DIACAP To Risk Management Framework (RMF) Transformation - NIST

Transcription

Click to edit Master title styleDIACAP to Risk ManagementFramework (RMF) TransformationCybersecurity Policy DirectorateOctober 2012

DIACAPto RMFBackgroundClick toeditTransformationMaster titlestyle2

Transformationthe entireClick to editbenefitsMastertitleenterprisestyle3

CybersecurityDevelopmentClick to edit PolicyMastertitle style PartnershipsDoDparticipates indevelopmentof CNSS andNISTdocumentsensuring DoDequities aremetDoD leveragesCNSS and NISTpolicies andfiltersrequirementsto meet DoDneedsDoD participates in CNSS and NIST policy development as a vested stakeholderwith the goals of a more synchronized cybersecurity landscape and to protect theunique requirements of DoD Missions and warfighters4

DoD is transforming IA policies and practices to align withClickto edit Master title styleFederal government risk management policies and practices5

DoD is transforming IA policies and practices to improve ITcategorizationandMastercontrol selection,and risk managementClick to edittitle styleprocedures6

aster title7

DoDsupportsimplementationof JointTransformation GoalsClickto editMaster titlestyle8

Successful execution of RMF Transformation is enabledClickto edit Master title stylethrough three inter-related DoD CIO initiatives9

PolicyClickInterdependenciesto edit Mastertitle style10

Why are there more NIST SP 800-53 controls than the legacyClickto edit Master title styleDoD controls?11

Categorization and Security Control Selection ProcessClick to edit Master title style(Steps 1 and 2 of the Risk Management Framework)12

The Knowledge Service is an authoritative source forClickto edit Master title styleDoD Transformation policy and guidance13

ClickTransformationto edit Mastertitle styleC&ATimeline1st QuarterFY122nd QuarterFY123rd QuarterFY124th QuarterFY121st QuarterFY132nd QuarterFY1314

The Enterprise Mission Assurance Support Service (eMASS)Clickto edit Master title styleis supporting DoD’s RMF Transformation15

ContactInformationClick toedit Mastertitle styleTo become part of the DoD RMF community of interest,visit the online Knowledge Service:https://diacap.iaportal.navy.mil ** Access requires a DoD PKI certificate or an ECA PKI certificate16

DoD participates in CNSS and NIST policy development as a vested stakeholder with the goals of a more synchronized cybersecurity landscape and to protect the unique requirements of DoD Missions and warfighters DoD participates in development of CNSS and NIST documents ensuring DoD . equities are met . DoD leverages CNSS and NIST policies and .