NIST Frameworks and SPs Overview

NIST (the National Institute of Standards and Technology) is a US federal institution that does research and forms national standards. As it relates to cybersecurity frameworks, NIST has created several frameworks and special publications (SPs) that describe best-practices for certain processes and problems. Some SPs are broad (like the NIST SP 800-37 (RMF) or 800-53R5), where others are extremely narrow in their focus (like the NIST SP 800-60)

This is a brief orientation document to help you understand how some of the major docs relate to each other.

Tip

The RMF and CSF are completely different frameworks that can draw from the same special publications.

RMF

NIST-RMF.png
[1]

CSF

NIST CSF.png
[2]

Resources

A Tale of Two Frameworks: The NIST CSF and NIST RMF Are Not the Same - Telos Corporation


  1. Risk Management Framework (RMF) Overview - FISMA Implementation Project | CSRC ↩︎

  2. nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf ↩︎