Frameworks & steps
The named steps inside NIST's major frameworks, explained one at a time.
19 terms
A handful of US frameworks come up constantly in security and AI governance conversations, and most people have only heard their acronyms. These are the actual steps and functions inside them, each explained as its own term and linked back to the parent framework.
NIST Risk Management Framework (RMF)
Showing 19 of 19
Assess
Step 5 of the RMF — an independent check on whether controls actually work.
NIST RMF · Step 5 of 7
Authorize
Step 6 of the RMF — a senior official formally approves the system to run.
NIST RMF · Step 6 of 7
Categorize
Step 2 of the RMF — classify the system by how much a loss would hurt.
NIST RMF · Step 2 of 7
Detect
The CSF function for spotting attacks and compromises as they happen.
NIST CSF 2.0 · Detect
Govern
The CSF 2.0 function for setting strategy, roles, and executive oversight.
NIST CSF 2.0 · Govern
Govern
The AI RMF function for setting accountability and policy for AI risk.
NIST AI RMF · Govern
Identify
The CSF function for cataloguing assets, data, and risk before protecting them.
NIST CSF 2.0 · Identify
Implement
Step 4 of the RMF — actually put the chosen controls in place.
NIST RMF · Step 4 of 7
Manage
The AI RMF function for treating AI risk and responding when something goes wrong.
NIST AI RMF · Manage
Map
The AI RMF function for understanding a specific AI system's context and risks.
NIST AI RMF · Map
Measure
The AI RMF function for actually measuring and tracking identified AI risk.
NIST AI RMF · Measure
Monitor
Step 7 of the RMF — ongoing tracking of security after the system is live.
NIST RMF · Step 7 of 7
NIST Risk Management Framework (RMF)
A seven-step US federal process for authorizing and monitoring a system's security.
NIST SP 800-37
Plan-Do-Check-Act (PDCA)
The Plan-Do-Check-Act cycle that Clauses 4–10 of every ISO management standard follow.
ISO Harmonized Structure
Prepare
Step 1 of the RMF — set priorities and groundwork before anything else.
NIST RMF · Step 1 of 7
Protect
The CSF function for putting safeguards in place to manage known risk.
NIST CSF 2.0 · Protect
Recover
The CSF function for restoring normal operations after an incident.
NIST CSF 2.0 · Recover
Respond
The CSF function for acting on an incident while it's actively happening.
NIST CSF 2.0 · Respond
Select
Step 3 of the RMF — choose the controls that fit the system's risk level.
NIST RMF · Step 3 of 7
No terms match your search.