RMF in the Department of Defense (DoD)DoD components include the Military Departments as well as numerous agencies within the Office of the Secretary of Defense (OSD) and the Joint Chiefs of Staff (JCS) (see list below). Since 2006-7, DoD components have been utilizing the DoD Information Assurance Certification and Accreditation Process (DIACAP) as the standard process for assessment and authorization of information systems. DIACAP is a five-step life cycle process that includes:
The DIACAP roles, responsibilities, and life cycle process are specified in DoD Instruction (DoDI) 8510.01. DIACAP focuses on compliance with a standard set of Information Assurance (IA) Controls (security requirements) that are documented in DoDI 8500.2. As an active participant in the Joint Task Force Transformation Initiative, DoD is committed to a transformation from DIACAP to RMF. It has been suggested they will begin using the term DoD Information Assurance Risk Management Framework (DIARMF) to refer to the RMF as implemented within DoD. A plan and time line for the “DIACAP to RMF transformation”, including publication of revised DoD Instructions, are under development within DoD, but have not been released. In the meantime, DoD components will continue to actively practice the “legacy” DIACAP process. RMF Resource Center is addressing both present and future DoD needs. Our affiliated DIACAP Resource Center continues to offer a comprehensive DIACAP training program as well as DIACAP consulting services. In addition, we highly recommend DoD personnel begin educating themselves on RMF in order to effectively manage the upcoming transition. Our RMF Training program is therefore open to DoD employees and contractors. DoD Components
|