computer Security Division Tri-Chair—Defense Community

Kevin Stine Chris Johnson Chief, Applied Cybersecurity Division Tri-Chair—Intelligence Community

Ron Ross Paul Cunningham FISMA Implementation Project Leader Tri-Chair—Civil Agencies

Joint Task Force Working Group

Ron Ross Kevin Dulany Peter Duspiva Kelley Dempsey NIST, JTF Leader DoD Intelligence Community NIST Taylor Roberts Ellen Nadeau Victoria Pillitteri Naomi Lefkovitz

OMB NIST NIST NIST

Jordan Burris Charles Cutshall Kevin Herms Carol Bales

OMB OMB OMB OMB

Jeff Marron Kaitlin Boeckl Kirsten Moncada Jon Boyens

NIST NIST OMB NIST

Dorian Pappas Dominic Cussatt Esten Porter Celia Paulsen CNSS Veterans Affairs The MITRE Corporation NIST Daniel Faigin Christina Sames Julie Snyder Martin Stanley The Aerospace Corporation The MITRE Corporation The MITRE Corporation Homeland Security

NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

PAGE iv

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

The authors also wish to recognize Matt Barrett, Kathleen Coupe, Jeff Eisensmith, Chris Enloe, Ned Goren, Matthew Halstead, Jody Jacobs, Ralph Jones, Martin Kihiko, Raquel Leone, and the scientists, engineers, and research staff from the Computer Security Division and the Applied Cybersecurity Division for their exceptional contributions in helping to improve the content of the publication. A special note of thanks to Jim Foti and the NIST web team for their outstanding administrative support.

In addition, the authors wish to acknowledge the United States Air Force and the “RMF Next” initiative, facilitated by Air Force CyberWorx, that provided the inspiration for some of the new ideas in this update to the RMF. The working group, led by Lauren Knausenberger, Bill Bryant, and Venice Goodwine, included government and industry representatives Jake Ames, Chris Bailey, James Barnett, Steve Bogue, Wes Chiu, Kurt Danis, Shane Deichman; Joe Erskine, Terence Goodman, Jason Howe, Brandon Howell, Todd Jacobs, Peter Klabe, William Kramer, Bryon Kroger, Kevin LaSalle, Dinh Le, Noam Liran, Sam Miles, Michael Morrison, Raymond Tom Nagley, Wendy Nather, Jasmine Neal, Ryan Perry, Eugene Peterson, Lawrence Rampaul, Jessica Rheinschmidt, Greg Roman, Susanna Scarveles, Justin Schoenthal, Christian Sorenson, Stacy Studstill, Charles Wade, Shawn Whitney, David Wilcox, and Thomas Woodring.

Finally, the authors also gratefully acknowledge the significant contributions from individuals and organizations in both the public and private sectors, nationally and internationally, whose thoughtful and constructive comments improved the overall quality, thoroughness, and usefulness of this publication.

HISTORICAL CONTRIBUTIONS TO NIST SPECIAL PUBLICATION 800-37

The authors acknowledge the many individuals who contributed to previous versions of Special Publication 800-37 since its inception in 2005. They include Marshall Abrams, William Barker, Beckie Koonge, Roger Caslow, John Gilligan, Peter Gouldmann, Richard Graubart, John Grimes, Gus Guissanie, Priscilla Guthrie, Jennifer Fabius, Cita Furlani, Richard Hale, Peggy Himes, William Hunteman, Arnold Johnson, Donald Jones, Stuart Katzke, Eustace King, Mark Morrison, Sherrill Nicely, Karen Quigg, George Rogers, Cheryl Roby, Gary Stoneburner, Marianne Swanson, Glenda Turner, and Peter Williams.

NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

PAGE v

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

Executive Summary

As we push computers to “the edge,” building a complex world of interconnected information systems and devices, security and privacy risks (including supply chain risks) continue to be a large part of the national conversation and topics of great importance. The significant increase in the complexity of the hardware, software, firmware, and systems within the public and private sectors (including the U.S. critical infrastructure) represents a significant increase in attack surface that can be exploited by adversaries. Moreover, adversaries are using the supply chain as an attack vector and effective means of penetrating our systems, compromising the integrity of system elements, and gaining access to critical assets.

The Defense Science Board Report, Resilient Military Systems and the Advanced Cyber Threat [DSB 2013], provides a sobering assessment of the vulnerabilities in the United States Government, the U.S. critical infrastructure, and the systems supporting the mission-essential operations and assets in the public and private sectors.

“…The Task Force notes that the cyber threat to U.S. critical infrastructure is outpacing efforts to reduce pervasive vulnerabilities, so that for the next decade at least the United States must lean significantly on deterrence to address the cyber threat posed by the most capable U.S. adversaries. It is clear that a more proactive and systematic approach to U.S. cyber deterrence is urgently needed…”

There is an urgent need to further strengthen the underlying information systems, component products, and services that we depend on in every sector of the critical infrastructure—ensuring that the systems, products, and services are sufficiently trustworthy throughout the system development life cycle (SDLC) and can provide the necessary resilience to support the economic and national security interests of the United States. System modernization, the increased use of automation, and the consolidation, standardization, and optimization of federal systems and networks to strengthen the protection for high value assets [OMB M-19-03], are key objectives for the federal government.

Executive Order (E.O.) 13800, Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure [EO 13800] recognizes the increasing interconnectedness of Federal information systems and requires heads of agencies to ensure appropriate risk management not only for the Federal agency’s enterprise, but also for the Executive Branch as a whole. The E.O. states:

“…The executive branch operates its information technology (IT) on behalf of the American people.

Its IT and data should be secured responsibly using all United States Government capabilities...”

“…Cybersecurity risk management comprises the full range of activities undertaken to protect IT and data from unauthorized access and other cyber threats, to maintain awareness of cyber threats, to detect anomalies and incidents adversely affecting IT and data, and to mitigate the impact of, respond to, and recover from incidents…”

OMB Memorandum M-17-25, Reporting Guidance for Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure [OMB M-17-25] provides implementation guidance to Federal agencies for E.O. 13800. The memorandum states:

“… An effective enterprise risk management program promotes a common understanding for recognizing and describing potential risks that can impact an agency’s mission and the delivery of services to the public. Such risks include, but are not limited to, strategic, market, cyber, legal, NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

PAGE vi

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

reputational, political, and a broad range of operational risks such as information security, human capital, business continuity, and related risks…”

“… Effective management of cybersecurity risk requires that agencies align information security management processes with strategic, operational, and budgetary planning processes…”

OMB Circular A-130, Managing Information as a Strategic Resource [OMB A-130], addresses responsibilities for protecting federal information resources and for managing personally identifiable information (PII). Circular A-130 requires agencies to implement the RMF that is described in this guideline and requires agencies to integrate privacy into the RMF process. In establishing requirements for information security programs and privacy programs, the OMB circular emphasizes the need for both programs to collaborate on shared objectives:

“While security and privacy are independent and separate disciplines, they are closely related, and it is essential for agencies to take a coordinated approach to identifying and managing security and privacy risks and complying with applicable requirements….”

This update to NIST Special Publication 800-37 (Revision 2) responds to the call by the Defense Science Board, the Executive Order, and the OMB policy memorandum to develop the next-generation Risk Management Framework (RMF) for information systems, organizations, and individuals.

There are seven major objectives for this update:

• To provide closer linkage and communication between the risk management processes and activities at the C-suite or governance level of the organization and the individuals, processes, and activities at the system and operational level of the organization;

• To institutionalize critical risk management preparatory activities at all risk management levels to facilitate a more effective, efficient, and cost-effective execution of the RMF;

• To demonstrate how the NIST Cybersecurity Framework [NIST CSF] can be aligned with the RMF and implemented using established NIST risk management processes;

• To integrate privacy risk management processes into the RMF to better support the privacy protection needs for which privacy programs are responsible;

• To promote the development of trustworthy secure software and systems by aligning life cycle-based systems engineering processes in NIST Special Publication 800-160, Volume 1 [SP 800-160 v1], with the relevant tasks in the RMF;

• To integrate security-related, supply chain risk management (SCRM) concepts into the RMF to address untrustworthy suppliers, insertion of counterfeits, tampering, unauthorized production, theft, insertion of malicious code, and poor manufacturing and development practices throughout the SDLC; and

• To allow for an organization-generated control selection approach to complement the traditional baseline control selection approach and support the use of the consolidated control catalog in NIST Special Publication 800-53, Revision 5.

The addition of the Prepare step is one of the key changes to the RMF—incorporated to achieve more effective, efficient, and cost-effective security and privacy risk management processes.

The primary objectives for institutionalizing organization-level and system-level preparation are:

NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

PAGE vii

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

• To facilitate effective communication between senior leaders and executives at the organization and mission/business process levels and system owners at the operational level;

• To facilitate organization-wide identification of common controls and the development of organizationally-tailored control baselines, reducing the workload on individual system owners and the cost of system development and asset protection;

• To reduce the complexity of the information technology (IT) and operations technology (OT) infrastructure using Enterprise Architecture concepts and models to consolidate, optimize, and standardize organizational systems, applications, and services;

• To reduce the complexity of systems by eliminating unnecessary functions and security and privacy capabilities that do not address security and privacy risk; and

• To identify, prioritize, and focus resources on the organization’s high value assets (HVA) that require increased levels of protection—taking measures commensurate with the risk to such assets.

By achieving the above objectives, organizations can simplify RMF execution, employ innovative approaches for managing risk, and increase the level of automation when carrying out specific tasks. Organizations implementing the RMF will be able to:

- Use the tasks and outputs of the Organization-Level and System-Level Prepare step to promote a consistent starting point within organizations to execute the RMF;

- Maximize the use of common controls at the organization level to promote standardized, consistent, and cost-effective security and privacy capability inheritance;

- Maximize the use of shared or cloud-based systems, services, and applications to reduce the number of authorizations needed across the organization;

- Employ organizationally-tailored control baselines to increase the speed of security and privacy plan development and the consistency of security and privacy plan content;

- Employ organization-defined controls based on security and privacy requirements generated from a systems security engineering process;

- Maximize the use of automated tools to manage security categorization; control selection, assessment, and monitoring; and the authorization process;

- Decrease the level of effort and resource expenditures for low-impact systems if those systems cannot adversely affect higher-impact systems through system connections;

- Maximize the reuse of RMF artifacts (e.g., security and privacy assessment results) for standardized hardware/software deployments, including configuration settings;

- Reduce the complexity of the IT/OT infrastructure by eliminating unnecessary systems, system components, and services — employing the least functionality principle; and

- Make the transition to ongoing authorization a priority and use continuous monitoring approaches to reduce the cost and increase the efficiency of security and privacy programs.

Recognizing that the preparation for RMF execution may vary from organization to organization, achieving the above objectives can reduce the overall IT/OT footprint and attack surface of

NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

PAGE viii

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

organizations, promote IT modernization objectives, conserve resources, prioritize security activities to focus protection strategies on the most critical assets and systems, and promote privacy protections for individuals.

NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

PAGE ix

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

COMMON SECURITY AND PRIVACY RISK FOUNDATIONS

In developing standards and guidelines, NIST consults with federal agencies, state, local, and tribal governments, and private sector organizations; avoids unnecessary and costly duplication of effort; and ensures that its publications are complementary with the standards and guidelines used for the protection of national security systems. In addition to implementing a transparent public review process for its publications, NIST collaborates with the Office of Management and Budget, the Office of the Director of National Intelligence, the Department of Defense, and the Committee on National Security Systems, and has established a unified risk management framework for the federal government. This common foundation provides the Civil, Defense, and Intelligence Communities of the federal government and their contractors, cost-effective, flexible, and consistent methods and techniques to manage security and privacy risks to organizational operations and assets, individuals, other organizations, and the Nation. The unified framework also provides a strong basis for reciprocal acceptance of assessment results and authorization decisions and facilitates information sharing and collaboration. NIST continues to work with public and private sector entities to establish mappings and relationships between its security and privacy standards and guidelines and those developed by external organizations.

NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

PAGE x

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

ACCEPTANCE OF SECURITY AND PRIVACY RISK

The Risk Management Framework addresses security and privacy risk from two perspectives— an information system perspective and a common controls perspective. For an information system, authorizing officials issue an authorization to operate or authorization to use for the system, accepting the security and privacy risks to the organization’s operations and assets, individuals, other organizations, and the Nation. For common controls, authorizing officials issue a common control authorization for a specific set of controls that can be inherited by designated organizational systems, accepting the security and privacy risks to the organization’s operations and assets, individuals, other organizations, and the Nation. Authorizing officials also consider the risk of inheriting common controls as part of their system authorizations. The different types of authorizations are described in Appendix F.

NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

PAGE xi

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

THE RMF IS TECHNOLOGY NEUTRAL

The RMF is purposefully designed to be technology neutral so that the methodology can be applied to any type of information system* without modification. While the specific controls selected, control implementation details, and control assessment methods and objects may vary with different types of IT resources, there is no need to adjust the RMF process to accommodate specific technologies.

All information systems process, store, or transmit some type of information. For example, information about the temperature in a remote facility collected and transmitted by a sensor to a monitoring station, location coordinates transmitted by radio to a controller on a weapons system, photographic images transmitted by a remote camera (land/satellite-based) to a server, or health IT devices transmitting patient information via a hospital network, require protection.

This information can be protected by: categorizing the information to determine the impact of loss; assessing whether the processing of the information could impact individuals’ privacy; and selecting and implementing controls that are applicable to the IT resources in use. Therefore, cloud-based systems, industrial/process control systems, weapons systems, cyber-physical systems, applications, IoT devices, or mobile devices/systems, do not require a separate risk management process but rather a tailored set of controls and specific implementation details determined by applying the existing RMF process.

The RMF is applied iteratively, as applicable, during the system development life cycle for any type of system development approach (including Agile and DevOps approaches). The security and privacy requirements and controls are implemented, verified, and validated as development progresses throughout the life cycle. This flexibility allows the RMF to support rapid technology cycles, innovation, and the use of current best practices in system and system component development.

* Note: The publication pertains to information systems, which are discrete sets of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information, whether such information is in digital or non-digital form. Information resources include information and related resources, such as personnel, equipment, funds, and information technology.

Therefore, information systems may or may not include hardware, firmware, and software.

NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

PAGE xii

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

USE OF AUTOMATION IN THE EXECUTION OF THE RMF

Organizations should maximize the use of automation, wherever possible, to increase the speed, effectiveness, and efficiency of executing the steps in the Risk Management Framework (RMF).

Automation is particularly useful in the assessment and continuous monitoring of controls, the preparation of authorization packages for timely decision-making, and the implementation of ongoing authorization approaches—together facilitating a real-time or near real-time risk-based decision-making process for senior leaders. Organizations have significant flexibility in deciding when, where, and how to use automation or automated support tools for their security and privacy programs. In some situations, automated assessments and monitoring of controls may not be possible or feasible.

NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

PAGE xiii

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

SCOPE AND APPLICABILITY

This publication is intended to help organizations manage security and privacy risk, and to satisfy the requirements in the Federal Information Security Modernization Act of 2014 (FISMA), the Privacy Act of 1974, OMB policies, and Federal Information Processing Standards, among other laws, regulations, and policies. The scope of this publication pertains to federal information systems, which are discrete sets of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information, whether such information is in digital or non-digital form. Information resources include information and related resources, such as personnel, equipment, funds, and information technology.

While mandatory for federal government use, the RMF can be applied to any type of nonfederal organization (e.g., business, industry, academia). As such, State, local, and tribal governments, as well as private sector organizations are encouraged to use these guidelines on a voluntary basis, as appropriate. In addition, nonfederal organizations that have adopted and implemented the Cybersecurity Framework might find value in using the RMF as a risk management process for execution of the Framework—providing the essential tasks for control implementation, assessment, and monitoring, as well as system authorizations (for risk-based decision making).

NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

PAGE xiv

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

MANAGING RISK

Using the Cybersecurity Framework

Executive Order (E.O.) 13800 requires federal agencies to modernize their IT infrastructure and systems and recognizes the increasing interconnectedness of federal information systems and networks. The E.O. also requires heads of agencies to manage risk at the agency level and across the Executive Branch using the Framework for Improving Critical Infrastructure Cybersecurity (i.e., Cybersecurity Framework). And finally, the E.O. reinforces the Federal Information Security Modernization Act (FISMA) of 2014 by holding heads of agencies responsible and accountable for managing the cybersecurity risk to their organizations.

The Cybersecurity Framework is adaptive to provide a flexible and risk-based implementation that can be used with a broad array of cybersecurity risk management processes. Therefore, consistent with OMB Memorandum M-17-25, the federal implementation of the Cybersecurity Framework fully supports the use of and is consistent with the risk management processes and approaches defined in [SP 800-39] and NIST Special Publication 800-37. This allows agencies to meet their concurrent obligations to comply with the requirements of FISMA and E.O. 13800.

Each task in the RMF includes references to specific sections in the Cybersecurity Framework.

For example, Task P-2, Risk Management Strategy, aligns with the Cybersecurity Framework Core [Identify Function]; Task P-4, Organizationally-Tailored Control Baselines and Cybersecurity Framework Profiles, aligns with the Cybersecurity Framework Profile construct; and Task R-5, Authorization Reporting, and Task M-5, Security and Privacy Reporting, support OMB reporting and risk management requirements organization-wide by using the Cybersecurity Framework constructs of Functions, Categories, and Subcategories. The Subcategory mappings to the [SP 800-53] controls are available at: https://www.nist.gov/cyberframework/federal-resources.

https://www.nist.gov/cyberframework/federal-resources

NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

PAGE xv

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

SECURITY AND PRIVACY IN THE RMF

Organizations are encouraged to collaborate on the plans, assessments, and plans of action and milestones (POAM) for security and privacy issues to maximize efficiency and reduce duplication of effort. The objective is to ensure that security and privacy requirements derived from laws, executive orders, directives, regulations, policies, standards, or missions and business functions are adequately addressed, and the appropriate controls are selected, implemented, assessed, and monitored on an ongoing basis. The authorization decision, a key step in the RMF, depends on the development of credible and actionable security and privacy evidence generated for the authorization package. Creating such evidence in a cost-effective and efficient manner is important.

The unified and collaborative approach to bring security and privacy evidence together in a single authorization package will support authorizing officials with critical information from security and privacy professionals to help inform the authorization decision. In the end, it is not about generating additional paperwork, artifacts, or documentation. Rather, it is about ensuring greater visibility into the implementation of security and privacy controls which will promote more informed, risk-based authorization decisions.

NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

PAGE xvi

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

Table of Contents

CHAPTER ONE INTRODUCTION

1.1 BACKGROUND

1.2 PURPOSE AND APPLICABILITY

1.3 TARGET AUDIENCE

1.4 ORGANIZATION OF THIS PUBLICATION

CHAPTER TWO THE FUNDAMENTALS

2.1 ORGANIZATION-WIDE RISK MANAGEMENT

2.2 RISK MANAGEMENT FRAMEWORK STEPS AND STRUCTURE

2.3 INFORMATION SECURITY AND PRIVACY IN THE RMF

2.4 SYSTEM AND SYSTEM ELEMENTS

2.5 AUTHORIZATION BOUNDARIES

2.6 REQUIREMENTS AND CONTROLS

2.7 SECURITY AND PRIVACY POSTURE

2.8 SUPPLY CHAIN RISK MANAGEMENT

CHAPTER THREE THE PROCESS

3.1 PREPARE

3.2 CATEGORIZE

3.3 SELECT

3.4 IMPLEMENT

3.5 ASSESS

3.6 AUTHORIZE

3.7 MONITOR

APPENDIX A REFERENCES

APPENDIX B GLOSSARY

APPENDIX C ACRONYMS

APPENDIX D ROLES AND RESPONSIBILITIES

APPENDIX E SUMMARY OF RMF TASKS

APPENDIX F SYSTEM AND COMMON CONTROL AUTHORIZATIONS

APPENDIX G AUTHORIZATION BOUNDARY CONSIDERATIONS

APPENDIX H SYSTEM LIFE CYCLE CONSIDERATIONS

NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

PAGE xvii

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

Errata

This table contains changes that have been incorporated into Special Publication 800-37. Errata updates can include corrections, clarifications, or other minor changes in the publication that are either editorial or substantive in nature.

DATE TYPE CHANGE PAGE

NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

CHAPTER ONE PAGE 1

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

CHAPTER ONE

INTRODUCTION

THE NEED TO MANAGE SECURITY AND PRIVACY RISK

rganizations depend on information systems1 to carry out their missions and business functions. The success of the missions and business functions depends on protecting the confidentiality, integrity, availability of information processed, stored, and transmitted by those systems and the privacy of individuals. The threats to information systems include equipment failure, environmental disruptions, human or machine errors, and purposeful attacks that are often sophisticated, disciplined, well-organized, and well-funded.2 When successful, attacks on information systems can result in serious or catastrophic damage to organizational operations3 and assets, individuals, other organizations, and the Nation.4 Therefore, it is imperative that organizations remain vigilant and that senior executives, leaders, and managers throughout the organization understand their responsibilities and are accountable for protecting organizational assets and for managing risk.5

In addition to the responsibility to protect organizational assets from the threats that exist in today’s environment, organizations have a responsibility to consider and manage the risks to individuals when information systems process personally identifiable information (PII).6 7 The information security and privacy programs implemented by organizations have complementary objectives with respect to managing the confidentiality, integrity, and availability of PII. While many privacy risks arise from unauthorized activities that lead to the loss of confidentiality, integrity, or availability of PII, other privacy risks result from authorized activities involving the creation, collection, use, processing, storage, maintenance, dissemination, disclosure, or disposal of PII that enables an organization to meet its mission or business objectives. For example, organizations could fail to provide appropriate notice of PII processing depriving an individual of knowledge of such processing or an individual could be embarrassed or stigmatized

1 An information system is a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information [44 USC 3502]. The term information system includes, for example, general-purpose computing systems; industrial/process control systems; cyber-physical systems; weapons systems; super computers; command, control, and communications systems; devices such as smart phones and tablets; environmental control systems; embedded devices/sensors; and paper-based systems.

2 Defense Science Board Task Force Report, Resilient Military Systems and the Advanced Cyber Threat [DSB 2013].

3 Organizational operations include mission, functions, image, and reputation.

4 Adverse impacts include, for example, compromises to systems supporting critical infrastructure applications or that are paramount to government continuity of operations as defined by the Department of Homeland Security.

5 Risk is a measure of the extent to which an entity is threatened by a potential circumstance or event. Risk is also a function of the adverse impacts that arise if the circumstance or event occurs, and the likelihood of occurrence. Types of risk include program risk; compliance/regulatory risk; financial risk; legal risk; mission/business risk; political risk;

security and privacy risk (including supply chain risk); project risk; reputational risk; safety risk; strategic planning risk.

6 [OMB A-130] defines PII as “information that can be used to distinguish or trace an individual’s identity, either alone or when combined with other information that is linked or linkable to a specific individual.”

7 Organizations may also choose to consider risks to individuals that may arise from interactions with information systems, where the processing of PII may be less impactful than the effect the system has on individuals’ behavior or activities. Such effects would constitute risks to individual autonomy and organizations may need to take steps to manage those risks in addition to information security and privacy risks.

O

NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

CHAPTER ONE PAGE 2

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

by the authorized disclosure of PII. While managing privacy risk requires close coordination between information security and privacy programs due to the complementary nature of the programs’ objectives around the confidentiality, integrity, and availability of PII, privacy risks also raise distinct concerns that require specialized expertise and approaches. Therefore, it is critical that organizations also establish and maintain robust privacy programs to ensure compliance with applicable privacy requirements and to manage the risk to individuals associated with the processing of PII.

Closely related to, and a part of security and privacy risks, supply chain risk8 is also of growing concern to organizations. Because of the increased reliance on third-party or external providers and commercial-off-the-shelf products, systems, and services, attacks or disruptions in the supply chain which impact an organization’s systems are increasing. Such attacks can be difficult to trace or manage and can result in serious, severe, or catastrophic consequences for an organization’s systems. Supply chain risk management (SCRM) overlaps and works in harmony with security and privacy risk management. This publication integrates security and privacy risk management practices associated with SCRM into the RMF to help promote a comprehensive approach to managing security and privacy risk. While the publication is principally focused on managing information security and privacy risk, SCRM concepts that support security and privacy risk management are specifically called out in several areas to add emphasis and to clarify how they can be addressed using the RMF.

1.1 BACKGROUND

NIST in its partnership with the Department of Defense, the Office of the Director of National Intelligence, and the Committee on National Security Systems, developed a Risk Management Framework (RMF) to improve information security, strengthen risk management processes, and encourage reciprocity9 among organizations. In July 2016, the Office of Management and Budget (OMB) revised Circular A-130 to include responsibilities for privacy programs under the

RMF.

The RMF emphasizes risk management by promoting the development of security and privacy capabilities into information systems throughout the system development life cycle (SDLC);10 by maintaining situational awareness of the security and privacy posture of those systems on an ongoing basis through continuous monitoring processes; and by providing information to senior leaders and executives to facilitate decisions regarding the acceptance of risk to organizational operations and assets, individuals, other organizations, and the Nation arising from the use and operation of their systems. The RMF:

• Provides a repeatable process designed to promote the protection of information and information systems commensurate with risk;

• Emphasizes organization-wide preparation necessary to manage security and privacy risks;

8 SCRM requirements are promulgated in [OMB A-130], [DODI 5200.44], and for national security systems in [CNSSD 505]. SCRM requirements have also been addressed by the Federal SCRM Policy Coordinating Committee.

9 Reciprocity is an agreement between organizations to accept one another’s security assessment results in order to reuse system resources or to accept each other’s assessed security posture in order to share information.

10 [SP 800-64] and [SP 800-160 v1] provide guidance on security considerations in the SDLC.

NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

CHAPTER ONE PAGE 3

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

• Facilitates the categorization of information and systems, the selection, implementation, assessment, and monitoring of controls, and the authorization of information systems and common controls;11

• Promotes the use of automation for near real-time risk management and ongoing system and control authorization through the implementation of continuous monitoring processes;

• Encourages the use of correct and timely metrics to provide senior leaders and managers with the necessary information to make cost-effective, risk-based decisions for information systems supporting their missions and business functions;

• Facilitates the integration of security and privacy requirements12 and controls into enterprise architecture,13 SDLC, acquisition processes, and systems engineering processes;

• Connects risk management processes at the organization and mission/business process levels to risk management processes at the information system level through a senior accountable official for risk management and risk executive (function);14 and

• Establishes responsibility and accountability for controls implemented within information systems and inherited by those systems.

The RMF provides a dynamic and flexible approach to effectively manage security and privacy risks in diverse environments with complex and sophisticated threats, evolving missions and business functions, and changing system and organizational vulnerabilities. The framework is policy and technology neutral, which facilitates ongoing upgrades to IT resources15 and to IT modernization efforts—to support and help ensure essential missions and services are provided during such transition periods.

1.2 PURPOSE AND APPLICABILITY

This publication describes the RMF and provides guidelines for managing security and privacy risks and applying the RMF to information systems and organizations. The guidelines have been developed:

• To ensure that managing system-related security and privacy risk is consistent with the mission and business objectives of the organization and risk management strategy established by the senior leadership through the risk executive (function);

• To achieve privacy protections for individuals and security protections for information and information systems through the implementation of appropriate risk response strategies;

• To support consistent, informed, and ongoing authorization decisions,16 reciprocity, and the transparency and traceability of security and privacy information;

11 Chapter 3 describes the seven steps and associated tasks in the RMF.

12 Section 2.6 describes the relationship between requirements and controls with respect to RMF execution.

13 [OMB FEA] provides guidance on the Federal Enterprise Architecture.

14 [OMB M-17-25] provides guidance on risk management roles and responsibilities.

15 IT resources refer to the information technology component of information resources defined in [OMB A-130].

16 [SP 800-137] provides guidance on information security continuous monitoring supporting ongoing authorization.

Future publications will address privacy continuous monitoring.

NIST SP 800-37, REVISION 2 RISK MANAGEMENT FRAMEWORK FOR INFORMATION SYSTEMS AND ORGANIZATIONS

CHAPTER ONE PAGE 4

This publication is available free of charge from : https://doi.org/10.6028/N

IST.S

• To facilitate the integration of security and privacy requirements and controls into the enterprise architecture, SDLC processes, acquisition processes, and systems engineering processes;17 and

• To facilitate the implementation of the Framework for Improving Critical Infrastructure Cybersecurity [NIST CSF] within federal agencies.18

This publication is intended to help organizations19 manage security and privacy risk and to satisfy the requirements in the Federal Information Security Modernization Act of 2014 [FISMA], the Privacy Act of 1974 [PRIVACT], OMB policies, and designated Federal Information Processing Standards, among other laws, regulations, and policies.

The scope of this publication pertains to federal information systems, which are discrete sets of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information, whether such information is in digital or non-digital form. Information resources include information and related resources, such as personnel, equipment, funds, and information technology.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .