The Defense Department is about halfway through its transition from the DoD Information Assurance Certification and Accreditation Process to the National Institute of Standards and Technology Risk Management Framework.
The transition to RMF, slated for completion by mid-2018, marks a sweeping cultural shift in the department’s approach to IT security. DIACAP established a standard set of activities to certify and accredit DoD information systems, and looked to refresh every three years. The RMF, on the other hand, takes a dynamic approach, focusing on risk management as its primary approach and emphasizing a need for ongoing continuous monitoring.
Learn more about the move to the RMF in our free whitepaper. Download it here.
Some in defense are rising to the challenge. The Army’s Medical Communications for Combat Casualty Care organization, for example, declared it had reached full implementation of RMF in 2015. Others have been slower to adopt the new standards, according to a recent survey by Splunk, a provider of a data-analytics platform for security and other IT-driven business needs.
Splunk found that a significant number of IT leaders have established baseline security controls for less than half of their information systems.
Moreover, nearly 50 percent of the survey respondents admitted that less than half of their security controls have been implemented with the deployment approach documented. Meanwhile, almost 40 percent say they fall well short of the RMF’s prescription for frequent and ongoing reviews.
Defense agencies struggle with RMF transition




