
These are the downloadable PowerPoint Slides I used for this course.
Explore the risk management framework step one, system categorization, using information types and the confidentiality, integrity, and availability objectives to assess impacts and develop provisional categorizations.
Categorize a system by applying confidentiality high, integrity moderate, and availability low impact values, then apply overlays in RMF step 1 to guide protection decisions.
Summarizes RMF steps 1–3: categorize information and systems, determine impact levels, select controls from a traceability matrix, then implement with technical, physical, or administrative controls.
Continuous monitoring provides ongoing assessment, reporting, and authorization to maintain situational awareness of vulnerabilities for risk decisions; apply control frequencies, verify encryption and antivirus, and recategorize when the environment changes.
This scenario is a simple example of me purchasing a new computer for my parents to demonstrate the practical application and simplicity of the Risk Management Framework (RMF). The aim is to explain RMF in a non-technical manner.
Whether we are planning the security for a network that supports a multi-million dollar corporation or deciding how to secure the new home we just purchased, the fundamental security concepts and principles are very similar. Even though our home example is typically not as structured (unless you are really meticulous) as a business model, the fundamental approach to security has not changed since the first caveman discovered the value of a wooden club and another caveman wanted it!
Throughout the scenario, we will cover the concepts of Risk Management as well as each of the six RMF Steps:
Categorize the risks associated with the information and the system.
Select the appropriate security controls to mitigate risks to an acceptable level.
Implement the selected controls.
Assess the implemented controls.
Authorize the system for use.
Continuously monitor the controls to ensure they effectively mitigate risks.
So, forget anything you may have already learned about RMF, NIST 800-53, and most of the other technical jargon, and join me in this adventure of buying a new computer for my parents!