Computer Security Resource Center

Computer Security Resource Center

Computer Security
Resource Center

ITL Bulletin

The Next Generation Risk Management Framework (RMF 2.0): A Holistic Methodology to Manage Information Security, Privacy and Supply Chain Risk

Date Published: February 2019

Editor(s)

Victoria Pillitteri (NIST)

Abstract

Keywords

authorization to operate; authorization to use; authorizing official; continuous monitoring; information security; ongoing authorization; plan of action and milestones; privacy; privacy plan; privacy risk; risk assessment; risk executive function; risk management; risk management framework; security; security assessment report; security engineering; security plan; security risk; supply chain risk management; system development life cycle
Control Families

Configuration Management; Security Assessment and Authorization; Risk Assessment; Planning; Program Management;

Documentation

Publication:
February 2019 ITL Bulletin

Supplemental Material:
None available

Related NIST Publications:
SP 800-37 Rev. 2