NIST SP 800-37: NIST Special Publication 800-37 presents guidelines for applying the Risk Management Framework to federal information systems. It includes processes for identifying and classifying information system assets, identifying relevant threats, determining risk, selecting and implementing appropriate controls, and documenting the process. The goal is to provide a structured and scalable approach for managing risk to information systems and to promote near real-time risk management.
Categories: CC D1: Security Principles | CCSP D6: Legal - Risk and Compliance | CISM D1: Information Security governance | CISSP D1: Security and Risk Management | Security+ D5: Security Program Management and Oversight | SSCP D3: Risk Identification Monitoring and Analysis
« Back to Glossary Index