The first RMF phase, where an organisation establishes context, roles, risk tolerance, and monitoring priorities before system-level controls are selected. It creates the organisational foundation for later decisions by aligning governance, common controls, and risk management strategy with mission needs and operating realities.
Expanded Definition
Prepare Step is the organisational setup phase in the Risk Management Framework, where leadership defines the context needed to make consistent security decisions before any control selection begins. It establishes roles, governance boundaries, risk tolerance, asset assumptions, and monitoring priorities so that later RMF steps are not improvised system by system. In NHI and IAM programs, this matters because service accounts, API keys, certificates, and other NIST Cybersecurity Framework 2.0 aligned assets often span teams and platforms, making ad hoc ownership a recurring failure point.
Definitions vary across vendors and operating models, but the core intent is stable: create the governance and risk foundation that lets common controls, inheritance, and continuous monitoring work at scale. In practice, Prepare Step also clarifies how mission needs influence identity assurance, logging depth, exception handling, and response expectations. The most common misapplication is treating Prepare Step as a paperwork exercise, which occurs when teams skip enterprise context and jump straight into per-system controls without defined ownership or risk thresholds.
Examples and Use Cases
Implementing Prepare Step rigorously often introduces upfront coordination overhead, requiring organisations to weigh faster control deployment against the cost of getting governance wrong later.
- Defining who owns service account policy, secret rotation standards, and exception approvals across application, platform, and security teams.
- Setting risk tolerance for unattended credentials so that Ultimate Guide to NHIs guidance can be translated into practical monitoring and revocation priorities.
- Establishing which workloads inherit common controls from a shared environment and which require separate assessment because of data sensitivity or external exposure.
- Aligning identity lifecycle expectations with assurance guidance from the NIST Cybersecurity Framework 2.0, especially where machine identities support critical services.
- Documenting monitoring signals for API keys, certificates, and automation accounts so detection teams know what “normal” looks like before an incident occurs.
In mature environments, Prepare Step also helps decide whether an NHI should be governed as a shared enterprise control or as a local exception with stricter compensating controls. That choice shapes later review cadence, incident ownership, and evidence collection.
Why It Matters in NHI Security
Prepare Step is where NHI security becomes operationally realistic rather than aspirational. Without it, organisations typically overfocus on individual secrets while missing the broader system of ownership, inheritance, and monitoring that makes compromise easier to spread. NHIMG research shows that only 5.7% of organisations have full visibility into their service accounts, and that lack of visibility is usually a preparation failure long before it becomes an incident. The same research also reports that 97% of NHIs carry excessive privileges, which makes risk tolerance and role clarity essential to any credible governance model.
This phase also supports Zero Trust thinking by defining what must be verified, logged, and reviewed continuously instead of assumed trustworthy. When teams do not establish prepare-stage boundaries, they often discover too late that secrets were stored outside approved controls, or that no one knows who can revoke a compromised credential. Organisations typically encounter the cost of weak preparation only after a credential leak or lateral movement event, at which point Ultimate Guide to NHIs findings become an urgent operational roadmap rather than a governance reference.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207), NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 | Prepare Step establishes enterprise risk context and tolerance before controls are selected. |
| NIST Zero Trust (SP 800-207) | Zero Trust depends on explicit context, policy, and continuous verification planning. | |
| OWASP Non-Human Identity Top 10 | NHI-01 | NHI governance begins with ownership, context, and lifecycle accountability. |
| NIST SP 800-63 | IAL | Identity assurance concepts inform how rigorously machine identities should be governed. |
| NIST AI RMF | AI RMF preparation aligns with defining risk context and operational roles upfront. |
Define identity risk appetite and governance boundaries before assigning and inheriting controls.
Related resources from NHI Mgmt Group
- What is the first step in building a modern NHI security programme?
- What is MCP Step-Up Authorisation and how does it implement least privilege for agents?
- How should organisations prepare their NHI programmes for Agentic AI adoption?
- What is the first step in managing non-human identities at scale?