• Skip to main content
  • Skip to primary sidebar

ConvoCourses

Cyber Security Compliance and IT Jobs

  • Cyber Security Training
  • about me.
  • Information Assurance Jobs

diarmf diacap

January 17, 2014 by Bruce Brown Leave a Comment

Diarmf diacap

diarmf assessment authorization
diarmf assessment authorization

We’ve gone from DoD Information Technology Security Certification and Accreditation Process (DITSCAP) to DoD Information Assurance Certification And Accreditation Process (DIACAP) to DoD Information Assurance Risk Management Framework (DIARMF).  

DIACAP transition is mainly about going from certification and accreditation (C&A) to a Risk Management Framework process. The DIARMF is a Risk Manager Framework that comes from National Institute of Standards and Technology (NIST) NIST Special Publication 800-37, “Guide for Applying the Risk Management Framework to Federal Information Systems”.  

The NIST standards have transitioned from certification and accreditation to risk management framework.  The NIST has replaced its C&A documents, NIST SP 800-47, Security Guide for Interconnecting Information Technology Systems, and  NIST SP 800-37, Guide for the Security Certification and Accreditation of Federal Information Systems.   

The current NIST SP 800-37, Rev 1 includes a risk management process.  Risk management is more in line with international standards, ISO 31000:2009, Risk management & ISO/IEC 31010:2009, Risk management

Some of the differences I have noticed have been:

  • More Flexible & Tailorable Boundaries.  Risk management framework is more flexible & tailorable on security boundaries.  RMF includes things like “dynamic subsystems” which allow you to do things like create a temporary subsystem and attach it to an existing system in the middle of its system life-cycle.  I have seen that done with DIACAP but typically organizations had to make up a their own detailed process to manage the risk.  Since DIACAP did not have that kind of flexibility so you ended up with 100’s of variations of DIACAP.  The NAVY, Army, Air Force each had their own version of DIACAP and then even units within those branches had their own.  For example, Space Command might have a different process than Euro Command and they could be in the same branch.

  • Focus of Security Factors.  Risk management framework looks at risk according to the system’s confidentiality, integrity and availability separately and as a whole.

  • More Quantitative.  With more controls and a focus on risk, risk management framework can be more quantitative as well as qualitative.

  • Tailorable Controls.  risk management framework is built to make the controls fit the actual system.  This probably one of DIACAPs biggest draw backs.  It has a generic set of controls that are not applicable in some cases and lacking areas of security.

  • DIARMF is based on NIST standards (NIST 800-37, rev 1)

  • DIACAP is based on DoD 8500/8510

Filed Under: DIACAP, DIARMF Tagged With: DIACAP, DIARMF, diarmf diacap, DITSCAP

Reader Interactions

Leave a Reply Cancel reply

You must be logged in to post a comment.

Social connect:

Primary Sidebar

search


This is a breakdown of each of the NIST 800-53 security control families and how they relate to each step in the NIST 800-37 risk management framework process.

also available on Amazon!

View Book


This is a breakdown of each of the NIST 800-53 security control families and how they relate to each step in the NIST 800-37 risk management framework process.

also available on Amazon!

View Book


This book is an overview of how the NIST SP 800-37 risk management framework works from the perspective of an information system security officer (ISSO).

also available on Amazon!

View Book

NIST RMF 800-37 templates
Free 800-37 templates

The NIST 800 Template download contains a .doc file template and xls templates for POAMs, Federal, State, cloud based and a legacy template as well as resources where you can find more on NIST 800-37 documents for your use.

View Book

Learn to Make 6 Figures in CyberSecurity

RMF ISSO Foundations Training
RMF ISSO Foundations Training

RMF ISSO Foundations

I was an Information System Security Officer (ISSO) doing Risk Management Framework (NIST SP 800-37) for over a decade. I am a Cybersecurity veteran and I can explain (in plain English) what you DO in the Risk Management Framework process as an ISSO.

View Course

NIST SP 800-37 Presentation
NIST SP 800-37 Presentation

View Course

login

  • Register
  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Recent Posts

  • Convocourses Podcast: Plan of Action and Milestone
  • Start with These IT Certifications (Part 1)
  • How to Tailor Security Controls in NIST 800
  • #cybersecurityjobs are recession proof
  • What IT Certifications for Information Security (part 2) (8140)

Meta

  • Register
  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Recent Comments

  • http://Www.Finance.Ipt.Pw/ on SRG/STIG Applicability Guide and Collection Tool Update
  • Elsa7 on ConvoCourses podcast: Cyber Security day to day activity
  • Tony on STIG Update – DISA has released the Microsoft SQL Server 2016 STIG Version 1
  • horloge on SCAP Compliance Checker SCC)
  • 218 Information assurance Success Criteria – ITSECURITYSURVIVAL.COM on Information Assurance Vulnerability Alert

Tags

8140 8570 ArcSight c&a CISSP convocourses cyber cybersecurity cyber security DIACAP DIARMF diarmf - implement disa DISA STIG dodd 8140 dodd 8140 cyberspace workforce IA implement implementation info assurance information assurance information security ISSO IT it jobs it jobs in usa job jobs Linux mcafee network nist nist risk management framework nist risk management framework 800-37 podcast risk risk assessment risk management risk management framework rmf security STIG stigs unix windows


This is a breakdown of each of the NIST 800-53 security control families and how they relate to each step in the NIST 800-37 risk management framework process.

also available on Amazon!

View Book

Copyright © 2023 · Author Pro on Genesis Framework · WordPress · Log in