FWK

Frameworks & steps

The named steps inside NIST's major frameworks, explained one at a time.

19 terms

A handful of US frameworks come up constantly in security and AI governance conversations, and most people have only heard their acronyms. These are the actual steps and functions inside them, each explained as its own term and linked back to the parent framework.

NIST Risk Management Framework (RMF)

Showing 19 of 19
Assess Step 5 of the RMF — an independent check on whether controls actually work. NIST RMF · Step 5 of 7 Authorize Step 6 of the RMF — a senior official formally approves the system to run. NIST RMF · Step 6 of 7 Categorize Step 2 of the RMF — classify the system by how much a loss would hurt. NIST RMF · Step 2 of 7 Detect The CSF function for spotting attacks and compromises as they happen. NIST CSF 2.0 · Detect Govern The CSF 2.0 function for setting strategy, roles, and executive oversight. NIST CSF 2.0 · Govern Govern The AI RMF function for setting accountability and policy for AI risk. NIST AI RMF · Govern Identify The CSF function for cataloguing assets, data, and risk before protecting them. NIST CSF 2.0 · Identify Implement Step 4 of the RMF — actually put the chosen controls in place. NIST RMF · Step 4 of 7 Manage The AI RMF function for treating AI risk and responding when something goes wrong. NIST AI RMF · Manage Map The AI RMF function for understanding a specific AI system's context and risks. NIST AI RMF · Map Measure The AI RMF function for actually measuring and tracking identified AI risk. NIST AI RMF · Measure Monitor Step 7 of the RMF — ongoing tracking of security after the system is live. NIST RMF · Step 7 of 7 NIST Risk Management Framework (RMF) A seven-step US federal process for authorizing and monitoring a system's security. NIST SP 800-37 Plan-Do-Check-Act (PDCA) The Plan-Do-Check-Act cycle that Clauses 4–10 of every ISO management standard follow. ISO Harmonized Structure Prepare Step 1 of the RMF — set priorities and groundwork before anything else. NIST RMF · Step 1 of 7 Protect The CSF function for putting safeguards in place to manage known risk. NIST CSF 2.0 · Protect Recover The CSF function for restoring normal operations after an incident. NIST CSF 2.0 · Recover Respond The CSF function for acting on an incident while it's actively happening. NIST CSF 2.0 · Respond Select Step 3 of the RMF — choose the controls that fit the system's risk level. NIST RMF · Step 3 of 7