NIST SP 800-37
RMF Step 0 - Prepare

NIST SP 800-37 1: RMF Prepare Step: Organisation-Level and System-Level Preparation

Execute the Prepare step of the NIST SP 800-37 Rev 2 Risk Management Framework per Chapter 3 Step 1 (Prepare). Prepare establishes context and priorities for managing security and privacy risk at the organisational level (Tasks P-1 through P-7) and at the system level (Tasks P-8 through P-18). Organisation-level tasks include (P-1) risk management roles, (P-2) risk management strategy, (P-3) risk assessment, (P-4) organisationally-tailored control baselines and cybersecurity framework profiles, (P-5) common control identification, (P-6) impact-level prioritisation, (P-7) continuous monitoring strategy. System-level tasks include (P-8) mission/business focus, (P-9) system stakeholders, (P-10) asset identification, (P-11) authorisation boundary, (P-12) information types, (P-13) information life cycle, (P-14) risk assessment for the system, (P-15) requirements definition, (P-16) enterprise architecture alignment, (P-17) requirements allocation, (P-18) system registration. Outputs feed every subsequent RMF step.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.