NIST Special Publication 800-37
NIST Special Publication 800-37, "Guide for Applying the Risk Management Framework to Federal Information Systems" was developed by the Joint Task Force Transformation Initiative Working Group. The first revision aimed to transform the traditional Certification and Accreditation process into the Risk Management [Framework (RMF)|Risk Management Framework], and the second version addressed privacy controls in a more central manner, and added a preparatory step.
The second step of the RMF is to select the appropriate subset of security controls from the control catalog in NIST Special Publication 800-53.