Is your RMF package detailed enough?
-
- Dale Bingham
- February 25, 2025
Question for you: are you providing enough detail in your RMF accreditation to actually assess proper RISK? That is the “R” in RMF. Not just get an approval stamp but actually assess risk?
Are you looking at patches, compliance, settings, mitigations, open POAM items and all network devices to see what is going on? And making sure you cover all your workstations, devices, cloud, and network? And those you inherit from as well?!?
If you are doing this manually, chances are you do not have enough time to do that! You do sections, you sample “similar machines”, you ask questions, and you take people’s word for it. Or you guess and do your best.