Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » NIST » NIST Risk Management Framework (RMF)

NIST Risk Management Framework (RMF)

NIST Risk Management Framework (RMF) is a seven-step repeatable process to manage and mitigate risks related to information systems. Developed by the National Institute of Standards and Technology (NIST), the framework was originally developed for federal agencies but has since been adopted by various industries to achieve compliance and manage cybersecurity risks.


The framework integrates security, privacy and cybersecurity supply chain risks into system development lifecycle to enable organizations to take a risk-based approach throughout the control implementation process.

The seven key steps in the NIST RMF include:

  • Prepare aims to enable the organizations to understand their risk profiles and prepare for security risks by assessing data, networks and other infrastructure
  • Categorize focuses on sensitivity of information processes and grouping systems accordingly to understand the impact of potential risks
  • Select aims to choose the right security measures to mitigate the identified risks
  • Implement ensures that the chosen controls are implemented and documented
  • Assess evaluates if the implemented controls are functioning as intended to protect the information systems
  • Authorize aims to promote accountability and ensures that the senior management oversees the implementation and assessment of controls to minimize risks
  • Monitor involves continuous oversight of the risk environment and updating the controls as required

Additional reading

PCI DSS Certification Process: A Complete Guide for 2026

TL;DR PCI DSS is for payment card data. It is seen as the gold standard for protecting sensitive authentication data and with PCI DSS 4.0 in effect the requirements have only become more stringent. The newer and stronger version was built after much input from the PCI Community, including 6,000+ comments from 200 companies and…

Why Continuous Compliance Is Becoming The New Standard

The audit landscape is evolving. Across the industry, audit firms are applying more detailed reviews and placing greater emphasis on how consistently controls operate across the full audit period. It’s a meaningful shift, and one that points toward stronger, more reliable assurance. For organizations, this is a positive development. Stronger audits mean stronger assurance, and…

Top 12 Cybersecurity Certifications (2025 Edition): Costs, Careers, and Skills

TL,DR: Cybersecurity certifications validate security, threat detection, risk management, and compliance knowledge. They help candidates structure learning and help employers assess role readiness. The article compares 12 certifications, including CISM, CEH, and CISA, with costs and career fit. If you’re trying to break into cybersecurity, you’ve probably asked the question: “Should I get certified or…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.