Instructor-Led Cybersecurity Training

Risk Management Framework for DoD with STIG Introduction

4 days

This Risk Management Framework (RMF) for DoD/IC Implementation course focuses on NIST Standards as prescribed by the DoD CIO Office. NIST provides a mechanism to inform risk decisions and improve cybersecurity. The seven-step life cycle process is explored through presentations and hands-on exercises as attendees learn the steps involved to prepare for RMF, categorize information systems, select security controls, implement controls, assess controls, authorize information systems, and monitor the security controls. The one-day STIG Introduction is also included in this 4-day course.

Course Outline

Chapter 1: Introduction to RMF

  • Module A: RMF overview
  • Module B: Cybersecurity policy regulations and framework
  • Module C: RMF roles and responsibilities

Chapter 2: Risk analysis

  • Module A: Risk management
  • Module B: Risk assessment and the RMF process

Chapter 3: The RMF process

  • Module A: Step 0—Prepare
  • Module B: Step 1—Categorize
  • Module C: Step 2—Select
  • Module D: Step 3—Implement
  • Module E: Step 4—Assess
  • Module F: Step 5—Authorize
  • Module G: Step 6—Monitor

Chapter 4: DoD RMF–specific areas

  • DoD CYBER.MIL site and resources
  • Continuous Monitoring and Risk Scoring (CMRS)
  • RMF Knowledge Service (RMFKS)
  • Joint SAP Implementation Guide (JSIG) for RMF
  • ICD-503
  • Service updates and adjustments to RMF for DoD IT

Appendices

  • A: Supplemental Reference
  • B: RMF Review and Steps Checklists
  • C: Acronym Reference

STIG Introduction – one-day course

Some STIG 101 topics include:

  • STIG Overview
  • Authoritative Documents
  • STIG Content
  • SCAP Compliance Checker (SCC)
  • Evaluate-STIG
  • STIG Viewer
  • How-to Resources

Back to top