---
sourceDocument: Zurich Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/governance-risk-compliance

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Process overview

# NIST RMF process overview {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The NIST RMF navigation
structure facilitates the management of the NIST security controls through activities of
categorization, selection, implementation, assessment, authorization, and monitoring. These
security controls are described in the NIST 800-37.r1 special publication.  
Note:  
Starting with version 10.1.0, the NIST RMF Use Case Accelerator will be supported only for customers who currently use the product. New and existing customers should consider using the GRC: Continuous Authorization Monitoring application. For details, [Continuous Authorization and Monitoring](https://www.servicenow.com/docs/KvuARTgnwDh27DBm1_IHoQ "Continuous Authorization and Monitoring (CAM) employs the seven steps defined by the NIST Risk Management Framework (RMF) to allow you to make better-informed decisions about your security posture.").

## NIST RMF process
overview {#nist-rmf-process__section_kdx_hhv_1gb}

1. The risk executives and/or the security officers categorize the targets.
2. The risk executives, the security officers and/or the control providers select baseline control definitions.
3. The risk executives and/or the security officers implement baseline security controls.
4. The security accessors, the risk executives, and/or the security officers assess the security controls:
   1. Manage and address issues
   2. Manage and address remediation tasks
   {#nist-rmf-process__ol_sn3_4rv_3hb}
5. The authorizing official, the risk executives, and/or the security officers authorize targets.
6. The risk executives and/or the security officers monitor security controls:
   1. Review and manage indicators
   2. Monitor the NIST RMF Overview dashboard
   {#nist-rmf-process__ol_rhc_ksv_3hb}
{#nist-rmf-process__ol_xby_smv_3hb}
* **[Categorize targets](https://www.servicenow.com/docs/vju1noTJT6chB9UVLvfJIg)**   
  Within the NIST RMF application, the Categorize section facilitates the categorization of targets through a preliminary risk assessment and an impact analysis.
* **[Select baseline control definitions](https://www.servicenow.com/docs/l~0yB3l9Ltw5cmQtLNv9jQ)**   
  Within the NIST RMF application, the Select section focuses on the review of the initial set of baseline control definitions. You can also tailor the control definitions, by tagging them based on organizational requirements.
* **[Implement security controls](https://www.servicenow.com/docs/DxlMXZbBeJT9I3fOPSmpSQ)**   
  Within the NIST RMF application, the Implement section focuses on the physical implementation of the baseline security controls. The NIST RMF application may also include other standard security controls, already used by the targets or its environment of operation.
* **[Assess controls, risks, issues, and remediation tasks](https://www.servicenow.com/docs/AORHjXJnk6NBu0QI6Lj1~A)**   
  Within the NIST RMF application, the Assess section involves performing security control attestations, evaluating the control effectiveness, managing associated risks and issues, and performing remediation tasks.
* **[Authorize targets](https://www.servicenow.com/docs/DVQUrpXhL2gYOVusIkpaOg)**   
  Within the NIST RMF application, the Authorize section involves the authorization of targets based on their compliance and risk posture.
* **[Monitor security controls](https://www.servicenow.com/docs/192~BLOmk30ZPmQfvRkbBg)**   
  Within the NIST RMF application, the Monitor section involves the on-going monitoring of the security controls for targets documenting changes to them or their environments of operation, conducting security impact analyses of the associated changes, and reporting their security state to designated officials.

