RMF step tracker
Every system's journey through the NIST Risk Management Framework NIST SP 800-37 — Prepare → Categorize → Select → Implement → Assess → Authorize → Monitor. Each step is derived from the asset's own data (no separate data entry); the ATO is granted on the asset's detail page. The 7 steps are walked through below.
0
Systems
0
Authorized
0
ATO expired
0%
Avg completion
The 7 steps, start to finish
The whole NIST Risk Management Framework NIST SP 800-37 in order — what each step means, and where you carry it out here.
1
Prepare NIST SP 800-37
Get ready: identify the system, its owner, scope and boundary before categorizing (added in Rev 2).
In PlumbTrack: Add the system on the inventory — set its owner, boundary, environment, and components (CM-8 inventory).
2
Categorize NIST FIPS 199
Rate the system's information for C/I/A impact (FIPS 199).
In PlumbTrack: Set the system's FIPS 199 C/I/A impact on its detail page; the tool takes the high-water mark (the worst of the three).
3
Select NIST SP 800-53B
Select the SP 800-53B control baseline the FIPS 200 impact level requires (Low / Moderate / High), then tailor it: scope out controls that don't apply (written rationale required), tailor in controls the baseline misses, and add overlays for every regulation that pertains to the data - PII privacy (the PT family), PCI DSS for cardholder data, HIPAA for health data.
In PlumbTrack: The impact level picks the SP 800-53B baseline automatically. Then tailor it on the asset's hardening table: mark what doesn't apply (with a written why), tailor in extras the baseline misses, and record a scoping determination in Evidence for each regulation ruled in or out (PII privacy, PCI DSS, HIPAA) — a ruled-out law is still a decision you document.
4
Implement NIST SP 800-53 Rev.5
Put the baseline controls in place on the system.
In PlumbTrack: Mark each control Implemented and attach hardening evidence on the asset.
5
Assess NIST SP 800-53A
Test the controls and record evidence (SP 800-53A).
In PlumbTrack: Record assessment evidence (SP 800-53A) on the controls; the asset's coverage bar reflects it.
6
Authorize NIST SP 800-37
An authorizing official accepts the residual risk (grants an ATO).
In PlumbTrack: Grant the ATO (Authorization to Operate) on the asset detail page — name the authorizing official and its expiry.
7
Monitor NIST CSF 2.0
Continuously monitor; re-authorize before the ATO expires.
In PlumbTrack: Watch this tracker and the KRIs; re-authorize before the ATO expires (PlumbWatch flags drift).
↻
It's a loop, not a line. Monitor feeds back: when the system, its data, or its risk changes, you re-Categorize and re-Authorize. Count systems by their authorization boundaries (one ATO = one system), not by the components inside them.
Systems × RMF steps
Checks fill in order: ✓ done · ● current · ○ pending · ⚠ ATO expired. Click a system to work it (and grant its ATO).
No assets yet. Add systems on the inventory, then work each through the RMF steps.