FWK

NIST Risk Management Framework RMF

NIST SP 800-37

A seven-step process, defined in NIST SP 800-37, for selecting, implementing, and monitoring security and privacy controls on a federal information system: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor.

For small firms

Even outside federal contracting, the sequence is a clean mental model for rolling out controls on any new system.