Building a DoD Security Package – RMF in Practice
The Program
The Building a DoD Security Package training program provides students with a comprehensive working knowledge of RMF, including DoD policies and procedures, along with the practical guidance needed to successfully implement them.
Discussion is centered on RMF for DoD IT policies, roles and responsibilities, along with key publications from DoD (DoDI 8500.01, 8510.01), NIST (SP 800-53, 800-37), and CNSS (Instruction 1253).
Program Structure
Part 1: Fundamentals (Day 1)
FoundationProvides a high-level view of the RMF for DoD IT lifecycle, including security authorization (certification and accreditation) and the RMF documentation package.
- Policy Background (FISMA, OMB)
- Roles & Responsibilities
- RMF Lifecycle Overview
- Controls & Assessment Procedures
Part 2: In-Depth (Days 2-4)
ImplementationExpands on topics at a level of detail that enables practitioners to immediately apply training to daily work. NIST SP 800-53 Security Controls and CNSS 1253 enhancements are covered in detail.
Step 1: Categorize
Define system boundary, conduct basic risk assessment, and register the system.
Step 2: Select
Select and tailor control baselines (overlays) and plan for continuous monitoring.
Step 3: Implement
Document control implementation, utilize STIGs, and leverage automated tools.
Step 4: Assess
Prepare for assessment, identify the SCA team, and execute assessment procedures.
Step 5: Authorize
Compile the Security Authorization Package and understand authorization decisions (ATO, IATT, DATO).
Step 6: Monitor
ISCM strategy considerations, automated tools, and system decommissioning.
Who Should Attend?
This program is suitable for DoD employees and contractors, as well as their supporting vendors and service providers.
- Full 4-Day Program: Recommended for most students/practitioners.
- 1-Day Fundamentals: An option for Managers and others who need only high-level knowledge of RMF.
Delivery Methods
Online Personal Classroom™
Offered on a regularly-scheduled basis using our live, instructor-led technology.
Classroom Locations
Available in several classroom locations nationwide.
Request Training
Flexible Scheduling
Contact us for the latest class schedule.
Payment Options
We accept SF-182s and GPC.