Back to Frameworks

NIST SP 800-37 Rev 2

United States
vRev 2
7 domains
47 controls

NIST SP 800-37 Revision 2 Risk Management Framework for Information Systems and Organizations.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

Assess

6 controls
Controls in the Assess domain of NIST SP 800-37 Rev 26 controls
CodeTitle
A-1Assessor Selection
A-2Assessment Plan
A-3Control Assessments
A-4Assessment Reports
A-5Remediation Actions
A-6Plan of Action and Milestones

Authorize

5 controls
Controls in the Authorize domain of NIST SP 800-37 Rev 25 controls
CodeTitle
R-1Authorization Package
R-2Risk Analysis and Determination
R-3Risk Response
R-4Authorization Decision
R-5Authorization Reporting

Categorize

3 controls
Controls in the Categorize domain of NIST SP 800-37 Rev 23 controls
CodeTitle
C-1System Description
C-2Security Categorization
C-3Categorization Decision

Implement

2 controls
Controls in the Implement domain of NIST SP 800-37 Rev 22 controls
CodeTitle
I-1Control Implementation
I-2Update Control Implementation Information

Monitor

7 controls
Controls in the Monitor domain of NIST SP 800-37 Rev 27 controls
CodeTitle
M-1System and Environment Changes
M-2Ongoing Assessments
M-3Ongoing Risk Response
M-4Authorization Package Updates
M-5Security and Privacy Reporting
M-6Ongoing Authorization
M-7System Disposal

Prepare

18 controls
Controls in the Prepare domain of NIST SP 800-37 Rev 218 controls
CodeTitle
P-1Risk Management Roles
P-10Asset Identification
P-11Authorization Boundary
P-12Information Types
P-13Information Life Cycle
P-14Risk Assessment System
P-15Requirements Definition
P-16Enterprise Architecture Alignment
P-17Requirements Allocation
P-18System Registration
P-2Risk Management Strategy
P-3Risk Assessment Organization
P-4Organizationally-Tailored Control Baselines
P-5Common Control Identification
P-6Impact-Level Prioritization
P-7Continuous Monitoring Strategy Organization
P-8Mission or Business Focus
P-9System Stakeholders

Select

6 controls
Controls in the Select domain of NIST SP 800-37 Rev 26 controls
CodeTitle
S-1Control Selection
S-2Control Tailoring
S-3Control Allocation
S-4Documentation of Planned Control Implementations
S-5Continuous Monitoring Strategy System
S-6Plan Review and Approval

Frequently Asked Questions

What is NIST SP 800-37 Rev 2?

NIST SP 800-37 Rev 2 is a compliance framework from United States with 7 domains and 47 controls. NIST SP 800-37 Revision 2 Risk Management Framework for Information Systems and Organizations. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does NIST SP 800-37 Rev 2 have?

NIST SP 800-37 Rev 2 has 47 controls organised across 7 domains. The largest domains are Prepare (18 controls), Monitor (7 controls), Assess (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does NIST SP 800-37 Rev 2 map to?

NIST SP 800-37 Rev 2 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with NIST SP 800-37 Rev 2 compliance?

Start your NIST SP 800-37 Rev 2 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-37 Rev 2 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 47 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 768 frameworks.

Get Started Free →

Free forever — no credit card required