0% found this document useful (0 votes)
11 views101 pages

NIST RMF Introductory Course Overview

Uploaded by

alamimran458
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
11 views101 pages

NIST RMF Introductory Course Overview

Uploaded by

alamimran458
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Risk Management Framework for Systems and

Organizations Introductory Course


Version 2.0
Updated August 2023

Based on NIST Special Publication (SP) 800-37, Revision 2


Risk Management Framework for Information Systems and Organizations: A System
Life Cycle Approach for Security and Privacy
This course is provided by the National Institute of Standards and
Technology and is available free of charge at [Link]
Terms of Use and Software Disclaimer

In accordance with its statutory authorities, NIST maintains a research information center to support the research, publishing, and preservation needs
required to fulfill the scientific and technical mission of NIST. NIST makes its RMF Introductory Course available to interested parties as a public service.
Pursuant to 17 USC 105, works authored by NIST employees are not subject to Copyright protection within the United States; foreign rights are reserved on
behalf of the Secretary of Commerce. To the extent that NIST may hold copyright or other rights in countries other than the United States, you are hereby
granted the non-exclusive irrevocable and unconditional right to print, publish, prepare derivative works, and distribute, in any medium, or authorize others
to do so on your behalf, on a royalty-free basis throughout the world. Downloads are made available as a courtesy of NIST. Please provide appropriate
attribution to NIST, the creator of the courses.
The RMF Introductory Course is provided “AS IS.” NIST makes NO WARRANTY of any kind, express or implied or statutory, including without limitation, the
implied warranty of merchantability, fitness for a particular purpose, non-infringement or data accuracy.
Permission to use this material is contingent upon your acceptance of these terms.

Software Disclaimer
NIST-developed software is provided by NIST as a public service. You may use, copy and distribute copies of the software in any medium, provided that you keep intact this entire notice. You may
improve, modify and create derivative works of the software or any portion of the software, and you may copy and distribute such modifications or works. Modified works should carry a notice
stating that you changed the software and should note the date and nature of any such change. Please explicitly acknowledge the National Institute of Standards and Technology as the source of the
software.
NIST-developed software is expressly provided "AS IS." NIST MAKES NO WARRANTY OF ANY KIND, EXPRESS, IMPLIED, IN FACT OR ARISING BY OPERATION OF LAW, INCLUDING, WITHOUT
LIMITATION, THE IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT AND DATA ACCURACY. NIST NEITHER REPRESENTS NOR WARRANTS THAT
THE OPERATION OF THE SOFTWARE WILL BE UNINTERRUPTED OR ERROR-FREE, OR THAT ANY DEFECTS WILL BE CORRECTED. NIST DOES NOT WARRANT OR MAKE ANY REPRESENTATIONS
REGARDING THE USE OF THE SOFTWARE OR THE RESULTS THEREOF, INCLUDING BUT NOT LIMITED TO THE CORRECTNESS, ACCURACY, RELIABILITY, OR USEFULNESS OF THE SOFTWARE.
You are solely responsible for determining the appropriateness of using and distributing the software and you assume all risks associated with its use, including but not limited to the risks and costs
of program errors, compliance with applicable laws, damage to or loss of data, programs or equipment, and the unavailability or interruption of operation. This software is not intended to be used in
any situation where a failure could cause risk of injury or damage to property. The software developed by NIST employees is not subject to copyright protection within the United States.

This course is provided by the National Institute of Standards and


2
Technology and is available free of charge at [Link]
Course Navigation Instructions

A brief overview on how to navigate through the course, when delivered via the NIST CSRC website:
• The course outline is shown in the left-hand navigation bar
• A keyword search is available, but you will only be able to access slides you have already viewed.
• The recommended use of this search function is meant for after you have completed the course and would like to refer to a particular topic.
• In the upper right-hand corner, there are two items of note: Marker Tools and Notes
• Clicking “Marker Tools” allows you to “mark up” (e.g. highlight, underline, etc) your version of the presentation slide, if you wish to do so
• Clicking “Notes” displays the written script of the audio track on that particular slide
• Under the main presentation slide, on the left-hand side:
• A Play/Pause button for the slide currently displayed
• A timer for the current slide is also displayed, as well as a replay button, volume control, and full-screen toggle button
• Under the main presentation slide, on the right-hand side:
• Navigate backward to slides you have already viewed using the “Prev” button
• Navigate forward to slides to return your current position in the course using the “Next” button
• Note that you cannot navigate forward to slides you have not yet seen
• The Accessibility icon is in the upper left-hand corner of the presentation window

At any time, you can leave the course and resume from where you left off in the
course – just be sure to enable cookies for this website in your browser.
This course is provided by the National Institute of Standards and
3
Technology and is available free of charge at [Link]
Welcome and Overview

Welcome to the Risk Management Framework (RMF) for Systems and Organizations
Course
• Why organizations need to manage risk
• Course purpose and target audience
• Course goal and authority
• Learning objectives

This course is provided by the National Institute of Standards and


RMF For Systems and Organizations Course Overview 4
Technology and is available free of charge at [Link]
Introduction

Why manage risk in an information security program?


• Prioritize security requirements and allocation of information security and privacy resources
• Facilitate decision-making about organizational, system security and privacy risk
• Promote development and dissemination of security and privacy policies and procedures
• Consolidate and streamline systems for tracking and risk management

This course is provided by the National Institute of Standards and


RMF For Systems and Organizations Course Overview 5
Technology and is available free of charge at [Link]
Course Purpose

The purpose of this course is to:


• Describe importance of organization-wide risk management program
• Detail the development, purpose, and steps of Risk Management Framework (RMF)
• Provide additional reference RMF materials

This course is provided by the National Institute of Standards and


RMF For Systems and Organizations Course Overview 6
Technology and is available free of charge at [Link]
Course Target Audience

The target audience for this course are individuals with responsibilities for:

• Mission and business functions

• System development and acquisition

• System security or privacy management oversight

• Security or privacy assessments, and system monitoring

• Security and privacy program implementation

This course is provided by the National Institute of Standards and


RMF For Systems and Organizations Course Overview 7
Technology and is available free of charge at [Link]
Course Goal and Authority

Course Goal
Gain familiarity with the RMF and supporting
publications, process, and integration into an
organization mission and business practices

Course Authority
Information from this course is applied in accordance
with legislative guidelines, standards, and requirements
established by the Federal Government and your
organization

This course is provided by the National Institute of Standards and


RMF For Systems and Organizations Course Overview 8
Technology and is available free of charge at [Link]
Learning Objectives

After completing this course, you will be able to:


• Explain the importance of establishing an organization-
wide risk management program
• Identify the federal information security legislation
related to organizational and system security and
privacy risk management
• Describe the purpose of the RMF
• Understand the steps and tasks in the RMF, including
relevant NIST publications to help with implementation
• Describe how use of the RMF assists in the creation of
an atmosphere of trust within an organization

This course is provided by the National Institute of Standards and


RMF For Systems and Organizations Course Overview 9
Technology and is available free of charge at [Link]
Course Structure

Completing the entire course should take approximately 3 hours. The breakdown in time
for each module is as follows:
• Welcome and Overview (9 minutes)
• Module 1: Federal Legislation and Policy (8 minutes)
• Module 2: NIST Special Publication 800-37 Background and Update Overview (10 minutes)
• Module 3: The Fundamentals (75 minutes)
• Lesson 1: Organization-wide Risk Management Lesson 6: Authorization Types and Decisions
• Lesson 2: Risk Management Framework Steps and Structure Lesson 7: Requirements and Controls
• Lesson 3: Information Security and Privacy in the RMF Lesson 8: Security and Privacy Posture
• Lesson 4: System and System Elements Lesson 9: Supply Chain Risk Management
• Lesson 5: Authorization Boundaries Lesson 10: Risk Management Roles and Responsibilities
• Module 4: The Risk Management Framework (59 minutes)
• Lesson 1: Overview of the Risk Management Framework
• Lesson 2: Risk Management Framework Steps
• Conclusion and Contact Information (3 minutes)

This course is provided by the National Institute of Standards and


RMF For Systems and Organizations Course Overview 10
Technology and is available free of charge at [Link]
Module 1: Federal Legislation and Policy
Objectives

Objectives for this module

• Identify specific United States Government


legislation and policy governing creation and
implementation of federal information security
practices

• Understand the requirements of the Federal


Information Security Modernization Act (FISMA) of
2014 for a federal organization

This course is provided by the National Institute of Standards and


Module 1: Federal Legislation and Policy 11
Technology and is available free of charge at [Link]
Information Technology Security Legislation and Policy

Federally mandated security practices:

• Are instituted by Congress and overseen and


coordinated by the Office of Management and Budget
(OMB)

• Govern creation and implementation of federal


information security practices

• Place responsibility and accountability for


information security at all levels within federal
agencies

• Are subject to reporting and oversight

This course is provided by the National Institute of Standards and


Module 1: Federal Legislation and Policy 12
Technology and is available free of charge at [Link]
Background: Relevant Legislation and Policy

E-Government Act (Public Law 107-347), Title III, Federal Information


Security Management Act (FISMA 2002)
• Requires each federal agency to develop, document, and implement an agency-wide program to
provide information security for the information and systems that support the operations and
assets of the agency, including those provided or managed by another agency, contractor, or other
sources
The Federal Informa on Security Moderniza on Act of 2014 (FISMA 2014)
• Amends FISMA 2002 with modifications to modernize federal security practices to address evolving
security concerns
• Less overall reporting
• Strengthens the use of con nuous monitoring in systems
• Increased focus on the agencies for compliance
• Reporting that is more focused on the issues caused by security incidents

This course is provided by the National Institute of Standards and


Module 1: Federal Legislation and Policy 13
Technology and is available free of charge at [Link]
Background: Relevant Legislation and Policy

Paperwork Reduction Act of 1995 and Information Technology Management Reform


Act of 1996
• Explicitly emphasizes a risk-based policy for cost-effec ve security
The Office of Management and Budget (OMB) Circular A-130, Managing
Federal Informa on as a Strategic Resource
• Establishes general policy for the planning, budgeting, governance, acquisition, and management of
Federal information, personnel, equipment, funds, IT resources and supporting infrastructure and
services. Also establishes responsibilities for protecting Federal information resources and
managing personally identifiable information (PII)
OMB Circular A-108, Federal Agency Responsibilities for Review, Reporting, and
Publication under the Privacy Act of 1974, as amended
• Regulates the collection, maintenance, use, and dissemination of personal information by federal
executive branch agencies

This course is provided by the National Institute of Standards and


Module 1: Federal Legislation and Policy 14
Technology and is available free of charge at [Link]
FISMA and Your Federal Organization

FISMA requires federal organizations to:


• Provide information security protections commensurate with the assessed risk
• Ensure senior leaders provide information security for assets under their control
• Ensure the organization has trained personnel to assist in complying with FISMA and related policies
• Provide annual reports on the adequacy and effectiveness of information security policies,
procedures, and practices
• Develop, document, and implement an information security program
• Develop and maintain an inventory of systems under the control of the organization
• Develop security awareness training to inform personnel of information security risks
• Perform an independent evaluation of the information security program and practices to determine
program and practices effectiveness

This course is provided by the National Institute of Standards and


Module 1: Federal Legislation and Policy 15
Technology and is available free of charge at [Link]
Module 2: NIST SP 800-37 Background
Objectives

Objectives for this module

• Discuss purpose and background of NIST


Special Publication (SP) 800-37, Revision 2

• Understand the major updates in NIST SP


800-37, Revision 2

This course is provided by the National Institute of Standards and


Module 2: NIST SP 800-37 Background 16
Technology and is available free of charge at [Link]
NIST SP 800-37 Purpose

• Promote an organization-wide risk management process to include privacy and


information security risk
• Manage privacy and information security risk consistent with mission/business
objectives and the overall risk strategy
• Ensure consistent risk posture throughout organization
• Integrate security and privacy requirements into the organization’s enterprise
architecture
• Establish who is accepting risk for the system and the organization
• Provide senior leaders the necessary information about organization’s risk posture to
make informed decisions

This course is provided by the National Institute of Standards and


Module 2: NIST SP 800-37 Background 17
Technology and is available free of charge at [Link]
Publication Evolution

May 2004 Feb 2010 Dec 2018


NIST SP 800-37, Guide for the NIST SP 800-37, Revision 1, Issued as a NIST SP 800-37, Revision 2,
Security Certification and Guide for Applying the Risk Joint Task Risk Management
Force (JTF) Framework for Information
Accreditation of Federal Management Framework to
publication
Information Systems, Federal Information Systems: Systems and Organizations:
originally published A Security Life Cycle Approach, A System Life Cycle
published Approach for Security and
Jun 2014 Privacy, published
NIST SP 800-37, Revision 1,
updated
2002 2004 2005 2006 2007 2008 2009 2010 2011 2013 2014 2015 2018 2020 2022 Future

Dec 2002 Dec 2014


FISMA enacted Feb 2004 Mar 2006 FISMA 2014 enacted
Jan 2020
FIPS 199 FIPS 200 Sep 2011 Apr 2015 NIST Privacy May 2022
originally originally NIST SP 800-161 Framework 1.0 NIST SP 800-161,
NIST SP 800-137
published published originally published published Revision 1, published
originally published
Feb 2005 Aug 2009 Apr 2013 Sep 2020
NIST SP 800-53, NIST SP 800-53, NIST SP 800-53, NIST SP 800-53,
originally published Revision 3, published Revision 4, published Revision 5, published

Jul 2008 Dec 2014 Jan 2022


NIST SP 800-53A, NIST SP 800-53A, NIST SP 800-53A,
originally published Revision 4, published Revision 5, published

Special Publications continue to be developed and updated to further NIST’s statutory responsibilities under the
Federal Information Security Modernization Act (FISMA), 44 U.S.C. § 3551 et seq., Public Law (P.L.) 113-283
This course is provided by the National Institute of Standards and
Module 2: NIST SP 800-37 Background 18
Technology and is available free of charge at [Link]
Differences Between NIST SP 800-37 Rev. 1 & Rev. 2

• New guidance addresses and includes:


• Alignment and integration of supply chain, privacy, Cybersecurity Framework (CSF), and
security engineering processes into the RMF
• Guidance on how RMF is implemented in the system development life cycle (SDLC)
• Addi on of the organiza on-level and system-level Prepare Step
• Poten al inputs and expected outputs for all RMF Tasks
• Closer linkages between C-Suite/Governance-level to system/operational-level to facilitate better
communication
• Updated and Expanded Guidance on:
• Authoriza on boundaries
• Authoriza on decisions & types
• Ongoing authoriza on
• Roles & responsibili es

This course is provided by the National Institute of Standards and


Module 2: NIST SP 800-37 Background 19
Technology and is available free of charge at [Link]
Privacy Integration into the RMF

• Addresses privacy risk management in accordance with Office of Management and


Budget (OMB) Circular A-130
• Privacy and RMF addressed in Section 2.3 – Information Security and Privacy in the
RMF
• Privacy called out in RMF task text as appropriate (e.g., Task P-3 is to assess security
and privacy risk)
• Privacy-specific Inputs, Outputs, Roles, and References specified as appropriate in
tasks
• Privacy-specific detail in task discussions

This course is provided by the National Institute of Standards and


Module 2: NIST SP 800-37 Background 20
Technology and is available free of charge at [Link]
RMF and Cybersecurity Framework Alignment

• Inputs and Outputs reference CSF, as


applicable (e.g., CSF profile as potential output
from Task P-4)

• Task Outcome tables reference CSF sections,


categories, or sub-categories as applicable

• References for tasks indicate relevant CSF


sections (if applicable)

This course is provided by the National Institute of Standards and


Module 2: NIST SP 800-37 Background 21
Technology and is available free of charge at [Link]
Systems Security Engineering and RMF Alignment

• Systems security engineering addresses security risks throughout the system


development life cycle (and system life cycle)
• Alignment of RMF steps/tasks with existing systems security engineering processes
• Task references list the related systems security engineering processes from NIST SP
800-160, Volume 1, Engineering Trustworthy Secure Systems, as applicable
• New Tasks in the Prepare System-Level Step to align with system security engineering
processes
• P-9: System stakeholders
• P-10: Asset identification
• P-15: Requirements definition
• P-17: Requirements allocation

This course is provided by the National Institute of Standards and


Module 2: NIST SP 800-37 Background 22
Technology and is available free of charge at [Link]
Supply Chain and RMF Alignment

• Discussion of Supply Chain Risk Management (SCRM) within the RMF added in section
2.8 – Supply Chain Risk Management

• SCRM addressed in Task discussions as applicable

• SCRM artifacts included in task Inputs and Outputs as applicable

• SCRM responsibilities noted in Appendix D

This course is provided by the National Institute of Standards and


Module 2: NIST SP 800-37 Background 23
Technology and is available free of charge at [Link]
Incorporating RMF into the SDLC

Example RMF Task

Each task in NIST SP 800-37 (RMF)


describes the primary responsibility (role)
and supporting roles associated with the
task and the phase of the SDLC where task
execution occurs
Primary Responsibility and Supporting Roles

SDLC Phase

This course is provided by the National Institute of Standards and


Module 2: NIST SP 800-37 Background 24
Technology and is available free of charge at [Link]
Module 3: The RMF Fundamentals

Objectives for this module

• Compare organization-wide risk management with security and privacy risk management and
supply chain risk management

• Introduce the RMF at a high level

• Identify roles and responsibilities associated with each task of the RMF

This course is provided by the National Institute of Standards and


Module 3: The RMF Fundamentals 25
Technology and is available free of charge at [Link]
Lesson 1: Organization-Wide Risk Management

• Security and privacy risk management


is the process of managing risk to
organizational operations resulting
from the operation or use of systems
• To integrate the risk management
process throughout the organization, a
three-level approach is employed that
addresses risk at the:
Level 1: Organization
Level 2: Mission/Business Process
Level 3: System

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
26
Lesson 1: Organization-Wide Risk Management Technology and is available free of charge at [Link]
Organization-Wide Risk Management

Risk management is a comprehensive process that requires


organizations to:
• Frame Risk
Establish a risk context by describing the environment in which risk-
based decisions are made and produce a risk management strategy
• Assess Risk
Identify threat sources and vulnerabilities to the organization,
potential mission/business impact, likelihood and uncertainty of
occurrence
• Respond to Risk
Provide consistent organization-wide response to risk by developing
and evaluating alternative courses of action, determining
appropriate course of action and implementing the risk response
• Monitor Risk
Verify planned risk response measures are implemented, determine
ongoing effectiveness of risk response, and how risk is monitored
over time

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
27
Lesson 1: Organization-Wide Risk Management Technology and is available free of charge at [Link]
Organization-Wide Risk Management Conclusion

• A key to success for an organization-wide risk management program is obtaining a


broad-based, organization-wide perspective and support
• The objective of an organization-wide risk management program is to enable the
organization to conduct its day-to-day operations and accomplish its missions
• Managing risk from the operation and use of systems is critical to your organization’s
goals and mission and should be considered within the enterprise architecture
• For more information about the content covered in this lesson, see NIST SP 800-39,
Managing Information Security Risk: Organization, Mission, and Information System
View

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
28
Lesson 1: Organization-Wide Risk Management Technology and is available free of charge at [Link]
Lesson 2: Risk Management Framework Steps and Structure

• There are seven steps in the RMF: a preparatory step to


ensure that organizations are ready to execute the
process and six main steps
• Organizations have flexibility in how each of the RMF
steps and tasks are implemented, as long as
organizations meet all applicable requirements
and effectively managing security and privacy risk
• All seven steps are essential for the
successful execution of the RMF
• Prepare
• Categorize
• Select
• Implement
• Assess
• Authorize
• Monitor

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
29
Lesson 2: RMF Steps and Structure Technology and is available free of charge at [Link]
Risk Management Framework Steps and Structure

Each step in the RMF has a purpose statement, set of outcomes, and tasks that are
carried out to achieve those outcomes captured in the Step Summary
Purpose
Example: Purpose The purpose of the Implement step is to implement the controls in the security and privacy plans for the system and
for the organization and to document in a baseline configuration, the specific details of the control implementation.

Tasks Outcomes
Example: RMF
TaskTask
I-1 Outcome  Controls specified in the security and privacy plans are implemented.
[Cybersecurity Framework: [Link]-1]
Control Implementation
 Systems security and privacy engineering methodologies are used to implement the controls
in the system security and privacy plans.
Example: Applicable CSF Component [Cybersecurity Framework: [Link]-2]

Task I-2  The configuration baseline is established.


Example: Task [Cybersecurity Framework: [Link]-1]
Baseline Configuration
 The security and privacy plans are updated based on information obtained during the
implementation of the controls.
[Cybersecurity Framework: Profile]

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
30
Lesson 2: RMF Steps and Structure Technology and is available free of charge at [Link]
Risk Management Framework Task Structure

• Task Section: Describes the specific RMF task within the appropriate step
• Potential Inputs: Lists information that may be needed to complete the task (NEW)
• Expected Outputs:
Describes the end result of task
completion (NEW)
• Primary Responsibility
Section: Lists the individual or
group within the organization
having primary responsibility
for ensuring completion of the
RMF task
• Supporting Roles Section:
Lists the supporting roles within
the organization that may help
with or provide input for task
completion
• SDLC Phase Section: Lists the
phase of the SDLC when the RMF task is typically executed
• Discussion Section: Provides additional information about the RMF task
• References Section: Provides general references to NIST security standards and guidelines that may be consulted for additional information

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
31
Lesson 2: RMF Steps and Structure Technology and is available free of charge at [Link]
Lesson 3: Security and Privacy in the RMF

• Security of personally identifiable information


(PII) plays an important role in the protection of
privacy
• Individual privacy cannot be achieved solely by
securing PII
• Authorized processing: system operations that
handle PII (collection - disposal) to enable the
system to achieve mission/business objectives
• Shared responsibility for managing the risks to
individuals that may arise from unauthorized
system activity or behavior
For more information about the privacy risk model, see NIST
Internal Report 8062, An Introduction to Privacy Engineering
and Risk Management in Federal Systems

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
32
Lesson 3: Information Security and Privacy Technology and is available free of charge at [Link]
NIST Privacy Risk Assessment Methodology (PRAM)

• The PRAM is a NIST-developed tool that applies the


risk model from NISTIR 8062 and helps organizations
analyze, assess, and prioritize privacy risks to
determine how to respond and select appropriate
solutions
• The PRAM helps drive collaboration and
communication between various components of an
organization, including privacy, cybersecurity,
business, and IT personnel
• Once the organization has determined which risks to
mitigate, the organization can refine the privacy and
security requirements and then select and
implement controls (i.e., technical and/or policy
safeguards) to meet the defined requirements

[Link]
engineering/resources#pram

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
33
Lesson 3: Information Security and Privacy Technology and is available free of charge at [Link]
Lesson 4: System and System Elements

The definitions below link the RMF to systems engineering community


• Per International Standards Organization (ISO) 15288, “System is defined as a set of interacting elements organized
to achieve one or more stated purposes”
• System elements within the system are implemented to fulfill specified requirements
• Can include technology or machine elements; human elements; and physical or environmental elements
• May be implemented via hardware, software, or firmware; physical structures or devices; or people, processes, and procedures
• For a large or complex system, a system element may be regarded as a system and composed of system elements
• System-of-interest may be supported by one or more enabling systems that provide support to the system life cycle
activities associated with the system-of-interest
• Enabling systems are not necessarily delivered with the system-of-interest and do not necessarily exist in the
operational environment of the system of interest
• Authorization boundary defines the system for RMF execution to facilitate risk management and accountability
• Finally, there are other systems the system-of-interest interacts with in the operational environment. These systems
may provide services to the system-of-interest or may be the beneficiaries of services provided by the system-of-
interest (i.e., potential two-way dependencies)

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
34
Lesson 4: System and System Elements Technology and is available free of charge at [Link]
System and Relational View of the System

• Applied to systems-of-
interest, not individual ENVIRONMENT OF OPERATION
system elements Enabling Enabling
System System

System
Element
• Diagram illustrates the Enabling Enabling
conceptual view of the System
System System
System

system-of-interest Element Element

SYSTEM
(AUTHORIZATION BOUNDARY)

Other Other Other


System System System

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
35
Lesson 4: System and System Elements Technology and is available free of charge at [Link]
Lesson 5: Authorization Boundaries

• Establishes the scope of protection for systems (i.e., what is to be protected as part of
a given system)
• Defines the scope of the authorizing official’s responsibility and accountability for
protecting information resources and individuals’ privacy
• Established during Task P-11 Authorization Boundary (before security categorization
and development of security plans)
• Guidance in Section 2.5 and Appendix G in NIST SP 800-37, Revision 2

To encourage consistency in terminology, the term “system boundary” is no


longer used interchangeably with the term “authorization boundary.”

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
36
Lesson 5: Authorization Boundaries Technology and is available free of charge at [Link]
Determination of Authorization Boundary Considerations

Organizations consider system elements and organization-wide activities when


determining authorization boundaries

Considerations for Determining Authorization Boundaries


Examples of System Elements Examples of Organization-wide Activities

• Are under same direct management • Mission/business requirements


• Support same mission or business functions • Security and privacy requirements
• Process/store/transmit similar information • Costs to the organization (with respect to
types potential loss)
• Reside in same/very similar operating
environments

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
37
Lesson 5: Authorization Boundaries Technology and is available free of charge at [Link]
Boundaries for Complex Systems and External Providers

Dividing a system into subsystems facilitates a targeted application of controls to


achieve adequate security, protection of individual privacy, and a cost-effective risk
management process
Potential Scenarios for Dividing a System Into Subsystems
Complex Systems External Providers
• Can be viewed as individual subsystems • Providers that process, store, transmit federal
• Divided up into set of manageable groups of information, operate systems on behalf of federal
system elements government must meet same security and privacy
• All support similar mission, but distinct enough to requirements as federal systems
be identified separately • Organization level of trust in external provider
• Monitor communications at internal boundaries dependent upon control implementation and
among subsystems privacy protection
• Security categorization of subsystems are
considered for control allocation

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
38
Lesson 5: Authorization Boundaries Technology and is available free of charge at [Link]
Lesson 6: Authorization Types and Decisions

• Authorization Types • Type Authorization


• Initial Authorization
• Ongoing Authorization • Facility Authorization
• Reauthorization

• Traditional Authorization
• Authorization Decisions
• Authorization to Operate
• Common Control Authorization
• Joint Authorization
• Authorization to Use
• Denial of Authorization

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
39
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Authorization Types

• Initial Authorization

• Ongoing Authorization

• Reauthorization

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
40
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Authorization Types:
Initial Authorization

• Initial (start-up) risk determination and risk acceptance


• Based on a complete, zero-based review of the system or of common controls
• Zero-based review includes:
• Assessment of all implemented system-level controls
• Review of the security status of inherited common controls specified in security and privacy plans
• Zero-based review of system does not require zero-based review of common controls
available and inherited by system
• Common control zero-based review includes:
• Assessment of any controls that contribute to the provision of a common control or set of common
controls

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
41
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Authorization Types:
Ongoing Authorization

• Subsequent (follow-on) risk determinations and


risk acceptance decisions

• Occurs at agreed-upon and documented


frequencies (time-driven) and when organization-
defined thresholds are exceeded (event-driven)

• Conducted with a similar level of effort as the


initial authorization and may be:
• A complete, zero-based assessment; or
• A targeted assessment based on the type of event that
triggered the reauthorization action

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
42
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Authorization Types:
Reauthorization

• Static, single point-in-time risk determination and risk acceptance that occurs after
the initial authorization
• May be time-driven or event-driven
• Separate activity from ongoing authorization
• Conducted with a similar level of effort as the initial authorization and may be:
• Complete, zero-based assessment; or
• Targeted assessment based on the type of event that triggered the reauthorization action
• Reauthorization actions may lead to a review of the ISCM strategy which could affect
ongoing authorization

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
43
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Authorization Decisions

• Authorization to Operate

• Common Control Authorization

• Authorization to Use

• Denial of Authorization

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
44
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Authorization Decisions:
Authorization to Operate

• Issued by the Authorizing Official after determining that the risk to organizational
operations, assets, individuals, other organizations, and the Nation is acceptable

• An authorization termination date is specified or, if under ongoing authorization, a


time-driven authorization frequency is specified

• Authorizing Official may include operating restrictions as part of the authorization to


operate

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
45
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Authorization Decisions:
Common Control Authorization

• Similar to authorization to operate for a system, but issued for common controls
• Common control authorization termination date is specified or, if under ongoing
authorization, a time-driven authorization frequency is specified
• Common controls implemented as part of a system do not require a separate
common control authorization

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
46
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Authorization Decisions:
Authorization to Use

• Employed when an organization (customer organization), after reviewing an existing


authorization package, accepts the authorization to operate (ATO) issued by an
authorizing official (AO) from another federal entity (provider organization)
• Issued by an official (customer organization) with the same level of responsibility and
authority for risk management as an AO that issues an ATO (provider organization)
• Indicates acceptance of risk by the customer organization with respect to customer’s
information
• Remains in effect as long as the customer organization continues to accept the risk as
indicated in provider organization’s authorization package

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
47
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Authorization Decisions:
Denial of Authorization

• Authorizing official denies authorization to operate, common control authorization, or


authorization to use when existing risk is determined to be unacceptable

• Denial of authorization indicates that there are significant deficiencies in controls


• Risk is not managed in accordance with organizational risk management strategy and risk tolerance
• Required controls are not implemented
• Implemented controls are not operating as intended

Authorizing officials should not feel pressured into accepting unacceptable risk

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
48
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Authorization Decisions:
Type, Facility, Traditional, Joint Authorization

• Type Authorization
• Single authorization for a common version of a system
• Utilized when system comprised of identical instances of architecture, software, information types
• Often used in conjunction with a facility authorization
• Facility Authorization
• Authorizes common controls provided in a specific environment of operation
• Provided at a specified impact level
• Traditional Authorization
• Single organizational official in a senior leadership position is responsible and accountable for a system or for
common controls
• Joint Authorization
• Multiple organizational officials either from the same organization or different organizations, have a shared
interest in authorizing a system

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
49
Lesson 6: Authorization Types and Decisions Technology and is available free of charge at [Link]
Lesson 7: Requirements and Controls

The terms, requirements and controls, can have different


definitions when used in different contexts.
• Requirements definition:
• In the context of federal information security and privacy policy, includes both legal and policy requirements,
as well as an expression of the broader set of stakeholder protection needs that may be derived from other
sources
• Assists in determining the required characteristics of the system—encompassing security, privacy, and
assurance
• Controls definition:
• Safeguards and protection capabilities appropriate for achieving the particular security and privacy objectives
of the organization
• Reflects the protection needs of organizational stakeholders
• Selected and implemented by the organization in order to satisfy the system requirements
• Includes technical aspects, administrative aspects, and physical aspects of the system

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
50
Lesson 7: Requirements and Controls Technology and is available free of charge at [Link]
Lesson 8: Security and Privacy Posture

• Represents the status of systems, information resources, and information technology


capabilities within an organization based on information assurance resources (e.g.,
personnel, equipment, funds, hardware, software, policies, procedures)

• Determined on an ongoing basis by assessing and continuously monitoring system-


specific, hybrid, and common controls

• Utilized by authorizing officials to determine if the risk to organizational operations


and assets, individuals, other organizations, or the Nation are acceptable based on the
organization’s risk management strategy and organizational risk tolerance

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
51
Lesson 8: Security and Privacy Posture Technology and is available free of charge at [Link]
Lesson 9: Supply Chain Risk Management

• Managing supply chain risk is a complex, multifaceted undertaking requiring a coordinated effort across
an organization
• Organizations develop a Supply Chain Risk Management (SCRM) Strategy, Policies and Plans for directing
SCRM activities
• SCRM activities involve:
• Identifying and assessing applicable risks
• Determining appropriate mitigating actions
• Developing appropriate SCRM plans to document selected mitigating actions
• Monitoring performance against SCRM plans
• SCRM strategy can be included as part the Risk Management Strategy, or a separate artifact
• SCRM policies direct the implementation of the SCRM strategy
• SCRM plans are tailored to the individual program, organizational, and operational contexts
• Organizations have flexibility on how the details of SCRM strategies and plans are documented

The organization and authorizing official are ultimately responsible for responding to
risks from the use of component products, systems, and services external providers
Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
52
Lesson 9: Supply Chain Risk Management Technology and is available free of charge at [Link]
Lesson 10: Risk Management Roles and Responsibilities

• Regardless of job function, everyone has a role in


security and privacy

• This course focuses on those roles that are related


to the security and privacy of a system

• When everyone in the organization functions as a


part of the “security and privacy team”
• Risk management is more effective
• Overall quantity and quality of risk-related operational
information is improved
• Better decisions can be made at the executive level

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
53
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities

The RMF describes the roles and responsibilities of key participants involved in an organization’s risk
management process. There may be differences in naming conventions and how responsibilities are
allocated among personnel. NIST SP 800-181, National Initiative for Cybersecurity Education (NICE)
Cybersecurity Workforce Framework, provides a reference and common lexicon for describing and
sharing information about cybersecurity work, the knowledge, skills and abilities needed.
• Authorizing Official • Risk Executive (Function)
• Authorizing Official Designated Representative • Security or Privacy Architect
• C-Suite Officials (e.g., Chief Acquisition Officer, • Senior Accountable Official for Risk Management
Chief Information Officer, Head of Agency) • Senior Agency Information Security Officer
• Common Control Provider • Senior Agency Official for Privacy
• Control Assessor • System Owner
• Enterprise Architect • System Security or Privacy Officer
• Information Owner or Steward • System Security or Privacy Engineer

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
54
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Authorizing Official

• Assumes responsibilities and accountability for making the decision on authorizing a


system to operate
• If the risk is deemed unacceptable, an ATO is not issued or is rescinded, and the system is not put
into operation or operations are halted on operational systems
• Consults with multiple organization personnel and other interested parties during the
authorization process
• For federal agencies, the role of authorizing official is an inherent U.S. Government
function and is assigned to government personnel only
• The AO is the only organizational official who can accept the security and privacy risk
to organizational operations, organizational assets, and individuals

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
55
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Authorizing Official Designated Representative

• Designated by the authorizing official

• Conducts day-to-day activities associated with managing risk to systems and


organizations

• Not authorized to accept risk and make authorization decisions

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
56
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
C-Suite Officials

• Oversees performance of security and privacy-related activities and programs

• Ensures accountability in respective program areas

• Establishes organizational risk management strategy, commitment, and risk tolerance

• Establishes the organizational commitment and the actions required to effectively


manage security and privacy risk and protect the missions and business functions
being carried out by the organization

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
57
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Common Control Provider

• Responsible for the implementation, assessment, and monitoring of common controls


(i.e., controls inherited by organizational systems)
• Provides organization-defined common controls are in security and privacy plans
• Ensures assessments of the common controls are conducted by qualified assessors
with an appropriate level of independence
• Documents assessment findings in control assessment reports
• Produces plans of action and milestones for common controls having deficiencies

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
58
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Control Assessor

• Conducts a comprehensive assessment of implemented controls and control


enhancements to determine the effectiveness of the controls
• Reviews the security and privacy plans to facilitate development of the assessment
plans
• Provides an assessment of the severity of the deficiencies discovered in the system,
environment of operation, and common controls and can recommend corrective
actions to address the identified vulnerabilities
• Prepares security and privacy assessment reports containing the results and findings
from the assessment

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
59
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Enterprise Architect

• Implements an enterprise architecture strategy that facilitates effective security and


privacy solutions
• Coordinates with security and privacy architects to
• Determine the optimal placement of systems/system elements within the enterprise architecture
• Address security and privacy issues between systems and the enterprise architecture
• Assists in reducing complexity within the IT infrastructure
• Assists with determining appropriate control implementations and initial
configuration baselines as they relate to the enterprise architecture
• Collaborates with system owners and authorizing officials to facilitate authorization
boundary determinations and allocation of controls to system elements

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
60
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Information Owner or Steward

• Responsible for management, or operational authority for specified information and


the responsibility for establishing the policies and procedures governing its generation,
collection, processing, dissemination, and disposal

• Responsible for establishing the rules for appropriate use and protection of the
information

• Provides input to system owners regarding the security and privacy requirements and
controls for the systems where the information is processed, stored, or transmitted

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
61
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Risk Executive (Function)

• Provides a comprehensive, organization-wide approach to risk management


• Ensures that risk-related considerations from systems are viewed from an
organization-wide perspective aligning with overall organization strategic goals and
objectives
• Ensures that risk is management is consistently throughout the organization, reflects
organizational risk tolerance, and is considered along with other types of risk to
ensure mission/business success
• For federal agencies, the risk executive (function) is an inherent U.S. Government
function and is assigned to government personnel only

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
62
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Security or Privacy Architect

• Responsible for ensuring that stakeholder protection needs and the corresponding
system requirements are met

• Serves as the primary liaison between the enterprise architect and the systems
security or privacy engineer

• Coordinates with system owners, common control providers, and system security or
privacy officers on the allocation of controls

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
63
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Senior Accountable Official for Risk Management (SAORM)

• Leads the risk executive (function) within an organization; is the head of the agency or
is designated by the head of the agency

• Responsible for aligning information security and privacy risk management processes
with strategic, operational, and budgetary planning processes

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
64
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Senior Agency Information Security Officer (SAISO)

• Organizational official responsible for carrying out the chief information officer
security responsibilities under FISMA

• Serves as the CIO’s liaison to the authorizing officials, system owners, and system
security officers

• May also be referred to as the Chief Information Security Officer (CISO)

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
65
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
Senior Agency Official for Privacy (SAOP)

• Ensures compliance with applicable privacy requirements and managing privacy risk
• Works with the senior agency information security officer to coordinate privacy and
information security activities
• Assesses privacy controls and provides privacy information to the authorizing official as
needed
• Identifies assessment methodologies and metrics to determine whether privacy controls
are implemented correctly, operating as intended, and sufficient to ensure compliance
with applicable privacy requirements and manage privacy risks
• Reviews authorization packages for systems that create, collect, use, process, store,
maintain, disseminate, disclose, or dispose of personally identifiable information
• Establishes and maintains privacy continuous monitoring program

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
66
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
System Owner

• Responsible for the overall procurement, development, integration, modification,


operation, maintenance, and disposal of a system
• Responsible for addressing the operational interests of the user community and
ensures compliance with security requirements
• Ensures that system users and support personnel receive the requisite security and
privacy training
• Receives the security and privacy assessment results from the control assessors and
then takes appropriate steps to reduce or eliminate vulnerabilities or security and
privacy risks
• Assembles the authorization package and submits the package to the authorizing
official or the authorizing official designated representative for adjudication

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
67
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
System Security or Privacy Officer

• Ensures that the operational security and privacy posture is maintained for an
organizational system and as such, works in close collaboration with the system owner

• Serves as a principal advisor on all matters, technical and otherwise, involving the
security or privacy controls for the system

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
68
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Risk Management Roles and Responsibilities:
System Security or Privacy Engineer

• Serves as part of the development team—designing and developing organizational


systems or upgrading existing systems along with ensuring continuous monitoring
requirements are addressed at the system level

• Employs best practices when implementing controls including software engineering


methodologies system and security or privacy engineering principles; security or
privacy-enhancing design, security or privacy-enhancing architecture, and security or
privacy-enhancing coding techniques

• Coordinates security and privacy activities with organization security and privacy
officials

Module 3: The RMF Fundamentals This course is provided by the National Institute of Standards and
69
Lesson 10: Roles and Responsibilities Technology and is available free of charge at [Link]
Module 3 Summary

• Managing risk is a complex, multifaceted activity that requires the involvement of the entire
organization—from senior leaders/executives, to mid-level leaders, to individuals responsible for
system-level security
• Privacy, security, and supply chain risk management is not a static process
• Authorization boundary defines the system for RMF execution to facilitate risk management and
accountability, define for an account for flow of information through the system
• Security and privacy programs require close collaboration, defining roles and responsibilities allows an
organization to effectively accomplish specific tasks, manage security and privacy risks, and clarify
expectations
• Authorizing officials should not feel pressured into accepting risk that is not consistent with the
organizational risk tolerance
• The RMF describes the roles and responsibilities of key participants involved in an organization’s risk
management process; across organizations, there may be differences in naming conventions and how
responsibilities are allocated among personnel

This course is provided by the National Institute of Standards and


Module 3: The RMF Fundamentals 70
Technology and is available free of charge at [Link]
Module 4: The Risk Management Framework

Objectives for this module

• Learn about about the process organization use to identify and select the appropriate risk
mitigations needed to protect the systems, information, and infrastructure supporting
organizational mission/business processes

• Understand guidance for organizations to develop robust and repeatable practices for securing and
protecting the privacy of its information and systems

This course is provided by the National Institute of Standards and


Module 4: The Risk Management Framework 71
Technology and is available free of charge at [Link]
Lesson 1: Overview of the Risk Management Framework

• The Risk Management Framework provides organizations with several key benefits:
• A structured, yet flexible process for managing risk related to the operation of systems
• Guidance for determining the appropriate risk mitigation needed to protect the systems and
infrastructure supporting organizational mission/business processes
• A repeatable methodology that balances key mission/business goals and organizational priorities
with security requirements and policy guidance
• A processes for continuous monitoring resulting in continuous improvement of the organization’s
security posture
• A technology-neutral methodology that can be applied to any type of information system without
modification
Specific controls selected, control implementation details, and control assessment methods/objects will vary
with different types of systems, there is no need to adjust the RMF process to accommodate specific
technologies (e.g., Internet of Things, industrial control and automation)

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
72
Lesson 1: Overview of the RMF Technology and is available free of charge at [Link]
What is the Risk Management Framework?

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
73
Lesson 1: Overview of the RMF Technology and is available free of charge at [Link]
Lesson 2: Risk Management Framework Steps

Organizations are expected to execute all steps and tasks in the RMF.
Organizations have significant flexibility in how the RMF steps and tasks are carried
out, if applicable requirements are met, and security and privacy risk is managed.

• There are seven steps in the RMF: a preparatory


step to ensure that organizations are ready to
execute the process and six main steps

• The RMF Steps are listed in sequential order, but


the steps following the Prepare step can be
carried out in a nonsequential order

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
74
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Prepare
Purpose

Carry out essential activities at all three


risk management levels to help prepare
the organization to manage its security
and privacy risks using the RMF

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
75
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Prepare
Organization and Mission/Business Process Level Tasks (NEW)
P-1: Risk Management Roles
Identify and assign individuals to specific roles associated with security and privacy risk management
P-2: Risk Management Strategy
Establish a risk management strategy for the organization that includes a determination of risk tolerance
P-3: Risk Assessment - Organization
Assess organization-wide security and privacy risk and update the risk assessment results on an ongoing basis
P-4: Organizationally-tailored Control Baselines and CSF Profiles (optional)
Establish, document, and publish organizationally-tailored control baselines and/or cybersecurity framework profiles
P-5: Common Control Identification
Identify, document, and publish organization-wide common controls that are available for inheritance by organizational systems
P-6: Impact Level Prioritization (optional)
Prioritize organizational systems within the same impact level
P-7: Continuous Monitoring Strategy - Organization
Develop and implement an organization-wide strategy for continuously monitoring control effectiveness

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
76
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Prepare
System Level Tasks (NEW)
P-8: Mission or Business Focus P-14: Risk Assessment - System
Identify the missions, business functions, and mission/business Conduct a system-level risk assessment and update the risk
processes that the system is intended to support assessment results on an ongoing basis
P-9: System Stakeholders P-15: Requirements Definition
Identify stakeholders who have an interest in the design, Define the security and privacy requirements for the system and
development, implementation, assessment, operation, the environment of operation
maintenance, or disposal of the system
P-16: Enterprise Architecture
P-10: Asset Identification Determine the placement of the system within the enterprise
Identify assets that require protection architecture
P-11: Authorization Boundary P-17: Requirements Allocation
Determine the authorization boundary of the system Allocate security and privacy requirements to the system and to
the environment of operation
P-12: Information Types
Identify the types of information to be processed, stored, or P-18: System Registration
transmitted by the system Register the system with organizational program or management
offices
P-13: Information Life Cycle
Identify and understand all stages of the information life cycle for
each information type processed, stored, or transmitted by the
system

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
77
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Prepare
Supporting Publications

The following NIST publications support this step:


• NIST SP 800-30, Guide for Conducting Risk Assessments
• NIST SP 800-39, Managing Information Security Risk: Organization, Mission, and Information System View
• NIST SP 800-53B, Control Baselines and Tailoring Guidance for Federal Information Systems and Organizations
• NIST SP 800-60, Volume 1, Guide for Mapping Types of Information and Information Systems to Security Categories
• NIST SP 800-60, Volume 2, Guide for Mapping Types of Information and Information Systems to Security Categories:
Appendices
• NIST SP 800-160, Volume 1, Engineering Trustworthy Secure Systems
• NIST SP 800-161, Supply Chain Risk Management Practices for Federal Information Systems and Organizations
• NIST IR 8062, An Introduction to Privacy Engineering and Risk Management in Federal Systems
• NIST IR 8179, Criticality Analysis Process Model: Prioritizing Systems and Components

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
78
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Categorize
Purpose

Inform organizational risk management


processes and tasks by determining the
adverse impact of the loss of
confidentiality, integrity, and availability of
organizational systems and information to
the organization

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
79
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Categorize
Tasks
C-1: System Description
Document the characteristics of the system
C-2: Security Categorization
Categorize the system and document the security categorization results
C-3: Security Categorization Review and Approval (NEW)
Review and approve the security categorization results and decision

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
80
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Categorize
Supporting Publications

The following NIST publications support this step:


• FIPS 199, Standards for Security Categorization of Federal Information and Systems
• NIST SP 800-60, Volume 1, Guide for Mapping Types of Information and Information Systems to Security Categories
• NIST SP 800-60, Volume 2, Guide for Mapping Types of Information and Information Systems to Security Categories:
Appendices
• NIST SP 800-18, Guide for Developing System Security Plans for Federal Systems

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
81
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Select
Purpose

Select, tailor, and document the controls


necessary to protect the system and
organization commensurate with risk to
organizational operations and assets,
individuals, and the Nation.

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
82
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Select
Tasks
S-1: Control Selection
Select the controls for the system and environment of operation
S-2: Control Tailoring (NEW)
Tailor the controls selected for the system and environment of operation
S-3: Control Allocation (REVISED)
Allocate security and privacy controls to the system and to the environment of operation
S-4: Document Planned Control Implementations (NEW)
Document the controls for the system and environment of operation in security and privacy plans
S-5: Continuous Monitoring Strategy – System (REVISED)
Develop and implement a system-level strategy for monitoring control effectiveness that is consistent with and supplements the organizational
continuous monitoring strategy
S-6: Plan Review and Approval
Review and approve the security and privacy plans for the system and environment of operation

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
83
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Select
Supporting Publications

The following NIST publications support this step:


• FIPS 200, Minimum Security Requirements for Federal Information and Systems
• NIST SP 800-53, Security and Privacy Controls for Federal Systems and Organizations
• NIST SP 800-53B, Security and Privacy Controls for Federal Information Systems and Organizations

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
84
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Implement
Purpose

Accomplish the activities necessary to


translate the security and privacy controls
identified in the system security plan into
an effective implementation

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
85
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Implement
Tasks
I-1: Control Implementation
Implement the controls as specified in security and privacy plans
I-2: Update Control Implementa on Informa on (REVISED)
Document changes to planned control implementa ons based on the as-implemented state of the controls

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
86
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Implement
Supporting Publications

The following NIST publications support this step:


• NIST SP 800-128, Guide for Security-Focused Configuration Management of Information Systems
• NIST SP 800-34, Contingency Planning Guide for Federal Information Systems
• NIST SP 800-61, Computer Security Incident Handling Guide
• NIST SP 800-86, Guide to Integrating Forensic Techniques into Incident Response

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
87
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Assess
Purpose

Determine if the controls selected for


implementation are implemented
correctly, operating as intended, and
producing the desired outcome with
respect to meeting the security and
privacy requirements for the system and
organization

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
88
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Assess
Tasks
A-1: Assessor Selection (NEW)
Select the appropriate assessor or assessment team for the type of control assessment to be conducted
A-2: Assessment Plan
Develop, review, and approve plans to assess implemented controls
A-3: Control Assessments (MOVED)
Assess the security controls in accordance with the assessment procedures defined in the security assessment plan
A-4: Assessment Reports
Prepare the assessment reports documenting the findings and recommendations from the control assessments
A-5: Remediation Actions
Conduct initial remediation actions on the controls and reassess remediated controls
A-6: Plan of Action and Milestones (MOVED)
Prepare the plan of action and milestones based on the findings and recommendations of the assessment reports

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
89
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Assess
Supporting Publications

The following NIST publications support this step:

• NIST SP 800-53A, Assessing Security and Privacy Controls in Federal Systems and Organizations: Building Effective
Security Assessment Plans

• NIST IR 8011, Automation Support for Ongoing


Assessment (Multiple Volumes)

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
90
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Authorize
Purpose

Provide accountability by requiring a


senior management official to determine if
the security and privacy risk to
organizational operations and assets,
individuals, other organizations, or the
Nation of operating a system or the use of
common controls, is acceptable

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
91
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Authorize
Tasks
R-1: Authorization Package
Assemble the authorization package and submit the package to the authorizing official for an authorization decision
R-2: Risk Analysis and Determination (REVISED)
Analyze and determine the risk from the operation or use of the system or the provision of common controls
R-3: Risk Response (NEW)
Identify and implement a preferred course of action in response to the risk determined
R-4: Authorization Decision (NEW)
Determine if the risk from the operation or use of the system or the provision or use of common controls is acceptable
R-5: Authorization Reporting
Report the authorization decision and any deficiencies in controls that represent significant security or privacy risk

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
92
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Authorize
Supporting Publications

There are no additional NIST publications to support this step

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
93
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Monitor
Purpose

Maintain an ongoing situational awareness


about the security and privacy posture of
the system and the organization in support
of risk management decisions

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
94
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Monitor
Tasks
M-1: System and Environment Changes
Monitor the system and its environment of operation for changes that impact the security and privacy posture of the system
M-2: Ongoing Assessments
Assess the controls implemented within and inherited by the system in accordance with the continuous monitoring strategy
M-3: Ongoing Risk Response
Respond to risk based on the results of ongoing monitoring activities, risk assessments, and outstanding items in plans of action and milestones
M-4: Authorization Package Updates
Update plans, assessment reports, and plans of action and milestones based on the results of the continuous monitoring process

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
95
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Step: Monitor
Tasks
M-5: Security and Privacy Reporting
Report the security status of the system (including the effectiveness of security controls employed within and inherited by the system) to
appropriate organizational officials on an ongoing basis in accordance with the organization-defined monitoring strategy
M-6: Ongoing Authorization
Review the reported security status of the system (including the effectiveness of security controls employed within and inherited by the system) on
an ongoing basis in accordance with the monitoring strategy to determine whether the risk to organizational operations, organizational assets,
individuals, other organizations, or the Nation remains acceptable
M-7: System Disposal
Implement a system decommissioning strategy which executes required actions when a system is removed from service

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
96
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
RMF Task: Monitor
Supporting Publications

The following NIST publications support this step


• NIST SP 800-137, Information Security Continuous Monitoring for Federal Information Systems and Organizations
• NIST SP 800-137A, Assessing Information Security Continuous Monitoring (ISCM) Programs: Developing an ISCM
Program Assessment
• NIST SP 800-53A, Assessing Security and Privacy Controls in Federal Systems and Organizations: Building Effective
Security Assessment Plans
• NIST IR 8011, Automation Support for Ongoing Assessment (Multiple Volumes)
• NIST IR 8212, ISCMA: An Information Security Continuous Monitoring Program Assessment
(and reference implementation to conduct ISCM Program Assessment)

Module 4: The Risk Management Framework This course is provided by the National Institute of Standards and
97
Lesson 2: RMF Steps Technology and is available free of charge at [Link]
Module 4 Summary

• Understanding what constitutes risk and how risk can be addressed and managed
using the Risk Management Framework will enable you to do your part to ensure the
integrity and trustworthiness of your organization’s systems

• The RMF is not a compliance or “one and done” process once an Authorization to
Operate is granted; managing risk is an ongoing activity that supports the
organizational mission and business functions

• The RMF is a technology-neutral methodology that can be applied to any type of


system without modification

This course is provided by the National Institute of Standards and


Module 4: The Risk Management Framework 98
Technology and is available free of charge at [Link]
Conclusion

Key Takeaways
• Managing risk for information security and privacy supports organizational mission and business
functions
• Security and privacy risk management relies on coordination between programs and resources
• Federal information security and privacy programs are driven by legislation, regulations and policy
• The Risk Management Framework (RMF) is a holistic, repeatable process to manage information
security and privacy risk; it is not a compliance or paper-work activity
• The RMF is a technology-neutral methodology that can be applied to any type of information
system without modification
• There are additional NIST resources available to support implementation of RMF steps and tasks

This course is provided by the National Institute of Standards and


RMF For Systems and Organizations Course Conclusion 99
Technology and is available free of charge at [Link]
Additional Resources and Contact Information

NIST Cybersecurity and Privacy Publications: [Link]

Risk Management Program: [Link]


Privacy Engineering Program: [Link]

NIST Cybersecurity and Privacy Mailing List:


[Link]

sec-cert@[Link]
@nistcyber
privacyeng@[Link]

This course is provided by the National Institute of Standards and


RMF Resources and Contacts 100
Technology and is available free of charge at [Link]
You have now completed the
Risk Management Framework for Systems and Organizations
Introductory Course Version 2.0
Updated August 2023

Feedback: If you have questions or comments regarding this course,


email sec-cert@[Link]

This course is provided by the National Institute of Standards and


101
Technology and is available free of charge at [Link]

You might also like