Critique Popular Risk Assessment and Management Procedures
Northeast Business & Economics Association Proceedings, 2017 11
Risk Management Framework (RMF) and the Implementation
Challenges
Lloyd Ahamefule Amaghionyeodiwe, PhD
Department of Accounting and Finance
York College
City University of New York (CUNY)
94-20 Guy R. Brewer Boulevard
Jamaica, New York USA 11451
(718) 262 2517
ABSTRACT
Recently, there has been a shift in the risk management
process of the federal government and its agencies. The shift
is the transition from the Information Assurance
Certification and Accreditation (C&A) to the National
Institute of Standards and Technology (NIST) Risk
Management Framework (RMF). This was also a shift from
a compliance-based approach to a risk-managed approach to
cybersecurity. However, as with any major changes, this
shift does not come without some resistance and
implementation challenges. This paper examines the new
risk management framework (RMF) and the implementation
challenges. Among the observed implementations challenges
are those related to solid governance as well as a culture that
promotes communication, trust, thinking, and informed risk
taking. Other challenges include the lack of top management
support and the need for Cybersecurity proficiency and
trainings. Based on these, this study suggests that the need
for security personnel to be adequately trained and educated
in the use of the RMF. Also, organizations should have an
avenue where they can share their various experiences about
the applicability and usage of the security mitigations (and
security controls). This will help improve the understanding
of how to use and what to expect from the implementation of
the RMF.
Keywords Risk management framework, cybersecurity, information
assurance
1 INTRODUCTION
Risk Management Framework has been used by security
practitioners in various ways based on the context and
circumstances of where it is applied. These practitioners are
those engaged in applying any of the disciplines referred to
as information security, information systems security,
computer security, and cyber security, to systems
engineering, business process engineering, strategic
planning, program planning, or operations. In the past, the
Department of defense (DoD) has executed various
frameworks to oversee information assurance (IA) measures
with an end goal of securing their information systems. One
of such frameworks is the DoD’s Information Assurance
Certification and Accreditation Process (DIACAP) which
was used as the accepted framework and helped reduced
system integration difficulties within the DoD. This
notwithstanding, there has been reason to expand its
adoption and usage to incorporate other Federal government
agencies while concentrating on the management of
organizational risk. As a result of this, there has been a move
from DIACAP to Risk Management Framework (RMF),
which was provided by NIST and CNSS. And in this regard,
the DoD contributes to the development process, and they
principally influence and control NIST/CNSS approaches to
address DoD needs.
In addition to allowing several officials from within or
outside their primary organization to share responsibility for
authorizing and accepting system-related security risks, the
shift to RMF changes the Certification & Authorization
(C&A) process to an Assessment & Authorization (A&A)
process. RMF shifts away from a compliance-based
approach to a risk-managed approach to cybersecurity.
Unlike previous government approaches for addressing
cybersecurity risk, the RMF provides a legitimate avenue to
accept the risk from addressing security needs differently
than initially expected so long as it is done in a thoughtful
manner. The reduced funding available to federal agencies
reinforces the need for an informed risk-based approach
such as what is promoted via the RMF. The shift to the RMF
also redefines the manner in which the security and privacy
controls in NIST’s 800-53 Publication as well as the role
descriptions and responsibilities are ordered and defined.
The RMF models are deliberately broad-based with the
defined means of evaluating risk and using appropriate risk
mitigation approaches provided by the supporting NIST
security standards and guidelines. RMF implementation is in
varying stages of maturity throughout the US Government
and as leadership of Federal Departments and Agencies
changes, their commitment to implement the RMF as
intended has fluctuated and the interpretation of what is
needed has at times changed. It is as a result of this that this
study intends to investigate the challenges associated with
implementing the RMF by the different agencies. The study
is divided into four sections.
Northeast Business & Economics Association Proceedings, 2017 12
2 DoD’s RISK MANAGEMENT FRAMEWORK
(RMF)
The background of the DOD migrating from DIACAP to
Risk Management Framework (RMF) began in an effort to
consolidate and standardize information risk management
for the federal government. The RMF is the “common
information security framework” for federal government and
its information systems. RMF have the main goals of
improving information security, fortifying the risk
management processes, and boosting mutuality among
federal agencies. According to NIST (2010) the Risk
Management Framework was described as a structured, yet
flexible approach for managing the portion of risk resulting
from the incorporation of information systems into the
mission and business processes of the organization. The
approach includes a six-step iterative process as shown in
Figure 1.
Source: Adopted from Fleener, Mayor and Zou (2015).
Figure 1. DoD RMF Six Step Process.
With the transition, the federal government intends to shift
from a compliance-based approach to a risk-managed
approach to cyber security. The major reasons for this
advancement include constrained spending plans, including
the need to "accomplish more with less", and also the
increasing occurrence of dynamic and sophisticated threats.
This is also based on the believe that security is not an end in
and of itself, rather security enables an entity to fulfill its
mission despite ongoing and successful attacks.
The RMF implementation is in varying stages of maturity
throughout the US Government. And leadership changes in
these federal department and agencies have led to variations
in the implementation of the RMF as well as in the
interpretation of what is needed. According to the Defense
Information Systems Agency, (2012), this shift will
standardize the language used for information assurance
across the entire federal government.
DIACAP was largely a static process with time driven
milestones to include triennial reaccreditations, annual
security reviews and few requirements for continuous
monitoring of the security posture of a system. RMF is
placing a significant emphasis on real time security. The
continuous monitoring of the security posture of a system, to
include reporting metrics and compliance to a higher agency,
is one of the cornerstones for the transition to RMF.
3 CHALLENGES IN IMPLEMENTING THE RISK
MANAGEMENT FRAMEWORK In implementing the RMF, there have been some challenges
towards viewing the RMF as an adaptable process. Some of
the reasons for these challenges include that of not being
familiar about the flexibility that is inherent in it. There is
also restricted engineering experience among many security
practitioners and lack of familiarity with the concept of a
trade space, and the pressure to remain within one’s silo due
to the political ramifications of convergence of security with
other domains.
Being a new introduction, it requires solid governance as
well as a culture that promotes communication, trust,
thinking, and informed risk taking, for it to be efficiently
implemented. But the implementation decision using RMF
have some apparent problems, which is that the RMF
embeds risk assessments in each step but the discussion of
risk in most steps is so restrained that many do not recognize
what risk-related activities need to occur. Across the users of
RMF, many of them see it and practice it as just security
controls, security testing and evaluation, and continuous
monitoring. While these concepts have a role in the RMF, in
and of themselves they cannot and will not lead to risk
management. Many officials fail to perform the necessary
risk framing activities that inform the execution of RMF
activities. This can be attributed to two main reasons which
include risk aversion and unwillingness to articulate in
writing their risk tolerance, that is, the level and nature of the
risk they are willing to accept. In this kind of situation, there
is the need to adopt a policy that assigns roles and
responsibilities for framing, assessing, and managing cyber
risks in these organizations. In these organizations, cyber
risk management must support enterprise risk management,
which includes managing financial, operational (or mission),
and existential risks. Also, because of the way the transition
was done, which many perceived this as being rushed. Thus,
they felt inhibited in their ability to meet the timeframes
mandated.
Another challenge is that of organizational change which
many see as is a precondition for developing how the RMF
should be implemented. This is also related to the fear of the
unknown given the transition to RMF and this comes with
lots of risk for the organizations. Changing the culture to
RMF comes with lots of expectation especially as it relates
training and adoption of these changes. Thus, many in the
industry are more enthusiastic and eager to embrace the way
the RMF was intended to be used while others become more
entrenched in their views that the process is cumbersome,
bulky and ultimately a threat to security. For instance,
several approaches for implementing the RMF have been
used by numerous organizations and each of them offers
divergent experiences. These experiences are more related to
the need for more skilled staff, more resources, more time to
transition and more training. By implication, these needs are
Northeast Business & Economics Association Proceedings, 2017 13
less concerned with the RMF itself but more to do with the
effects over time of underinvestment in staff capabilities, as
well as the inherent complexity of cyber security.
There are also some technical challenges especially as it
relates to the use of baselines as the minimum and basis for
compliance. Many of these security baselines often fail to
articulate the operational or technical environment, thus,
implementing baselines without fitting it to organization’s
need sets up users for an unrealistic or unnecessary set of
controls. Also, many of the controls are based on various
assumptions (like assumes a physical infrastructure, assumes
a high degree of persistence of data, or assumes that the
organization is a government entity). But these assumptions
are not articulated or captured in any knowledge base.
Consequently, users lack the information and tools that are
needed to support making informed risk management
decisions.
Furthermore, there is the use of automated tools most of
which tend to be compliance focused tools. And determining
whether solutions implemented are compliant is an element
of monitoring, but should not be the sole reason for
monitoring. With respect to the automated tools and
controls, many people consider controls as-is are technical
specifications while others see the potential to use security
controls as an input into the requirements management
process. Hence, they believe that the number of controls and
the relative merits and applicability of the controls is too
much for any human being to keep in his/her head.
Therefore, there is the need for automated tools that are
well-maintained, shared database/repository, with relevant
metadata regarding the controls, are necessary to aid security
practitioners in making informed decisions regarding the
effectiveness, cost, and relevance of the various controls in
different environments and different threat settings. Without
these tools it become cumbersome and more difficult for the
security professionals to keep pace with the changing cyber
threat environment and associated security mitigations.
Many of the users also fail to recognize cybersecurity as a
“design consideration” and they forgot that to achieve
positive acquisition outcomes, there is the need to
consistently “bake in” Cybersecurity into our acquisition
programs. This is made complicated by the integration of
multiple complex processes (RMF & DoD Acquisition
Lifecycle) into the Cybersecurity requirements for this
system. Other RMF implementation challenges are that
program Managers view of Cybersecurity as just another
unfunded requirement and the lack of a common
understanding and definition of Cybersecurity given that the
effective Cybersecurity on DoD acquisition programs is
much more than just the RMF. There is also lack of top
management support and the need for Cybersecurity
expertise and training. This will help in enhancing the
number of the Cybersecurity workforce.
4 CONCLUSION
Given the importance of risk management in an
organization, and given some of the challenges in
implementing the RMF, it important that security personnel
should be adequately trained and educated in the use of the
RMF. More skilled security personnel should also be
involved. In terms of automation, there is the need for an
automation that will allow for practitioners to mine, analyze
and add to this knowledge base in analysis of possible
mitigations (and associated security controls) in a timely
manner. Some combination of databases and automated
tools may also help decisions makers in determining their
risk tolerance and risk thresholds as well as selection of risk
responses. Organizations should have an avenue where they
can share their various experiences about the applicability
and usage of the security mitigations (and security controls)
as well as contribute and expand the knowledge base. This
will help improve the understanding of how to use and what
to expect from the implementation of the RMF. Transiting
from one system to another is always a difficult one as such
there is a need for a mentality change through better training
for those responsible for making cyber security risk
management decisions and for the security professionals
who support them. In line with this there is a need for a risk
executive function that is responsible for making risk
decision trade-offs. Additionally, such a risk executive
function needs to be appropriately empowered to make the
necessary risk management trade-off decisions. In all, the
RMF provides a structured, yet flexible approach for
managing risk. When executed as intended, risk based
decision-making at every step of the process allows for the
options of acceptance, avoidance, transfer, sharing and
mitigation of risk. Effective risk management must be done
in context of the strategic, operational and tactical
imperatives facing an enterprise. Also, cyber security should
not be seen as an end in of itself but rather a means to help
achieve a mission. As such it should be viewed as an
integrated set of processes and activities that contribute to
the accomplishment of organizational and mission activities.
Achieving the full benefits of the Risk Management
Framework requires significant changes on the political,
cultural and technical fronts.
REFERENCES
David, R., and Wendy W. 2012 “IA OM as an Enterprise
Risk Management Metric”, Risk Management - Current
Issues and Challenges. Retrieved from:
http://www.intechopen.com/books/risk-management-
current-issues-and-challenges/ia-om-as-an-enterprise-risk-
management-metric
Department of Defense (DoD) 2014. “Risk Management
Framework (RMF) for DoD Information Technology (IT)
Instruction 8510.01.” March 12. Retrieved on February 21,
2016 from
http://www.dtic.mil/whs/directives/corres/pdf/851001_2014.
Northeast Business & Economics Association Proceedings, 2017 14
Defense Information Systems Agency 2012. “DIACAP to
Risk Management Framework (RMF) Transformation”.
Washington, DC.
Fabius, Jennifer and Richard Graubart 2014. “Beyond
Compliance – Addressing the Political, Cultural and
Technical Dimensions of Applying the Risk Management
Framework”. Retrieved on February 21, 2016 from
https://www.mitre.org/sites/default/files/publications/pr-14-
3551-beyond-compliance-applying-risk-management-
framework.pdf
Fleener, Graham., Marco Mayor and Cliff Zou 2015. “Risk
Management Framework (RMF) Transition Impacts in
Training Simulation Systems”. Interservice/Industry
Training, Simulation, and Education Conference (I/ITSEC)
Paper No. 15009. Retrieved from:
http://www.cs.ucf.edu/~czou/research/Graham-IITSEC-
2015.pdf
Gantz, Stephen D., and Daniel R. Philpott. 2013. “FISMA
and the Risk Management Framework the New Practice of
Federal Cyber Security”. Waltham, MA: Elsevier/Syngress.
Health Information Trust Alliance 2013. “Risk Management
Frameworks”. March. Retrieved on February 21, 2016 from
https://hitrustalliance.net/content/uploads/2014/05/HITRUS
T-RMF-Whitepaper2.pdf
Maximo, Danny 2013. “Risk Management Framework
(RMF) and the Future of DoD Information Assurance (IA)”.
September 24th. Retrieved on February 21, 2016 from
http://www.seguetech.com/blog/2013/09/24/risk-
management-framework-future-dod-information-assurance
National Institute of Standards and Technology (NIST)
2010. “Guide for Applying the Risk Management
Framework to Federal Information Systems - A Security
Life Cycle Approach”. NIST Special Publication 800-37
Revision 1. February. Retrieved on February 21, 2016 from
http://csrc.nist.gov/publications/nistpubs/800-37-rev1/sp800-
37-rev1-final.pdf
Onuskanich, Rebecca 2011. “Out with the DIACAP, In with
the DIARMF”. December 12. Retrieved on April 02 from:
https://lunarline.com/sites/default/files/out%20with%20diac
ap%20in%20with%20diarmf%20-
%20lunarline%20white%20paper_dec%2011.pdf
Wheele, E. 2011. “Security Risk Management: Building an
Information Security Risk Management Program from the
Ground Up”. Elsevier.
Copyright of Proceedings of the Northeast Business & Economics Association is the property of Northeast Business & Economics Association and its content may not be copied or emailed to multiple sites or posted to a listserv without the copyright holder's express written permission. However, users may print, download, or email articles for individual use.