Module 22 · Advanced · ⌛ 60 min · 🏆 +350 XP

RMF Lifecycle — CGRC Deep Dive

The NIST Risk Management Framework is the gold standard for federal information systems — and increasingly for regulated industries. Master all six steps, from categorization to continuous monitoring, and understand how to navigate Authorization to Operate (ATO) decisions.

NIST RMFATOFIPS 199FIPS 200FedRAMPContinuous Monitoring

Learning Objectives

  • Execute all six RMF steps: Categorize → Select → Implement → Assess → Authorize → Monitor.
  • Apply FIPS 199 to categorize information and systems by confidentiality, integrity, and availability.
  • Explain the Authorization to Operate (ATO) decision and the role of the Authorizing Official (AO).
  • Design a continuous monitoring strategy for an authorized system.
  • Explain FedRAMP and how it extends the RMF for cloud services.
  • Write a Plan of Action and Milestones (POA&M) for an RMF assessment finding.

Lecture

1 · What is the RMF?

The NIST Risk Management Framework (NIST SP 800-37 Rev. 2) is the mandatory framework for securing US federal information systems. It provides a structured, risk-based approach to integrating security and risk management activities into the system development lifecycle. Increasingly, regulated industries (healthcare, defense contractors, financial institutions) adopt RMF principles as their primary security governance model.

2 · The Six RMF Steps

Step 1 — Categorize: Determine system impact level using FIPS 199 (Low, Moderate, High). Step 2 — Select: Choose a baseline control set from NIST 800-53 (tailored for the impact level). Step 3 — Implement: Deploy the selected controls. Step 4 — Assess: Independent assessment of control design and operating effectiveness. Step 5 — Authorize: Authorizing Official (AO) makes an ATO risk acceptance decision. Step 6 — Monitor: Ongoing monitoring of controls throughout the system lifecycle.

3 · The ATO Decision

The Authorizing Official (AO) — a senior federal executive — accepts the residual risk of operating the system. The ATO decision is based on the Security Assessment Report (SAR) and the System Security Plan (SSP). If the AO determines residual risk is unacceptable, the ATO is denied — the system cannot operate until risks are addressed.

Key Insight

RMF insight: The ATO is not a rubber stamp — it is a formal risk acceptance decision by a named individual with personal accountability. The AO signs their name to the statement that residual risk is acceptable. This accountability structure is central to RMF governance.

Theory Deep Dive

📋 FIPS 199 — Information Categorization

FIPS 199 provides the security categorization standard for federal information and information systems. Systems are categorized by their potential impact if a security breach occurs:

Impact LevelConfidentialityIntegrityAvailabilityControl Baseline
LowLimited adverse effectLimited adverse effectLimited adverse effectNIST 800-53 Low Baseline (~100 controls)
ModerateSerious adverse effectSerious adverse effectSerious adverse effectNIST 800-53 Moderate Baseline (~330 controls)
HighSevere/catastrophic effectSevere/catastrophic effectSevere/catastrophic effectNIST 800-53 High Baseline (~420+ controls)

The system overall impact level is the high-water mark — if any security objective is High, the system is High impact overall.

📄 Key RMF Documents

System Security Plan (SSP)

The master document describing the system, its boundaries, the selected controls, and how each is implemented. The SSP is the primary input to the assessment. It must be accurate, complete, and current before assessment begins.

Security Assessment Plan (SAP)

The plan developed by the assessor describing what will be tested, how, and the test methodology. The SAP is reviewed and approved before fieldwork begins.

Security Assessment Report (SAR)

The assessor's findings document. States each control's status: Satisfied, Other Than Satisfied (OTS), or Not Applicable. OTS findings include recommendations. The SAR drives the ATO decision.

Plan of Action and Milestones (POA&M)

Tracks all open findings. For each POA&M item: finding description, risk level, responsible official, planned remediation actions, and target completion dates. The POA&M is the living risk register for the authorized system.

Authorization Package

The complete set of documents submitted to the AO: SSP, SAR, POA&M, and Risk Assessment. The AO uses these documents to make the ATO decision.

Continuous Monitoring Strategy

Describes how the system will be monitored post-authorization. Includes: ongoing control testing cadence, security status reporting frequency, significant change process, and conditions requiring re-authorization.

☁️ FedRAMP — RMF for Cloud Services

FedRAMP (Federal Risk and Authorization Management Program) applies the RMF to cloud service providers (CSPs) seeking to serve federal agencies. Key features:

1
Do Once, Use Many

A CSP obtains a single FedRAMP authorization. That authorization can be reused by any federal agency — eliminating the need for each agency to independently assess the cloud service.

2
Three Authorization Paths

Agency Authorization: A specific federal agency sponsors and authorizes the CSP. JAB Authorization: The Joint Authorization Board (DHS, DOD, GSA) reviews and authorizes the highest-reuse services. FedRAMP Ready: Pre-authorization designation indicating the CSP is ready for authorization.

3
Impact Levels

FedRAMP Low: non-sensitive federal information. FedRAMP Moderate: CUI (Controlled Unclassified Information) — applies to ~80% of federal requirements. FedRAMP High: law enforcement, emergency services data.

4
Third-Party Assessment Organizations (3PAOs)

FedRAMP assessments must be conducted by accredited 3PAOs — independent organizations vetted by FedRAMP to conduct cloud service assessments. Not just any auditor can conduct FedRAMP assessments.

🧪 Lab — NIST RMF Authorization Package

You are the Information System Security Officer (ISSO) leading a federal agency's medical device management system through the NIST Risk Management Framework (RMF). Work through each RMF step — from FIPS 199 categorization through ATO documentation and continuous monitoring design.

Real-World Scenario

Mission Quiz

Mission Complete

← Module 21 Next: Module 23 →