ASOM-Fedv6.1Open the explorer
Lifecycle · National Institute of Standards and Technology

Risk Management Framework for Information Systems and Organizations

The seven-step lifecycle — prepare, categorize, select, implement, assess, authorize, monitor — that governs how a federal system is authorized to operate and kept under continuous monitoring.

7/7Lifecycle steps fedEvery step receives an artifact. Not one receives the document the step is graded on.
37Controls carrying itEach with an evidence artifact and an assessment procedure
4Stated boundariesWhat this framework does not do for this regime
The Claim

What This Framework Contributes.

The framework feeds RMF and produces none of its artifacts. Every step below receives something; not one of them receives the document the step is actually graded on.

The Boundary

What it does not do for RMF · SP 800-37.

Read this before the crosswalk, not after it. A reader who takes the mappings below as coverage of RMF · SP 800-37 will be wrong in a way that is expensive to discover later.

Step by Step

What the Loop Hands to the Lifecycle.

Which cycle step produces each artifact below is derived, not asserted: it is read from the products index, which is itself built from the controls’ own declared outputs. Three modules would have to agree to lie for this to be wrong.

Prepare

5 artifacts · 10 controls

Carry out the essential activities at organization, mission and system level that make risk management possible at all — roles, strategy, boundary, asset identification, and a continuous monitoring strategy.

Fed fromFrameMap

  • Cyber Terrain OverlayProduced at Map

    The positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.

  • The zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration.

  • Workforce terrain registerStanding — held continuously

    The roles whose compromise is equivalent to compromising a decisive point — the operators of decisive points, and the roles with standing access to them.

  • The declared length of a cycle, its close date, and the refresh intervals that inherit from it. Makes “per cycle” a measurable unit rather than a figure of speech.

  • One signed paragraph stating what the defense exists to protect, what may be degraded to protect it, and the acceptable risk. The commander’s-intent analog, and the citation every downstream designation rests on.

What the framework supplies

Prepare asks for an authorization boundary and an asset picture. The overlay is that picture drawn positionally — where each element sits relative to a boundary — which is strictly more than an inventory and reconciles against one.

What it does not

Organizationally-tailored control baselines, common control identification and system registration are all Prepare outputs, and the framework produces none of them.

Categorize

4 artifacts · 7 controls

Categorize the system and the information it processes, stores and transmits, based on an analysis of the impact of loss.

Fed fromMapAssess

  • The elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.

  • Bill of DefenseProduced at Assess

    Per mission service: the maneuvers and assets protecting it, its rolled-up coverage, and its residual risk. The view that lets a mission owner see their own defense rather than the enterprise average.

  • Statutory availability floorStanding — held continuously

    The mission services whose availability is set by statute or regulation, and the floor below which degradation stops being a defensive choice. Bounds what may be pre-authorized and what may be degraded under contact.

  • Where privacy holdings and controlled unclassified information sit, the authorities under which they are held, and the boundaries their handling requires — expressed as denied paths, not as policy statements.

What the framework supplies

The framework supplies the mission-to-asset chain that an impact analysis needs as its input, and it supplies the statutory availability floor that bounds what may be traded away.

What it does not

The categorization itself is a FIPS 199 determination made under agency authority. Defensive weight is not an impact level and must never be entered as one.

Select

5 artifacts · 6 controls

Select an initial set of controls, tailor them to reduce risk to an acceptable level, and document the selection in a system security plan.

Fed fromMapArrayFuseAssess

  • Scheme of maneuverProduced at Array

    One graphic and one narrative: which forms of maneuver are sited where, in what sequence. The assignment record behind it carries the element, the avenue and the implementation state for every move.

  • Main effort designationProduced at Array

    The single designated main effort for the cycle, and the sentence citing the decisive point that justifies it. The answer to which work wins when two things need the same engineer.

  • Adopted maneuver catalogProduced at Array and Fuse

    The forms of defensive maneuver the organization has adopted, each with the effectiveness it is assumed to deliver — recorded so the assumption can later be validated rather than believed indefinitely.

  • Control inheritance mappingProduced at Assess

    How the cycle’s output maps onto the organization’s existing control baseline and assessment results, so that federal obligations are satisfied as a by-product of defending rather than as a parallel program.

  • The specific barriers holding the line where reachability is prevented, each with a named enforcing owner. What the reachability result depends on, made explicit so its erosion is visible.

What the framework supplies

The inheritance mapping is the direct contribution: it states which of the agency’s existing controls this framework’s controls stand on, so a Select decision can see what is already inherited rather than re-selecting it.

What it does not

No baseline, no tailoring rationale, no system security plan. The scheme selects defensive moves against ground; it does not select controls from a catalog, and a reviewer should not read it as though it does.

Implement

5 artifacts · 4 controls

Implement the selected controls and describe how they are employed within the system and its environment of operation.

Fed fromArrayManeuver

  • Implementation state recordProduced at Maneuver

    Planned, partial or operational, per maneuver assignment. The mechanism that stops intended work being counted as deployed protection.

  • Change recordProduced at Maneuver

    Every defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from.

  • Rules of engagementProduced at Array

    Which defensive actions may be taken by whom without escalation, which need the Authorizing Official, and what is prohibited outright. The cyber analog of engagement authority, and the single largest determinant of tempo.

  • The specific containment and response actions the SOC may execute at machine speed, bounded by the statutory availability floor. Directly measurable: it shortens the decision segment of the defender loop.

  • Authority exception logProduced at Maneuver

    Actions taken outside the standing rules of engagement, with who approved them and why. Exceptions are not failures; unrecorded exceptions are.

What the framework supplies

Implementation state is tracked as a state rather than assumed from a purchase, and the change record is the evidence that a maneuver was actually emplaced — which is the question Implement is really asking.

What it does not

The evidence here is of maneuvers, not of the agency’s selected controls, and nothing updates the system security plan. An assessor tracing a selected control will not find its implementation narrative in these artifacts.

Assess

6 artifacts · 6 controls

Determine whether the controls are implemented correctly, operating as intended, and producing the desired outcome — and record the result and the remediation that follows.

Fed fromMapFuseAssess

  • Whether the moves claiming operational status produced the effect the catalog assumed — from exercise results, control testing, and observed incident performance.

  • The formal result: from each entry point, which decisive points are reachable over the permitted-path graph. The framework’s hardest single finding, and the headline of the brief when it changes.

  • Coverage and residual risk computed over the whole overlay population, weighted by consequence, discounted by implementation state and corrected by validated effectiveness — with the denominator stated.

  • Reconstitution exercise reportStanding — held continuously

    What was rebuilt, from what media, in what time, verified how — and which recovery objectives were missed. Includes supplier severance scenarios.

  • Remediation backlogProduced at Assess

    The ranked list of what to fix, ordered by residual risk, main-effort weighting, and decisive-point floor breaches — which sit above higher-volume, lower-weight work regardless of count.

  • Findings disposition recordProduced at Assess

    Every finding with an outcome: remediate with an owner and a date, accept with a named accepter and an expiry, or transfer with the party named. “Under review” is not a disposition.

What the framework supplies

Reachability and effectiveness validation answer a question a control assessment cannot: whether the control, working as designed, actually stops the movement it was sited to stop.

What it does not

No security assessment plan and no security assessment report in their required forms, and the remediation backlog is ordered by defensive weight rather than in the plan-of-action-and-milestones schema.

Authorize

4 artifacts · 9 controls

Require a senior official to determine whether the security and privacy risk is acceptable, and record that determination.

Fed fromFuseAssess

  • Cycle briefProduced at Assess

    The published product: terrain, reachability, main effort, temporal advantage, coverage, trend, and the top-ranked backlog items — each confidence-tagged. Also the evidence that feeds the next intent.

  • Cyber Running EstimateProduced at Fuse

    The living situational picture the SOC, hunt and intelligence cell share: current posture, current assessments and their confidence, open requirements, and what has moved since the last look.

  • Temporal advantage resultProduced at Assess

    Defender decision loop against adversary dwell, reported as a ratio against the threshold set at Frame, with the result written as a word: met, or not met. The framework’s single honest scoreboard.

  • Bill of DefenseProduced at Assess

    Per mission service: the maneuvers and assets protecting it, its rolled-up coverage, and its residual risk. The view that lets a mission owner see their own defense rather than the enterprise average.

What the framework supplies

The Authorizing Official is the same accountable person in both models. What the framework adds at this step is a positional picture with a confidence level attached, rather than a compliance state with none.

What it does not

No authorization package and no authorization decision. The framework informs the judgment and produces none of the documents the judgment is recorded in.

Monitor

6 artifacts · 11 controls

Maintain ongoing situational awareness of security and privacy posture to support risk management decisions — ongoing assessment, change monitoring, reporting and ongoing authorization.

Fed fromMapManeuverFuseAssess

  • Cycle record and trendProduced at Assess

    The closed record of the cycle — posture, loop measurement, conclusions and their confidence, backlog state at close — and the trend across cycles that makes a second cycle worth more than a first.

  • Detect to decide to contain, measured per incident from the change record’s timestamps and reported as a distribution rather than as a mean.

  • Adversary dwell estimateProduced at Fuse

    The estimated time an adversary could operate undetected in this estate, with its basis stated — measured dwell, sector reporting, or partner intelligence — and its bias acknowledged.

  • Indicators and signpostsProduced at Fuse

    For each surviving hypothesis, the observable events that would confirm or kill it, handed to collection. The mechanism that makes this cycle’s analysis into next cycle’s requirements.

  • Cyber Terrain OverlayProduced at Map

    The positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.

  • Coverage and residual risk computed over the whole overlay population, weighted by consequence, discounted by implementation state and corrected by validated effectiveness — with the denominator stated.

What the framework supplies

This is the step the framework was built for. Continuous monitoring here is a loop with a cadence, a clock and a record of whether it turned — not a periodic report about whether it exists.

What it does not

The reporting that continuous monitoring is graded on has formats and recipients the framework does not address, and ongoing authorization decisions are made outside it.

Half derived. The artifacts feeding each RMF step are authored citations; where each artifact is produced, and which controls produce it, is read from the products index and the control chain. What the framework takes from this source and what it declines to take is set out in sources and provenance; the controls named on this page each carry their full lineage on their own sheet.