Risk Management Framework (RMF) (NIST): The National Institute of Standards and Technology (NIST) framework for managing information security risks in federal agencies. It provides a systematic and repeatable process for identifying, evaluating, and mitigating risks to information systems and data. Examples of agencies using the RMF include the Department of Defense and the Department of Homeland Security.
Categories: CC D1: Security Principles | CCSP D6: Legal - Risk and Compliance | CISM D2: Information security risk management | CISSP D1: Security and Risk Management | Security+ D5: Security Program Management and Oversight | SSCP D3: Risk Identification Monitoring and Analysis
« Back to Glossary Index