By Cyber Defense Technologies February 10, 2026 5 min read
The Risk Management Framework (RMF) is the process federal agencies, including the Department of War (DoW), use to secure information systems and decide whether they may operate. It is defined in NIST Special Publication 800-37 Revision 2. The Department implements it through DoD Instruction 8510.01, and national security systems follow Committee on National Security Systems guidance such as CNSSI 1253.
RMF can look like paperwork. Done well, it is a disciplined way to understand a system's risk, build the right protections, verify them, and keep them working.
The Risk Management Framework (NIST SP 800-37 Rev. 2)
-
1 Prepare
Establish context, roles, risk strategy and common controls.
-
2 Categorize
Determine impact levels for the system and its information.
-
3 Select
Choose and tailor the control baseline.
-
4 Implement
Put controls in place and document how.
-
5 Assess
Determine whether controls work as intended.
-
6 Authorize
An authorizing official accepts the residual risk.
-
7 Monitor
Track changes, reassess and report continuously.
Monitoring feeds back into every step for the life of the system.
Step 1: Prepare
Preparation happens at two levels. At the organization level, leadership establishes risk management roles, a risk management strategy, and common controls that many systems can inherit, such as physical security or enterprise identity. At the system level, the team identifies the mission or business function the system supports, its stakeholders, its assets and its boundary.
Key outputs: roles assigned, system boundary and description, a list of common controls available for inheritance.
Step 2: Categorize
The system and its information are categorized by the potential impact of a loss of confidentiality, integrity or availability. Civilian systems use FIPS 199 and NIST SP 800-60; national security systems use CNSSI 1253, which rates each security objective separately as low, moderate or high.
Categorization drives everything after it, so it deserves care. Over-categorizing adds unnecessary cost; under-categorizing leaves the system underprotected and invites challenge later.
Key outputs: security categorization, approved by the authorizing official or designee.
Step 3: Select
Based on the categorization, the team selects a control baseline from NIST SP 800-53 (or the CNSSI 1253 baseline), then tailors it: adding controls for specific threats or technologies, applying overlays for special cases such as classified information or cross-domain solutions, and removing controls that genuinely do not apply, with justification.
Key outputs: tailored control set, identification of common and hybrid controls, and a continuous monitoring strategy.
Step 4: Implement
The controls are put in place and documented. This includes technical settings, such as DISA Security Technical Implementation Guides (STIGs), as well as processes and procedures. The System Security Plan describes how each control is implemented.
The most important advice for this step: implement during design and build, not afterward. Retrofitting controls into a finished system is where schedules slip.
Key outputs: implemented controls, updated System Security Plan, configuration baselines.
Step 5: Assess
An assessor, independent of the system's developers and operators to the degree the authorizing official requires, determines whether controls are implemented correctly, operating as intended and producing the desired outcome. Assessors use the methods described in NIST SP 800-53A: examining documents and settings, interviewing people and testing controls.
Key outputs: security assessment report, and a Plan of Action and Milestones for weaknesses found.
Step 6: Authorize
The authorizing official (AO), a senior leader with the authority to accept risk on behalf of the organization, reviews the authorization package: the security plan, the assessment report and the POA&M. The AO then decides whether the residual risk is acceptable.
Under DoDI 8510.01, possible decisions include an authorization to operate (ATO), an ATO with conditions, and a denial of authorization. An interim authorization to test (IATT) may allow testing in an operational environment before the full decision.
Key outputs: authorization decision document, with any terms and conditions.
Step 7: Monitor
Authorization is not the end. The system and its environment change, new vulnerabilities appear, and threats evolve. Continuous monitoring tracks changes, reassesses controls on a schedule, remediates findings, updates documentation and reports security status to the AO. Mature programs use this information to support ongoing authorization rather than periodic reauthorization.
Key outputs: ongoing assessments, updated POA&Ms, security status reports.
The tools of the trade
In the Department, RMF packages are typically managed in the Enterprise Mission Assurance Support Service (eMASS), and technical compliance is evidenced with vulnerability scans, STIG checklists and automated compliance tools. The tools matter less than the discipline: accurate documentation, verified controls and honest reporting.
Where programs lose time
- Late engagement. Bringing cybersecurity in after the design is fixed.
- Unclear boundaries. Disputes over what is in the system slow every step.
- Paper controls. Documentation that describes intentions rather than configurations.
- Assessment surprises. No internal validation before the formal assessment.
- Stale POA&Ms. Weaknesses with dates that have passed and no explanation.
Who does what in RMF
RMF works when roles are clear. The main ones, as defined in NIST SP 800-37 and applied in the Department of War:
- Authorizing official (AO): the senior leader who accepts risk and makes the authorization decision.
- System owner: responsible for the system's development, operation and compliance, including the authorization package.
- Information system security manager (ISSM): oversees the security program for one or more systems and maintains the security posture.
- Information system security officer (ISSO): carries out day-to-day security tasks for the system, often under the ISSM.
- Security control assessor: independently assesses whether controls are implemented and effective.
- Common control provider: the organization that provides controls many systems inherit, such as a data center or enterprise identity service.
When a program cannot name the person in each role, that gap is usually the first thing to fix.
Frequently asked questions
How long does RMF take? It depends on the system's size, complexity, categorization and how early security was built in. Systems designed with RMF in mind move far faster than those retrofitted at the end.
Is RMF the same for classified systems? The process is the same, but national security systems use CNSSI 1253 for categorization and control baselines, and overlays add requirements for classified information and cross-domain solutions.
Can we reuse another system's authorization? You can often inherit controls from authorized platforms and use reciprocity for components already assessed, reducing effort. The AO decides what is accepted.
How CDT can help
CDT supports every RMF step, from categorization and control selection to implementation, assessment preparation and continuous monitoring, through our RMF, A&A and ATO, system hardening and security control assessment services.