NIST RMF Introductory Course Overview
NIST RMF Introductory Course Overview
In accordance with its statutory authorities, NIST maintains a research information center to support the research, publishing, and preservation needs
required to fulfill the scientific and technical mission of NIST. NIST makes its RMF Introductory Course available to interested parties as a public service.
Pursuant to 17 USC 105, works authored by NIST employees are not subject to Copyright protection within the United States; foreign rights are reserved on
behalf of the Secretary of Commerce. To the extent that NIST may hold copyright or other rights in countries other than the United States, you are hereby
granted the non-exclusive irrevocable and unconditional right to print, publish, prepare derivative works, and distribute, in any medium, or authorize others
to do so on your behalf, on a royalty-free basis throughout the world. Downloads are made available as a courtesy of NIST. Please provide appropriate
attribution to NIST, the creator of the courses.
The RMF Introductory Course is provided “AS IS.” NIST makes NO WARRANTY of any kind, express or implied or statutory, including without limitation, the
implied warranty of merchantability, fitness for a particular purpose, non-infringement or data accuracy.
Permission to use this material is contingent upon your acceptance of these terms.
Software Disclaimer
NIST-developed software is provided by NIST as a public service. You may use, copy and distribute copies of the software in any medium, provided that you keep intact this entire notice. You may
improve, modify and create derivative works of the software or any portion of the software, and you may copy and distribute such modifications or works. Modified works should carry a notice
stating that you changed the software and should note the date and nature of any such change. Please explicitly acknowledge the National Institute of Standards and Technology as the source of the
software.
NIST-developed software is expressly provided "AS IS." NIST MAKES NO WARRANTY OF ANY KIND, EXPRESS, IMPLIED, IN FACT OR ARISING BY OPERATION OF LAW, INCLUDING, WITHOUT
LIMITATION, THE IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT AND DATA ACCURACY. NIST NEITHER REPRESENTS NOR WARRANTS THAT
THE OPERATION OF THE SOFTWARE WILL BE UNINTERRUPTED OR ERROR-FREE, OR THAT ANY DEFECTS WILL BE CORRECTED. NIST DOES NOT WARRANT OR MAKE ANY REPRESENTATIONS
REGARDING THE USE OF THE SOFTWARE OR THE RESULTS THEREOF, INCLUDING BUT NOT LIMITED TO THE CORRECTNESS, ACCURACY, RELIABILITY, OR USEFULNESS OF THE SOFTWARE.
You are solely responsible for determining the appropriateness of using and distributing the software and you assume all risks associated with its use, including but not limited to the risks and costs
of program errors, compliance with applicable laws, damage to or loss of data, programs or equipment, and the unavailability or interruption of operation. This software is not intended to be used in
any situation where a failure could cause risk of injury or damage to property. The software developed by NIST employees is not subject to copyright protection within the United States.
A brief overview on how to navigate through the course, when delivered via the NIST CSRC website:
• The course outline is shown in the left-hand navigation bar
• A keyword search is available, but you will only be able to access slides you have already viewed.
• The recommended use of this search function is meant for after you have completed the course and would like to refer to a particular topic.
• In the upper right-hand corner, there are two items of note: Marker Tools and Notes
• Clicking “Marker Tools” allows you to “mark up” (e.g. highlight, underline, etc) your version of the presentation slide, if you wish to do so
• Clicking “Notes” displays the written script of the audio track on that particular slide
• Under the main presentation slide, on the left-hand side:
• A Play/Pause button for the slide currently displayed
• A timer for the current slide is also displayed, as well as a replay button, volume control, and full-screen toggle button
• Under the main presentation slide, on the right-hand side:
• Navigate backward to slides you have already viewed using the “Prev” button
• Navigate forward to slides to return your current position in the course using the “Next” button
• Note that you cannot navigate forward to slides you have not yet seen
• The Accessibility icon is in the upper left-hand corner of the presentation window
At any time, you can leave the course and resume from where you left off in the
course – just be sure to enable cookies for this website in your browser.
This course is provided by the National Institute of Standards and
3
Technology and is available free of charge at [Link]
Welcome and Overview
Welcome to the Risk Management Framework (RMF) for Systems and Organizations
Course
• Why organizations need to manage risk
• Course purpose and target audience
• Course goal and authority
• Learning objectives
The target audience for this course are individuals with responsibilities for:
Course Goal
Gain familiarity with the RMF and supporting
publications, process, and integration into an
organization mission and business practices
Course Authority
Information from this course is applied in accordance
with legislative guidelines, standards, and requirements
established by the Federal Government and your
organization
Completing the entire course should take approximately 3 hours. The breakdown in time
for each module is as follows:
• Welcome and Overview (9 minutes)
• Module 1: Federal Legislation and Policy (8 minutes)
• Module 2: NIST Special Publication 800-37 Background and Update Overview (10 minutes)
• Module 3: The Fundamentals (75 minutes)
• Lesson 1: Organization-wide Risk Management Lesson 6: Authorization Types and Decisions
• Lesson 2: Risk Management Framework Steps and Structure Lesson 7: Requirements and Controls
• Lesson 3: Information Security and Privacy in the RMF Lesson 8: Security and Privacy Posture
• Lesson 4: System and System Elements Lesson 9: Supply Chain Risk Management
• Lesson 5: Authorization Boundaries Lesson 10: Risk Management Roles and Responsibilities
• Module 4: The Risk Management Framework (59 minutes)
• Lesson 1: Overview of the Risk Management Framework
• Lesson 2: Risk Management Framework Steps
• Conclusion and Contact Information (3 minutes)
Special Publications continue to be developed and updated to further NIST’s statutory responsibilities under the
Federal Information Security Modernization Act (FISMA), 44 U.S.C. § 3551 et seq., Public Law (P.L.) 113-283
This course is provided by the National Institute of Standards and
Module 2: NIST SP 800-37 Background 18
Technology and is available free of charge at [Link]
Differences Between NIST SP 800-37 Rev. 1 & Rev. 2
• Discussion of Supply Chain Risk Management (SCRM) within the RMF added in section
2.8 – Supply Chain Risk Management
SDLC Phase
• Compare organization-wide risk management with security and privacy risk management and
supply chain risk management
• Identify roles and responsibilities associated with each task of the RMF
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
26
Lesson 1: Organization-Wide Risk Management Technology and is available free of charge at [Link]
Organization-Wide Risk Management
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
27
Lesson 1: Organization-Wide Risk Management Technology and is available free of charge at [Link]
Organization-Wide Risk Management Conclusion
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
28
Lesson 1: Organization-Wide Risk Management Technology and is available free of charge at [Link]
Lesson 2: Risk Management Framework Steps and Structure
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
29
Lesson 2: RMF Steps and Structure Technology and is available free of charge at [Link]
Risk Management Framework Steps and Structure
Each step in the RMF has a purpose statement, set of outcomes, and tasks that are
carried out to achieve those outcomes captured in the Step Summary
Purpose
Example: Purpose The purpose of the Implement step is to implement the controls in the security and privacy plans for the system and
for the organization and to document in a baseline configuration, the specific details of the control implementation.
Tasks Outcomes
Example: RMF
TaskTask
I-1 Outcome Controls specified in the security and privacy plans are implemented.
[Cybersecurity Framework: [Link]-1]
Control Implementation
Systems security and privacy engineering methodologies are used to implement the controls
in the system security and privacy plans.
Example: Applicable CSF Component [Cybersecurity Framework: [Link]-2]
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
30
Lesson 2: RMF Steps and Structure Technology and is available free of charge at [Link]
Risk Management Framework Task Structure
• Task Section: Describes the specific RMF task within the appropriate step
• Potential Inputs: Lists information that may be needed to complete the task (NEW)
• Expected Outputs:
Describes the end result of task
completion (NEW)
• Primary Responsibility
Section: Lists the individual or
group within the organization
having primary responsibility
for ensuring completion of the
RMF task
• Supporting Roles Section:
Lists the supporting roles within
the organization that may help
with or provide input for task
completion
• SDLC Phase Section: Lists the
phase of the SDLC when the RMF task is typically executed
• Discussion Section: Provides additional information about the RMF task
• References Section: Provides general references to NIST security standards and guidelines that may be consulted for additional information
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
31
Lesson 2: RMF Steps and Structure Technology and is available free of charge at [Link]
Lesson 3: Security and Privacy in the RMF
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
32
Lesson 3: Information Security and Privacy Technology and is available free of charge at [Link]
NIST Privacy Risk Assessment Methodology (PRAM)
[Link]
engineering/resources#pram
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
33
Lesson 3: Information Security and Privacy Technology and is available free of charge at [Link]
Lesson 4: System and System Elements
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
34
Lesson 4: System and System Elements Technology and is available free of charge at [Link]
System and Relational View of the System
• Applied to systems-of-
interest, not individual ENVIRONMENT OF OPERATION
system elements Enabling Enabling
System System
System
Element
• Diagram illustrates the Enabling Enabling
conceptual view of the System
System System
System
SYSTEM
(AUTHORIZATION BOUNDARY)
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
35
Lesson 4: System and System Elements Technology and is available free of charge at [Link]
Lesson 5: Authorization Boundaries
• Establishes the scope of protection for systems (i.e., what is to be protected as part of
a given system)
• Defines the scope of the authorizing official’s responsibility and accountability for
protecting information resources and individuals’ privacy
• Established during Task P-11 Authorization Boundary (before security categorization
and development of security plans)
• Guidance in Section 2.5 and Appendix G in NIST SP 800-37, Revision 2
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
36
Lesson 5: Authorization Boundaries Technology and is available free of charge at [Link]
Determination of Authorization Boundary Considerations
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
37
Lesson 5: Authorization Boundaries Technology and is available free of charge at [Link]
Boundaries for Complex Systems and External Providers
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
38
Lesson 5: Authorization Boundaries Technology and is available free of charge at [Link]
Lesson 6: Authorization Types and Decisions
• Traditional Authorization
• Authorization Decisions
• Authorization to Operate
• Common Control Authorization
• Joint Authorization
• Authorization to Use
• Denial of Authorization
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
39
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Authorization Types
• Initial Authorization
• Ongoing Authorization
• Reauthorization
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
40
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Authorization Types:
Initial Authorization
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
41
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Authorization Types:
Ongoing Authorization
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
42
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Authorization Types:
Reauthorization
• Static, single point-in-time risk determination and risk acceptance that occurs after
the initial authorization
• May be time-driven or event-driven
• Separate activity from ongoing authorization
• Conducted with a similar level of effort as the initial authorization and may be:
• Complete, zero-based assessment; or
• Targeted assessment based on the type of event that triggered the reauthorization action
• Reauthorization actions may lead to a review of the ISCM strategy which could affect
ongoing authorization
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
43
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Authorization Decisions
• Authorization to Operate
• Authorization to Use
• Denial of Authorization
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
44
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Authorization Decisions:
Authorization to Operate
• Issued by the Authorizing Official after determining that the risk to organizational
operations, assets, individuals, other organizations, and the Nation is acceptable
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
45
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Authorization Decisions:
Common Control Authorization
• Similar to authorization to operate for a system, but issued for common controls
• Common control authorization termination date is specified or, if under ongoing
authorization, a time-driven authorization frequency is specified
• Common controls implemented as part of a system do not require a separate
common control authorization
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
46
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Authorization Decisions:
Authorization to Use
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
47
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Authorization Decisions:
Denial of Authorization
Authorizing officials should not feel pressured into accepting unacceptable risk
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
48
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Authorization Decisions:
Type, Facility, Traditional, Joint Authorization
• Type Authorization
• Single authorization for a common version of a system
• Utilized when system comprised of identical instances of architecture, software, information types
• Often used in conjunction with a facility authorization
• Facility Authorization
• Authorizes common controls provided in a specific environment of operation
• Provided at a specified impact level
• Traditional Authorization
• Single organizational official in a senior leadership position is responsible and accountable for a system or for
common controls
• Joint Authorization
• Multiple organizational officials either from the same organization or different organizations, have a shared
interest in authorizing a system
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
49
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Lesson 7: Requirements and Controls
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
50
Lesson 7: Requirements and Controls Technology and is available free of charge at [Link]
Lesson 8: Security and Privacy Posture
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
51
Lesson 8: Security and Privacy Posture Technology and is available free of charge at [Link]
Lesson 9: Supply Chain Risk Management
• Managing supply chain risk is a complex, multifaceted undertaking requiring a coordinated effort across
an organization
• Organizations develop a Supply Chain Risk Management (SCRM) Strategy, Policies and Plans for directing
SCRM activities
• SCRM activities involve:
• Identifying and assessing applicable risks
• Determining appropriate mitigating actions
• Developing appropriate SCRM plans to document selected mitigating actions
• Monitoring performance against SCRM plans
• SCRM strategy can be included as part the Risk Management Strategy, or a separate artifact
• SCRM policies direct the implementation of the SCRM strategy
• SCRM plans are tailored to the individual program, organizational, and operational contexts
• Organizations have flexibility on how the details of SCRM strategies and plans are documented
The organization and authorizing official are ultimately responsible for responding to
risks from the use of component products, systems, and services external providers
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
52
Lesson 9: Supply Chain Risk Management Technology and is available free of charge at [Link]
Lesson 10: Risk Management Roles and Responsibilities
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
53
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities
The RMF describes the roles and responsibilities of key participants involved in an organization’s risk
management process. There may be differences in naming conventions and how responsibilities are
allocated among personnel. NIST SP 800-181, National Initiative for Cybersecurity Education (NICE)
Cybersecurity Workforce Framework, provides a reference and common lexicon for describing and
sharing information about cybersecurity work, the knowledge, skills and abilities needed.
• Authorizing Official • Risk Executive (Function)
• Authorizing Official Designated Representative • Security or Privacy Architect
• C-Suite Officials (e.g., Chief Acquisition Officer, • Senior Accountable Official for Risk Management
Chief Information Officer, Head of Agency) • Senior Agency Information Security Officer
• Common Control Provider • Senior Agency Official for Privacy
• Control Assessor • System Owner
• Enterprise Architect • System Security or Privacy Officer
• Information Owner or Steward • System Security or Privacy Engineer
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
54
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Authorizing Official
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
55
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Authorizing Official Designated Representative
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
56
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
C-Suite Officials
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
57
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Common Control Provider
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
58
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Control Assessor
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
59
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Enterprise Architect
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
60
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Information Owner or Steward
• Responsible for establishing the rules for appropriate use and protection of the
information
• Provides input to system owners regarding the security and privacy requirements and
controls for the systems where the information is processed, stored, or transmitted
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
61
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Risk Executive (Function)
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
62
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Security or Privacy Architect
• Responsible for ensuring that stakeholder protection needs and the corresponding
system requirements are met
• Serves as the primary liaison between the enterprise architect and the systems
security or privacy engineer
• Coordinates with system owners, common control providers, and system security or
privacy officers on the allocation of controls
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
63
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Senior Accountable Official for Risk Management (SAORM)
• Leads the risk executive (function) within an organization; is the head of the agency or
is designated by the head of the agency
• Responsible for aligning information security and privacy risk management processes
with strategic, operational, and budgetary planning processes
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
64
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Senior Agency Information Security Officer (SAISO)
• Organizational official responsible for carrying out the chief information officer
security responsibilities under FISMA
• Serves as the CIO’s liaison to the authorizing officials, system owners, and system
security officers
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
65
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Senior Agency Official for Privacy (SAOP)
• Ensures compliance with applicable privacy requirements and managing privacy risk
• Works with the senior agency information security officer to coordinate privacy and
information security activities
• Assesses privacy controls and provides privacy information to the authorizing official as
needed
• Identifies assessment methodologies and metrics to determine whether privacy controls
are implemented correctly, operating as intended, and sufficient to ensure compliance
with applicable privacy requirements and manage privacy risks
• Reviews authorization packages for systems that create, collect, use, process, store,
maintain, disseminate, disclose, or dispose of personally identifiable information
• Establishes and maintains privacy continuous monitoring program
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
66
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
System Owner
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
67
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
System Security or Privacy Officer
• Ensures that the operational security and privacy posture is maintained for an
organizational system and as such, works in close collaboration with the system owner
• Serves as a principal advisor on all matters, technical and otherwise, involving the
security or privacy controls for the system
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
68
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
System Security or Privacy Engineer
• Coordinates security and privacy activities with organization security and privacy
officials
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
69
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Module 3 Summary
• Managing risk is a complex, multifaceted activity that requires the involvement of the entire
organization—from senior leaders/executives, to mid-level leaders, to individuals responsible for
system-level security
• Privacy, security, and supply chain risk management is not a static process
• Authorization boundary defines the system for RMF execution to facilitate risk management and
accountability, define for an account for flow of information through the system
• Security and privacy programs require close collaboration, defining roles and responsibilities allows an
organization to effectively accomplish specific tasks, manage security and privacy risks, and clarify
expectations
• Authorizing officials should not feel pressured into accepting risk that is not consistent with the
organizational risk tolerance
• The RMF describes the roles and responsibilities of key participants involved in an organization’s risk
management process; across organizations, there may be differences in naming conventions and how
responsibilities are allocated among personnel
• Learn about about the process organization use to identify and select the appropriate risk
mitigations needed to protect the systems, information, and infrastructure supporting
organizational mission/business processes
• Understand guidance for organizations to develop robust and repeatable practices for securing and
protecting the privacy of its information and systems
• The Risk Management Framework provides organizations with several key benefits:
• A structured, yet flexible process for managing risk related to the operation of systems
• Guidance for determining the appropriate risk mitigation needed to protect the systems and
infrastructure supporting organizational mission/business processes
• A repeatable methodology that balances key mission/business goals and organizational priorities
with security requirements and policy guidance
• A processes for continuous monitoring resulting in continuous improvement of the organization’s
security posture
• A technology-neutral methodology that can be applied to any type of information system without
modification
Specific controls selected, control implementation details, and control assessment methods/objects will vary
with different types of systems, there is no need to adjust the RMF process to accommodate specific
technologies (e.g., Internet of Things, industrial control and automation)
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
72
Lesson 1: Overview of the RMF Technology and is available free of charge at [Link]
What is the Risk Management Framework?
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
73
Lesson 1: Overview of the RMF Technology and is available free of charge at [Link]
Lesson 2: Risk Management Framework Steps
Organizations are expected to execute all steps and tasks in the RMF.
Organizations have significant flexibility in how the RMF steps and tasks are carried
out, if applicable requirements are met, and security and privacy risk is managed.
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
74
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Prepare
Purpose
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
75
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Prepare
Organization and Mission/Business Process Level Tasks (NEW)
P-1: Risk Management Roles
Identify and assign individuals to specific roles associated with security and privacy risk management
P-2: Risk Management Strategy
Establish a risk management strategy for the organization that includes a determination of risk tolerance
P-3: Risk Assessment - Organization
Assess organization-wide security and privacy risk and update the risk assessment results on an ongoing basis
P-4: Organizationally-tailored Control Baselines and CSF Profiles (optional)
Establish, document, and publish organizationally-tailored control baselines and/or cybersecurity framework profiles
P-5: Common Control Identification
Identify, document, and publish organization-wide common controls that are available for inheritance by organizational systems
P-6: Impact Level Prioritization (optional)
Prioritize organizational systems within the same impact level
P-7: Continuous Monitoring Strategy - Organization
Develop and implement an organization-wide strategy for continuously monitoring control effectiveness
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
76
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Prepare
System Level Tasks (NEW)
P-8: Mission or Business Focus P-14: Risk Assessment - System
Identify the missions, business functions, and mission/business Conduct a system-level risk assessment and update the risk
processes that the system is intended to support assessment results on an ongoing basis
P-9: System Stakeholders P-15: Requirements Definition
Identify stakeholders who have an interest in the design, Define the security and privacy requirements for the system and
development, implementation, assessment, operation, the environment of operation
maintenance, or disposal of the system
P-16: Enterprise Architecture
P-10: Asset Identification Determine the placement of the system within the enterprise
Identify assets that require protection architecture
P-11: Authorization Boundary P-17: Requirements Allocation
Determine the authorization boundary of the system Allocate security and privacy requirements to the system and to
the environment of operation
P-12: Information Types
Identify the types of information to be processed, stored, or P-18: System Registration
transmitted by the system Register the system with organizational program or management
offices
P-13: Information Life Cycle
Identify and understand all stages of the information life cycle for
each information type processed, stored, or transmitted by the
system
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
77
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Prepare
Supporting Publications
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
78
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Categorize
Purpose
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
79
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Categorize
Tasks
C-1: System Description
Document the characteristics of the system
C-2: Security Categorization
Categorize the system and document the security categorization results
C-3: Security Categorization Review and Approval (NEW)
Review and approve the security categorization results and decision
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
80
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Categorize
Supporting Publications
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
81
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Select
Purpose
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
82
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Select
Tasks
S-1: Control Selection
Select the controls for the system and environment of operation
S-2: Control Tailoring (NEW)
Tailor the controls selected for the system and environment of operation
S-3: Control Allocation (REVISED)
Allocate security and privacy controls to the system and to the environment of operation
S-4: Document Planned Control Implementations (NEW)
Document the controls for the system and environment of operation in security and privacy plans
S-5: Continuous Monitoring Strategy – System (REVISED)
Develop and implement a system-level strategy for monitoring control effectiveness that is consistent with and supplements the organizational
continuous monitoring strategy
S-6: Plan Review and Approval
Review and approve the security and privacy plans for the system and environment of operation
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
83
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Select
Supporting Publications
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
84
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Implement
Purpose
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
85
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Implement
Tasks
I-1: Control Implementation
Implement the controls as specified in security and privacy plans
I-2: Update Control Implementa on Informa on (REVISED)
Document changes to planned control implementa ons based on the as-implemented state of the controls
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
86
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Implement
Supporting Publications
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
87
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Assess
Purpose
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
88
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Assess
Tasks
A-1: Assessor Selection (NEW)
Select the appropriate assessor or assessment team for the type of control assessment to be conducted
A-2: Assessment Plan
Develop, review, and approve plans to assess implemented controls
A-3: Control Assessments (MOVED)
Assess the security controls in accordance with the assessment procedures defined in the security assessment plan
A-4: Assessment Reports
Prepare the assessment reports documenting the findings and recommendations from the control assessments
A-5: Remediation Actions
Conduct initial remediation actions on the controls and reassess remediated controls
A-6: Plan of Action and Milestones (MOVED)
Prepare the plan of action and milestones based on the findings and recommendations of the assessment reports
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
89
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Assess
Supporting Publications
• NIST SP 800-53A, Assessing Security and Privacy Controls in Federal Systems and Organizations: Building Effective
Security Assessment Plans
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
90
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Authorize
Purpose
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
91
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Authorize
Tasks
R-1: Authorization Package
Assemble the authorization package and submit the package to the authorizing official for an authorization decision
R-2: Risk Analysis and Determination (REVISED)
Analyze and determine the risk from the operation or use of the system or the provision of common controls
R-3: Risk Response (NEW)
Identify and implement a preferred course of action in response to the risk determined
R-4: Authorization Decision (NEW)
Determine if the risk from the operation or use of the system or the provision or use of common controls is acceptable
R-5: Authorization Reporting
Report the authorization decision and any deficiencies in controls that represent significant security or privacy risk
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
92
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Authorize
Supporting Publications
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
93
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Monitor
Purpose
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
94
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Monitor
Tasks
M-1: System and Environment Changes
Monitor the system and its environment of operation for changes that impact the security and privacy posture of the system
M-2: Ongoing Assessments
Assess the controls implemented within and inherited by the system in accordance with the continuous monitoring strategy
M-3: Ongoing Risk Response
Respond to risk based on the results of ongoing monitoring activities, risk assessments, and outstanding items in plans of action and milestones
M-4: Authorization Package Updates
Update plans, assessment reports, and plans of action and milestones based on the results of the continuous monitoring process
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
95
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Monitor
Tasks
M-5: Security and Privacy Reporting
Report the security status of the system (including the effectiveness of security controls employed within and inherited by the system) to
appropriate organizational officials on an ongoing basis in accordance with the organization-defined monitoring strategy
M-6: Ongoing Authorization
Review the reported security status of the system (including the effectiveness of security controls employed within and inherited by the system) on
an ongoing basis in accordance with the monitoring strategy to determine whether the risk to organizational operations, organizational assets,
individuals, other organizations, or the Nation remains acceptable
M-7: System Disposal
Implement a system decommissioning strategy which executes required actions when a system is removed from service
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
96
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Task: Monitor
Supporting Publications
Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
97
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
Module 4 Summary
• Understanding what constitutes risk and how risk can be addressed and managed
using the Risk Management Framework will enable you to do your part to ensure the
integrity and trustworthiness of your organization’s systems
• The RMF is not a compliance or “one and done” process once an Authorization to
Operate is granted; managing risk is an ongoing activity that supports the
organizational mission and business functions
Key Takeaways
• Managing risk for information security and privacy supports organizational mission and business
functions
• Security and privacy risk management relies on coordination between programs and resources
• Federal information security and privacy programs are driven by legislation, regulations and policy
• The Risk Management Framework (RMF) is a holistic, repeatable process to manage information
security and privacy risk; it is not a compliance or paper-work activity
• The RMF is a technology-neutral methodology that can be applied to any type of information
system without modification
• There are additional NIST resources available to support implementation of RMF steps and tasks
sec-cert@[Link]
@nistcyber
privacyeng@[Link]