skip to main content
OSTI.GOV title logo U.S. Department of Energy
Office of Scientific and Technical Information

Title: Selecting RMF Controls for National Security Systems

Technical Report ·
DOI:https://doi.org/10.2172/1212270· OSTI ID:1212270
 [1]
  1. Sandia National Lab. (SNL-NM), Albuquerque, NM (United States)

In 2014, the United States Department of Defense started tra nsitioning the way it performs risk management and accreditation of informatio n systems to a process entitled Risk Management Framework for DoD Information Technology or RMF for DoD IT. There are many more security and privacy contro ls (and control enhancements) from which to select in RMF, than there w ere in the previous Information Assurance process. This report is an attempt t o clarify the way security controls and enhancements are selected. After a brief overview and comparison of RMF for DoD I T with the previously used process, this report looks at the determination of systems as National Security Systems (NSS). Once deemed to be an NSS, this report addr esses the categorization of the information system with respect to impact level s of the various security objectives and the selection of an initial baseline o f controls. Next, the report describes tailoring the controls through the use of overl ays and scoping considerations. Finally, the report discusses organizatio n-defined values for tuning the security controls to the needs of the information system.

Research Organization:
Sandia National Lab. (SNL-NM), Albuquerque, NM (United States)
Sponsoring Organization:
USDOE Office of Defense Programs (DP)
DOE Contract Number:
AC04-94AL85000
OSTI ID:
1212270
Report Number(s):
SAND2015-6770; 598953
Country of Publication:
United States
Language:
English

Similar Records

Audit Report on "Protection of the Department of Energy's Unclassified Sensitive Electronic Information"
Technical Report · Sat Aug 01 00:00:00 EDT 2009 · OSTI ID:1212270

Facility Cybersecurity Framework Best Practices
Technical Report · Sun Aug 30 00:00:00 EDT 2020 · OSTI ID:1212270

Evaluation Report on "The Department's Unclassified Cyber Security Program"
Technical Report · Thu Oct 01 00:00:00 EDT 2009 · OSTI ID:1212270

Related Subjects