Instructor-Led Cybersecurity Training
Risk Management Framework for DoD with STIG Introduction
4 days
This Risk Management Framework (RMF) for DoD/IC Implementation course focuses on NIST Standards as prescribed by the DoD CIO Office. NIST provides a mechanism to inform risk decisions and improve cybersecurity. The seven-step life cycle process is explored through presentations and hands-on exercises as attendees learn the steps involved to prepare for RMF, categorize information systems, select security controls, implement controls, assess controls, authorize information systems, and monitor the security controls. The one-day STIG Introduction is also included in this 4-day course.
Course Outline
Chapter 1: Introduction to RMF
- Module A: RMF overview
- Module B: Cybersecurity policy regulations and framework
- Module C: RMF roles and responsibilities
Chapter 2: Risk analysis
- Module A: Risk management
- Module B: Risk assessment and the RMF process
Chapter 3: The RMF process
- Module A: Step 0—Prepare
- Module B: Step 1—Categorize
- Module C: Step 2—Select
- Module D: Step 3—Implement
- Module E: Step 4—Assess
- Module F: Step 5—Authorize
- Module G: Step 6—Monitor
Chapter 4: DoD RMF–specific areas
- DoD CYBER.MIL site and resources
- Continuous Monitoring and Risk Scoring (CMRS)
- RMF Knowledge Service (RMFKS)
- Joint SAP Implementation Guide (JSIG) for RMF
- ICD-503
- Service updates and adjustments to RMF for DoD IT
Appendices
- A: Supplemental Reference
- B: RMF Review and Steps Checklists
- C: Acronym Reference
STIG Introduction – one-day course
Some STIG 101 topics include:
- STIG Overview
- Authoritative Documents
- STIG Content
- SCAP Compliance Checker (SCC)
- Evaluate-STIG
- STIG Viewer
- How-to Resources
