NIST SP 800-37
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Cross-Cutting Roles and Functions
Operate the cross-cutting roles and functions defined throughout NIST SP 800-37 Rev 2 Chapter 2 (Fundamentals). Cross-cutting elements include (a) RMF Roles per Chapter 2 (Risk Executive Function + Chief Information Officer + Senior Agency Information Security Officer + Senior Agency Privacy Officer + Authorising Official + System Owner + Common Control Provider + Control Assessor + Information System Security Officer + Mission/Business Owner + Information Owner/Steward), (b) Risk Executive Function aggregating risk across systems for organisational risk decisions, (c) Automation enabling Ongoing Authorisation (OSCAL + configuration scanning + control inheritance evidence + continuous monitoring telemetry), (d) Privacy Integration with security in every step (joint SSPP + joint SAR + joint POAM where privacy controls apply), (e) Supply Chain Risk Management (SCRM) integration per NIST SP
- named individuals or roles for the 11 RMF roles per system + organisation
- Risk Executive Function charter + cadence + risk aggregation outputs
- OSCAL or equivalent automation enabling Ongoing Authorisation
- joint security and privacy artefacts (SSPP + SAR + POAM) where privacy controls apply
- SCRM integration evidence per SP 800-161
- ATO maintenance log showing ongoing authorisation + significant change re-authorisation + termination on disposal
- Risk Executive Function not staffed or not consuming RMF outputs
- privacy treated as separate process producing parallel artefacts inconsistent with security RMF
- SCRM not integrated into Select or Assess
- ATO maintenance gaps so disposed systems retain authorisation while operating systems are unauthorised
RMF Step 0 - Prepare
Execute the Prepare step of the NIST SP 800-37 Rev 2 Risk Management Framework per Chapter 3 Step 1 (Prepare). Prepare establishes context and priorities for managing security and privacy risk at the organisational level (Tasks P-1 through P-7) and at the system level (Tasks P-8 through P-18). Organisation-level tasks include (P-1) risk management roles, (P-2) risk management strategy, (P-3) risk assessment, (P-4) organisationally-tailored control baselines and cybersecurity framework profiles, (P-5) common control identification, (P-6) impact-level prioritisation, (P-7) continuous monitoring strategy. System-level tasks include (P-8) mission/business focus, (P-9) system stakeholders, (P-10) asset identification, (P-11) authorisation boundary, (P-12) information types, (P-13) information life cycle, (P-14) risk assessment for the system, (P-15) requirements definition, (P-16) enterprise
- organisation-level Prepare evidence covering P-1 risk roles + P-2 strategy + P-3 risk assessment + P-4 tailored baselines + P-5 common controls + P-6 prioritisation + P-7 ConMon strategy
- system-level Prepare evidence per system covering P-8 mission focus + P-9 stakeholders + P-10 assets + P-11 boundary + P-12 information types + P-13 lifecycle + P-14 system risk assessment + P-15-18 requirements/architecture/allocation/registration
- common control catalogue with inheritance instructions
- organisational Prepare tasks P-1 through P-7 not completed before system authorisations begin
- no common control catalogue so every system re-implements baseline controls
- system Prepare done by procurement/architecture without security and privacy input
RMF Step 1 - Categorize
Execute the Categorize step per NIST SP 800-37 Rev 2 Chapter 3 Step 2. Categorise the information processed, stored, and transmitted by the system and the system itself per the impact levels in FIPS 199 (Low, Moderate, High) for confidentiality + integrity + availability. Tasks include (C-1) document system characteristics, (C-2) identify information types per NIST SP 800-60 guidance, (C-3) determine provisional and adjusted impact levels per information type, (C-4) determine system security categorisation (high water mark across information types), (C-5) review and approve security categorisation. Categorisation determines control baseline selection and is the foundation for the Authorize decision.
- FIPS 199 security categorisation worksheet per system with CIA impact rationale
- information types inventory per NIST SP 800-60 with categorisation per type
- approved categorisation decision signed by senior agency information security and privacy officials
- categorisation done by IT staff alone without information owner input
- high water mark not applied across information types
- categorisation rationale not documented so cannot be defended at Authorize
RMF Step 2 - Select
Execute the Select step per NIST SP 800-37 Rev 2 Chapter 3 Step 3. Select an initial set of security and privacy controls from NIST SP 800-53 Rev 5 (or successor) commensurate with the system categorisation, then tailor the baseline (adding, removing, scoping, parameterising, supplementing with overlays for sectoral or mission-specific requirements). Tasks include (S-1) select control baselines per FIPS 200 + SP 800-53B (Low/Moderate/High), (S-2) tailor controls (designating common, system-specific, hybrid), (S-3) allocate controls to specific implementation responsibilities, (S-4) document control selections in the System Security and Privacy Plan (SSPP), (S-5) develop continuous monitoring strategy aligned with control selections, (S-6) review and approve SSPP. Apply overlays (e.g. FedRAMP, CNSSI 1253, IRS Pub 1075) where required by mission, regulation, or contract.
- System Security and Privacy Plan (SSPP) with selected controls + tailoring rationale + overlay application
- control allocation showing common / system-specific / hybrid designation per control
- ConMon strategy aligned with control selections
- SSPP uses unmodified baseline without tailoring rationale
- common controls not inherited explicitly
- overlays (FedRAMP / CNSSI 1253 / IRS) not applied where required
RMF Step 3 - Implement
Execute the Implement step per NIST SP 800-37 Rev 2 Chapter 3 Step 4. Implement the controls selected in Step 2 and document how the controls are employed in the system and environment of operation. Tasks include (I-1) implement security and privacy controls per SSPP, (I-2) update SSPP with as-built implementation details (settings, configurations, evidence locations). Implementation must produce machine-readable evidence where feasible (configuration scanning results, IaC repositories with policy-as-code, build provenance) and preserve traceability from control selection through configuration through evidence collection.
- updated SSPP with as-built control implementation details + configuration settings + evidence locations
- automated control implementation evidence (configuration scan + IaC policy + build provenance) where feasible
- manual evidence collection cadence and owner where automation absent
- SSPP not updated post-implementation so it describes intent not reality
- no machine-readable evidence even where automation exists
- control implementation evidence scattered across teams without consolidation
RMF Step 4 - Assess
Execute the Assess step per NIST SP 800-37 Rev 2 Chapter 3 Step 5. Determine whether controls selected for implementation are implemented correctly + operating as intended + producing the desired outcome with respect to meeting the security and privacy requirements. Tasks include (A-1) select assessor (independent + appropriately qualified + with documented assessment plan reviewed and approved), (A-2) develop security and privacy assessment plans (SAP) aligned with SP 800-53A assessment procedures, (A-3) review and approve assessment plans, (A-4) assess controls per the SAP using examine + interview + test methods, (A-5) develop security and privacy assessment reports (SAR), (A-6) initial remediation actions on findings, (A-7) develop Plan of Action and Milestones (POAM) for unremediated findings. Assessment outputs feed the Authorize decision.
- assessor selection record demonstrating independence per SP 800-37 Rev 2 + SP 800-53A
- approved Security and Privacy Assessment Plan (SAP) per system
- Security and Privacy Assessment Report (SAR) with findings + evidence + assessor signature
- POAM with milestones + ownership + risk-based scheduling for unremediated findings
- assessor not independent or independence not documented
- SAP not approved before assessment
- POAM aging beyond AO tolerance with no escalation
- initial remediation skipped pushing all findings to POAM
RMF Step 5 - Authorize
Execute the Authorize step per NIST SP 800-37 Rev 2 Chapter 3 Step 6. The Authorising Official (AO) reviews the authorisation package (SSPP + SAR + POAM + executive summary) and makes one of three decisions: (a) Authorisation to Operate (ATO) granted (with or without conditions and risk acceptance), (b) Common Control Authorisation, or (c) Denial of Authorisation. Tasks include (R-1) assemble authorisation package, (R-2) risk determination by AO informed by Risk Executive Function and risk assessment outputs (NIST SP 800-30), (R-3) risk response determination (accept + avoid + mitigate + share + transfer), (R-4) authorisation decision and ATO letter with conditions, (R-5) authorisation reporting to senior leadership + risk owners + system stakeholders. Ongoing Authorisation Maintenance must keep ATO current as risk posture evolves.
- complete authorisation package (SSPP + SAR + POAM + executive summary)
- AO risk determination informed by Risk Executive Function input
- ATO letter with conditions + time bound or ongoing authorisation flag + risk acceptance rationale
- authorisation reporting to leadership + stakeholders
- ATO renewed on schedule despite incomplete package
- AO risk acceptance not documented or not informed by Risk Executive Function
- ATO conditions not tracked through to completion
RMF Step 6 - Monitor
Execute the Monitor step per NIST SP 800-37 Rev 2 Chapter 3 Step 7. Maintain ongoing situational awareness of the security and privacy posture of the system to support risk management decisions. Tasks include (M-1) monitor system and environment changes (configuration drift + boundary changes + dependency changes + threat changes), (M-2) ongoing control assessments per the continuous monitoring strategy, (M-3) ongoing risk response (re-categorisation + re-selection + re-implementation + re-assessment as posture changes), (M-4) authorisation package updates with current state, (M-5) security and privacy reporting (dashboards + status reports + incident impact on authorisation), (M-6) ongoing authorisation (re-authorise based on continuous evidence rather than calendar). NIST SP 800-137 (Information Security Continuous Monitoring) provides the operational guidance for this step.
- ConMon execution evidence aligned with strategy + control-by-control monitoring frequency + automation status
- ongoing authorisation decision record showing data-driven re-authorisation rather than calendar-driven
- system and environment change log with re-authorisation triggers
- ConMon dashboards consumed by Risk Executive Function and AO
- ConMon plan documented but not executed against
- calendar-driven re-authorisation despite Rev 2 ongoing-authorisation guidance
- ConMon data not consumed by AO or Risk Executive Function so it has no effect on decisions
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-37 framework page.