RMF Resources

Practical guidance on the NIST SP 800-37 Risk Management Framework

This section publishes authoritative, plain-language articles on each step of the NIST SP 800-37 RMF lifecycle. Written by Securitique™ assessors with direct federal cybersecurity experience. New articles are added as the knowledge base grows.

RMF Step Articles

Two articles are published now. Five more are in development, one for each remaining RMF step.

RMF Step 1 The Categorize Step

Where most federal engagements fail before they even begin. A Securitique™ guide to CUI scoping, boundary documentation, FIPS 199 categorization, and SSP accuracy.

RMF Step 4 The Assess Step

Where Securitique™ leads. A deep guide to EFAS™-governed control assessment, evidence standards, and the complete deliverable package that supports ATO decisions.

RMF — Prepare — The Foundation Step — Coming Soon

RMF Step 2 — The Select Step — Coming Soon

RMF Step 3 — The Implement Step — Coming Soon

RMF Step 5 — The Authorize Step — Coming Soon

RMF Step 6 — The Monitor Step — Coming Soon

Ready to Work With the Firm Behind the Standard?

Securitique™ is the firm that published EFAS™. Every assessment we deliver is governed by the standard you just read. If you are ready to know exactly where you stand against NIST, ISO, CMMC, or AI governance requirements the conversation starts at securitique.us.