---
sourceDocument: Xanadu Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/governance-risk-compliance

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Set up a target for use with NIST RMF

# Set up a target for use with NIST RMF {#ariaid-title1}

* Release version: Xanadu
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Set up a target and populate the basic information.

## Before you begin

Note:  
Starting with version 10.1.0, the NIST RMF Use Case Accelerator will be supported only for customers who currently use the product. New and existing customers should consider using the GRC: Continuous Authorization Monitoring application. For details, [Continuous Authorization and Monitoring](https://www.servicenow.com/docs/I0~PoJDm1GgYbbPb7m44Og "Continuous Authorization and Monitoring (CAM) employs the seven steps defined by the NIST Risk Management Framework (RMF) to allow you to make better-informed decisions about your security posture.").

Role required: sn_irm_nist_rmf.risk_executive or sn_irm_nist_rmf.security_officer

## Procedure

1. Navigate to AllNIST RMFCategorizeImpact Analysis.
2. Search for the target using the Name or Profile fields.
3. Open the target record.
4. In Framework, select NIST RMF, and click Update.
5. Open the target record again and update the following fields:  
   Note:  
   Review [NIST RMF supporting concepts](https://www.servicenow.com/docs/WzOTZODJigTbkuqSDEhayA "Familiarize yourself with these concepts, developed from the NIST RMF guidance."), for more detailed information about these fields.
   * RMF State: Identify the current NIST RMF state for the target.
   * Scoping Considerations: Provide guidance on the selection of security controls for implementation.
   {#set-up-target-nist-rmf__ul_l55_zyc_jhb}
6. Verify that the NIST RMF related lists are visible:  
   * Baseline Policy Statements
   * Baseline Controls
   * Risks
   * Approvals
   {#set-up-target-nist-rmf__ul_pq4_l1y_3hb}
{#set-up-target-nist-rmf__steps_xgn_4vx_3hb}

*[\>]: and then


