Course objectives
After completing this course, students will be able to:
- Execute the RMF: Master all seven steps of the NIST Risk Management Framework (Prepare $\rightarrow$ Categorize $\rightarrow$ Select $\rightarrow$ Implement $\rightarrow$ Assess $\rightarrow$ Authorize $\rightarrow$ Monitor).
- Categorize Systems: Use FIPS 199 and NIST SP 800-60 to determine the impact levels (Low, Moderate, High) of information systems.
- Tailor Security Controls: Select and customize security and privacy controls from NIST SP 800-53 based on risk assessment.
- Draft Security Documentation: Create essential artifacts like the System Security Plan (SSP) and Plan of Action and Milestones (POA&M).
- Evaluate Risk Posture: Determine residual risk and provide actionable data to stakeholders for informed authorization decisions.
- Maintain Compliance: Implement automated and manual continuous monitoring strategies to ensure the system stays secure after launch.
.
Course outlines
- Domain 1: Security and Privacy Governance, Risk Management, and Compliance Program
- Principles of the CIA Triad and non-repudiation.
- Understanding federal laws (FISMA, FedRAMP) and international standards (ISO 27001, GDPR).
- Establishing roles and responsibilities (AO, ISSO, Scoping).
- Domain 2: Scope of the System
- Describing the information system purpose and boundaries.
- Categorization: Identifying information types and determining security impact levels.
- Domain 3: Selection and Approval of Framework, Security, and Privacy Controls
- Identifying baseline and inherited (common) controls.
- Tailoring: Applying overlays and selecting compensating controls.
- Developing a continuous monitoring strategy.
- Domain 4: Implementation of Security and Privacy Controls
- Aligning implementation with organizational and regulatory expectations.
- Documenting the "as-implemented" state of technical, management, and operational controls.
- Domain 5: Assessment/Audit of Security and Privacy Controls
- Preparing the Security Assessment Plan (SAP).
- Conducting tests, interviews, and examinations.
- Analyzing results and identifying vulnerabilities in the Security Assessment Report (SAR).
- Domain 6: System Compliance
- Reviewing the "Security Authorization Package" (SSP, SAR, and POA&M).
- Authorization Decision: Understanding ATO, ATU, and Denial of Authorization.
- Domain 7: Compliance Maintenance
- Change Management: Assessing the security impact of system changes.
- Performing ongoing assessments and reporting.
- System Decommissioning: Securely removing systems from operation