U.S. flag   An official website of the United States government

NIST Risk Management Framework RMF

Risk Management Framework (RMF) - Authorize Step

At A Glance

RMF Authorize Step



Purpose: Provide  accountability by requiring a senior official to determine if the security and privacy risk based on the operation of a system or the use of common controls, is acceptable.

  • authorization package (executive summary, system security and privacy plan, assessment report(s), plan of action and milestones)
  • risk determination rendered
  • risk responses provided
  • authorization for the system or common controls is approved or denied

Resources for Implementers

There are additional supporting publications for the Authorize Step.


Back to About the RMF

Created November 30, 2016, Updated April 14, 2021