DoD Risk Management Framework (RMF) Manual, October 2015 Version
Sold Out / Out of Stock
DoD Risk Management Framework (RMF) Manual, October 2015 Version
This October 2015 instructional manual provides an introduction to the new DoD RMF process for securing military systems (DoDI 8500.01 and DoDI 8510.01). It includes samples of key documents (Security Plan, Security Assessment Report, POA&M, Information Security Continuous Monitoring Plan). The DoD RMF process is based the key concepts of mission- and risk-based, cost-effective, and enterprise information system security. Uniquely this new process was developed with the progressive visions that future information systems will have: Automated presentation of security status; Proactive and preventative configuration control to prevent unauthorized changes; Automated updating and patching; Near-real-time awareness from an enterprise level; and, Continuous security authorization. This manual was written specifically based on all the above instructions and related NIST Special Publications with the purpose of providing individuals with the knowledge to understand the DoD RMF process and implement the same for their systems. This manual's author is a certified (ISC)2 Instructor, who has taught CISSP, ISSEP, and CAP certification review courses for over 8 years internationally. Additionally, he has lead or supported over 300 military, civilian and Federal system security assessments over the past 20 years. Using his experience, he has augmented the course with successful strategies and real-world samples of key documents (i.e., Security Plan (SP), Security Assessment Reports (SAR), Plan of Action and Milestones (POA&M), Overlays, and Information Security Continuous Monitoring Plans (ISCMP)). These help to ensure this manual supports the all the personnel at the DoD Component levels from the Chief Information Officer (CIO) and Authorizing Official (AO) to the Information System Owner (ISO) and User Representative (UR) in understanding the process and their responsibilities in implementing the DoD RMF process. Covers are in color and pages are black and white.