NIST Risk Management Framework RMF
NIST SP 800-37A seven-step process, defined in NIST SP 800-37, for selecting, implementing, and monitoring security and privacy controls on a federal information system: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor.
For small firms
Even outside federal contracting, the sequence is a clean mental model for rolling out controls on any new system.