Critique Popular Risk Assessment and Management Procedures

profileZEKEB
RiskManagementFrameworkandImplementationChallenges.pdf

Northeast Business & Economics Association Proceedings, 2017 11

Risk Management Framework (RMF) and the Implementation

Challenges

Lloyd Ahamefule Amaghionyeodiwe, PhD

Department of Accounting and Finance

York College

City University of New York (CUNY)

94-20 Guy R. Brewer Boulevard

Jamaica, New York USA 11451

(718) 262 2517

[email protected]

ABSTRACT

Recently, there has been a shift in the risk management

process of the federal government and its agencies. The shift

is the transition from the Information Assurance

Certification and Accreditation (C&A) to the National

Institute of Standards and Technology (NIST) Risk

Management Framework (RMF). This was also a shift from

a compliance-based approach to a risk-managed approach to

cybersecurity. However, as with any major changes, this

shift does not come without some resistance and

implementation challenges. This paper examines the new

risk management framework (RMF) and the implementation

challenges. Among the observed implementations challenges

are those related to solid governance as well as a culture that

promotes communication, trust, thinking, and informed risk

taking. Other challenges include the lack of top management

support and the need for Cybersecurity proficiency and

trainings. Based on these, this study suggests that the need

for security personnel to be adequately trained and educated

in the use of the RMF. Also, organizations should have an

avenue where they can share their various experiences about

the applicability and usage of the security mitigations (and

security controls). This will help improve the understanding

of how to use and what to expect from the implementation of

the RMF.

Keywords Risk management framework, cybersecurity, information

assurance

1 INTRODUCTION

Risk Management Framework has been used by security

practitioners in various ways based on the context and

circumstances of where it is applied. These practitioners are

those engaged in applying any of the disciplines referred to

as information security, information systems security,

computer security, and cyber security, to systems

engineering, business process engineering, strategic

planning, program planning, or operations. In the past, the

Department of defense (DoD) has executed various

frameworks to oversee information assurance (IA) measures

with an end goal of securing their information systems. One

of such frameworks is the DoD’s Information Assurance

Certification and Accreditation Process (DIACAP) which

was used as the accepted framework and helped reduced

system integration difficulties within the DoD. This

notwithstanding, there has been reason to expand its

adoption and usage to incorporate other Federal government

agencies while concentrating on the management of

organizational risk. As a result of this, there has been a move

from DIACAP to Risk Management Framework (RMF),

which was provided by NIST and CNSS. And in this regard,

the DoD contributes to the development process, and they

principally influence and control NIST/CNSS approaches to

address DoD needs.

In addition to allowing several officials from within or

outside their primary organization to share responsibility for

authorizing and accepting system-related security risks, the

shift to RMF changes the Certification & Authorization

(C&A) process to an Assessment & Authorization (A&A)

process. RMF shifts away from a compliance-based

approach to a risk-managed approach to cybersecurity.

Unlike previous government approaches for addressing

cybersecurity risk, the RMF provides a legitimate avenue to

accept the risk from addressing security needs differently

than initially expected so long as it is done in a thoughtful

manner. The reduced funding available to federal agencies

reinforces the need for an informed risk-based approach

such as what is promoted via the RMF. The shift to the RMF

also redefines the manner in which the security and privacy

controls in NIST’s 800-53 Publication as well as the role

descriptions and responsibilities are ordered and defined.

The RMF models are deliberately broad-based with the

defined means of evaluating risk and using appropriate risk

mitigation approaches provided by the supporting NIST

security standards and guidelines. RMF implementation is in

varying stages of maturity throughout the US Government

and as leadership of Federal Departments and Agencies

changes, their commitment to implement the RMF as

intended has fluctuated and the interpretation of what is

needed has at times changed. It is as a result of this that this

study intends to investigate the challenges associated with

implementing the RMF by the different agencies. The study

is divided into four sections.

Northeast Business & Economics Association Proceedings, 2017 12

2 DoD’s RISK MANAGEMENT FRAMEWORK

(RMF)

The background of the DOD migrating from DIACAP to

Risk Management Framework (RMF) began in an effort to

consolidate and standardize information risk management

for the federal government. The RMF is the “common

information security framework” for federal government and

its information systems. RMF have the main goals of

improving information security, fortifying the risk

management processes, and boosting mutuality among

federal agencies. According to NIST (2010) the Risk

Management Framework was described as a structured, yet

flexible approach for managing the portion of risk resulting

from the incorporation of information systems into the

mission and business processes of the organization. The

approach includes a six-step iterative process as shown in

Figure 1.

Source: Adopted from Fleener, Mayor and Zou (2015).

Figure 1. DoD RMF Six Step Process.

With the transition, the federal government intends to shift

from a compliance-based approach to a risk-managed

approach to cyber security. The major reasons for this

advancement include constrained spending plans, including

the need to "accomplish more with less", and also the

increasing occurrence of dynamic and sophisticated threats.

This is also based on the believe that security is not an end in

and of itself, rather security enables an entity to fulfill its

mission despite ongoing and successful attacks.

The RMF implementation is in varying stages of maturity

throughout the US Government. And leadership changes in

these federal department and agencies have led to variations

in the implementation of the RMF as well as in the

interpretation of what is needed. According to the Defense

Information Systems Agency, (2012), this shift will

standardize the language used for information assurance

across the entire federal government.

DIACAP was largely a static process with time driven

milestones to include triennial reaccreditations, annual

security reviews and few requirements for continuous

monitoring of the security posture of a system. RMF is

placing a significant emphasis on real time security. The

continuous monitoring of the security posture of a system, to

include reporting metrics and compliance to a higher agency,

is one of the cornerstones for the transition to RMF.

3 CHALLENGES IN IMPLEMENTING THE RISK

MANAGEMENT FRAMEWORK In implementing the RMF, there have been some challenges

towards viewing the RMF as an adaptable process. Some of

the reasons for these challenges include that of not being

familiar about the flexibility that is inherent in it. There is

also restricted engineering experience among many security

practitioners and lack of familiarity with the concept of a

trade space, and the pressure to remain within one’s silo due

to the political ramifications of convergence of security with

other domains.

Being a new introduction, it requires solid governance as

well as a culture that promotes communication, trust,

thinking, and informed risk taking, for it to be efficiently

implemented. But the implementation decision using RMF

have some apparent problems, which is that the RMF

embeds risk assessments in each step but the discussion of

risk in most steps is so restrained that many do not recognize

what risk-related activities need to occur. Across the users of

RMF, many of them see it and practice it as just security

controls, security testing and evaluation, and continuous

monitoring. While these concepts have a role in the RMF, in

and of themselves they cannot and will not lead to risk

management. Many officials fail to perform the necessary

risk framing activities that inform the execution of RMF

activities. This can be attributed to two main reasons which

include risk aversion and unwillingness to articulate in

writing their risk tolerance, that is, the level and nature of the

risk they are willing to accept. In this kind of situation, there

is the need to adopt a policy that assigns roles and

responsibilities for framing, assessing, and managing cyber

risks in these organizations. In these organizations, cyber

risk management must support enterprise risk management,

which includes managing financial, operational (or mission),

and existential risks. Also, because of the way the transition

was done, which many perceived this as being rushed. Thus,

they felt inhibited in their ability to meet the timeframes

mandated.

Another challenge is that of organizational change which

many see as is a precondition for developing how the RMF

should be implemented. This is also related to the fear of the

unknown given the transition to RMF and this comes with

lots of risk for the organizations. Changing the culture to

RMF comes with lots of expectation especially as it relates

training and adoption of these changes. Thus, many in the

industry are more enthusiastic and eager to embrace the way

the RMF was intended to be used while others become more

entrenched in their views that the process is cumbersome,

bulky and ultimately a threat to security. For instance,

several approaches for implementing the RMF have been

used by numerous organizations and each of them offers

divergent experiences. These experiences are more related to

the need for more skilled staff, more resources, more time to

transition and more training. By implication, these needs are

Northeast Business & Economics Association Proceedings, 2017 13

less concerned with the RMF itself but more to do with the

effects over time of underinvestment in staff capabilities, as

well as the inherent complexity of cyber security.

There are also some technical challenges especially as it

relates to the use of baselines as the minimum and basis for

compliance. Many of these security baselines often fail to

articulate the operational or technical environment, thus,

implementing baselines without fitting it to organization’s

need sets up users for an unrealistic or unnecessary set of

controls. Also, many of the controls are based on various

assumptions (like assumes a physical infrastructure, assumes

a high degree of persistence of data, or assumes that the

organization is a government entity). But these assumptions

are not articulated or captured in any knowledge base.

Consequently, users lack the information and tools that are

needed to support making informed risk management

decisions.

Furthermore, there is the use of automated tools most of

which tend to be compliance focused tools. And determining

whether solutions implemented are compliant is an element

of monitoring, but should not be the sole reason for

monitoring. With respect to the automated tools and

controls, many people consider controls as-is are technical

specifications while others see the potential to use security

controls as an input into the requirements management

process. Hence, they believe that the number of controls and

the relative merits and applicability of the controls is too

much for any human being to keep in his/her head.

Therefore, there is the need for automated tools that are

well-maintained, shared database/repository, with relevant

metadata regarding the controls, are necessary to aid security

practitioners in making informed decisions regarding the

effectiveness, cost, and relevance of the various controls in

different environments and different threat settings. Without

these tools it become cumbersome and more difficult for the

security professionals to keep pace with the changing cyber

threat environment and associated security mitigations.

Many of the users also fail to recognize cybersecurity as a

“design consideration” and they forgot that to achieve

positive acquisition outcomes, there is the need to

consistently “bake in” Cybersecurity into our acquisition

programs. This is made complicated by the integration of

multiple complex processes (RMF & DoD Acquisition

Lifecycle) into the Cybersecurity requirements for this

system. Other RMF implementation challenges are that

program Managers view of Cybersecurity as just another

unfunded requirement and the lack of a common

understanding and definition of Cybersecurity given that the

effective Cybersecurity on DoD acquisition programs is

much more than just the RMF. There is also lack of top

management support and the need for Cybersecurity

expertise and training. This will help in enhancing the

number of the Cybersecurity workforce.

4 CONCLUSION

Given the importance of risk management in an

organization, and given some of the challenges in

implementing the RMF, it important that security personnel

should be adequately trained and educated in the use of the

RMF. More skilled security personnel should also be

involved. In terms of automation, there is the need for an

automation that will allow for practitioners to mine, analyze

and add to this knowledge base in analysis of possible

mitigations (and associated security controls) in a timely

manner. Some combination of databases and automated

tools may also help decisions makers in determining their

risk tolerance and risk thresholds as well as selection of risk

responses. Organizations should have an avenue where they

can share their various experiences about the applicability

and usage of the security mitigations (and security controls)

as well as contribute and expand the knowledge base. This

will help improve the understanding of how to use and what

to expect from the implementation of the RMF. Transiting

from one system to another is always a difficult one as such

there is a need for a mentality change through better training

for those responsible for making cyber security risk

management decisions and for the security professionals

who support them. In line with this there is a need for a risk

executive function that is responsible for making risk

decision trade-offs. Additionally, such a risk executive

function needs to be appropriately empowered to make the

necessary risk management trade-off decisions. In all, the

RMF provides a structured, yet flexible approach for

managing risk. When executed as intended, risk based

decision-making at every step of the process allows for the

options of acceptance, avoidance, transfer, sharing and

mitigation of risk. Effective risk management must be done

in context of the strategic, operational and tactical

imperatives facing an enterprise. Also, cyber security should

not be seen as an end in of itself but rather a means to help

achieve a mission. As such it should be viewed as an

integrated set of processes and activities that contribute to

the accomplishment of organizational and mission activities.

Achieving the full benefits of the Risk Management

Framework requires significant changes on the political,

cultural and technical fronts.

REFERENCES

David, R., and Wendy W. 2012 “IA OM as an Enterprise

Risk Management Metric”, Risk Management - Current

Issues and Challenges. Retrieved from:

http://www.intechopen.com/books/risk-management-

current-issues-and-challenges/ia-om-as-an-enterprise-risk-

management-metric

Department of Defense (DoD) 2014. “Risk Management

Framework (RMF) for DoD Information Technology (IT)

Instruction 8510.01.” March 12. Retrieved on February 21,

2016 from

http://www.dtic.mil/whs/directives/corres/pdf/851001_2014.

pdf

Northeast Business & Economics Association Proceedings, 2017 14

Defense Information Systems Agency 2012. “DIACAP to

Risk Management Framework (RMF) Transformation”.

Washington, DC.

Fabius, Jennifer and Richard Graubart 2014. “Beyond

Compliance – Addressing the Political, Cultural and

Technical Dimensions of Applying the Risk Management

Framework”. Retrieved on February 21, 2016 from

https://www.mitre.org/sites/default/files/publications/pr-14-

3551-beyond-compliance-applying-risk-management-

framework.pdf

Fleener, Graham., Marco Mayor and Cliff Zou 2015. “Risk

Management Framework (RMF) Transition Impacts in

Training Simulation Systems”. Interservice/Industry

Training, Simulation, and Education Conference (I/ITSEC)

Paper No. 15009. Retrieved from:

http://www.cs.ucf.edu/~czou/research/Graham-IITSEC-

2015.pdf

Gantz, Stephen D., and Daniel R. Philpott. 2013. “FISMA

and the Risk Management Framework the New Practice of

Federal Cyber Security”. Waltham, MA: Elsevier/Syngress.

Health Information Trust Alliance 2013. “Risk Management

Frameworks”. March. Retrieved on February 21, 2016 from

https://hitrustalliance.net/content/uploads/2014/05/HITRUS

T-RMF-Whitepaper2.pdf

Maximo, Danny 2013. “Risk Management Framework

(RMF) and the Future of DoD Information Assurance (IA)”.

September 24th. Retrieved on February 21, 2016 from

http://www.seguetech.com/blog/2013/09/24/risk-

management-framework-future-dod-information-assurance

National Institute of Standards and Technology (NIST)

2010. “Guide for Applying the Risk Management

Framework to Federal Information Systems - A Security

Life Cycle Approach”. NIST Special Publication 800-37

Revision 1. February. Retrieved on February 21, 2016 from

http://csrc.nist.gov/publications/nistpubs/800-37-rev1/sp800-

37-rev1-final.pdf

Onuskanich, Rebecca 2011. “Out with the DIACAP, In with

the DIARMF”. December 12. Retrieved on April 02 from:

https://lunarline.com/sites/default/files/out%20with%20diac

ap%20in%20with%20diarmf%20-

%20lunarline%20white%20paper_dec%2011.pdf

Wheele, E. 2011. “Security Risk Management: Building an

Information Security Risk Management Program from the

Ground Up”. Elsevier.

Copyright of Proceedings of the Northeast Business & Economics Association is the property of Northeast Business & Economics Association and its content may not be copied or emailed to multiple sites or posted to a listserv without the copyright holder's express written permission. However, users may print, download, or email articles for individual use.