A self-paced course on the working practice of the Risk Management Framework as it is applied to United States federal and Department of Defense systems. Six modules cover the RMF’s purpose and roles, categorising and scoping a system, selecting and tailoring controls from NIST SP 800-53, implementing and documenting controls in a System Security Plan, assessment and the Plan of Action and Milestones, and earning and sustaining the Authorisation to Operate through continuous monitoring.
Written for information system security officers, security control assessors, engineers and programme staff who are responsible for getting a system authorised and keeping it that way. Tech Skills Library is independent and issues no certification, credential or licence.