SP 800-37 Rev. 2 describes the Risk Management Framework for information systems and organisations across the system life cycle. It connects preparation, categorisation, control selection, implementation, assessment, authorisation and monitoring. See the NIST publication.
Use in a programme
Connect system-level work with organisational risk decisions. Define responsibilities for the system, common controls, assessment and authorisation, and retain the evidence needed to support those decisions.
Continuous monitoring informs ongoing risk management. Completing an initial assessment does not mean that authorisation or control effectiveness remains unchanged as the system and its environment evolve.
Use in CSFaaS
The reviewed library lists NIST SP 800-37 Rev. 2 - EN. Inspect its scope and source before adoption.
Use system records, framework requirements, risk demands, policies and evidence to organise the relevant work. Map each activity to the decision or artefact it supports. Approval of a framework or demand within CSFaaS is an internal workflow; it is not automatically a formal authorisation to operate under the RMF.