RMF Process
NIST Controls
ISSO Documents
Cloud & Hosting
Acronym Madness
100

What is Prepare?


This is the first RMF step where the organization establishes the context and groundwork for managing security and privacy risk.


100

What is RA-05?


What is RA-05 (Vulnerability Monitoring and Scanning)?

This control focuses on vulnerability monitoring and scanning to identify security weaknesses within a system.


100

What is an SSP (System Security Plan)?

What is a document that describes how security controls are implemented within a system.


100

What is SaaS (Software as a Service)?


In this cloud service model, the provider manages the application, platform, and infrastructure, and users simply access the software through a web browser.


100

What does ISCP stand for? 

What is Information System Contingency Plan?

200

What is Categorize?


During this RMF step, the system is assigned a security categorization based on the potential impact to confidentiality, integrity, and availability.


200

What is IA?

What is IA (Identification and Authentication)?

This control family is responsible for ensuring users are properly identified and authenticated before accessing a system.


200

What is a POA&M (Plan of Action and Milestones)?


What is a document that is used to track security weaknesses until they have been remediated and verified.

200

What is PaaS (Platform as a Service)?


In this cloud service model, the provider manages the infrastructure and platform, while the customer manages their applications and data.


200

What does BIA stand for?

What is Business Impact Analysis?

300

What is Select?


During this RMF step, security and privacy controls are chosen based on the system’s categorization and risk requirements.


300

What is CM-02?

What is Baseline Configuration?

This control requires organizations to establish, document, and maintain a current baseline configuration for the system.


300

What is a SAR (Security Assessment Report)?


What is a document that contains the results of a security control assessment and identifies findings and weaknesses.


300

What is IaaS (Infrastructure as a Service)?


In this cloud service model, the provider supplies virtual servers, storage, and networking, while the customer manages the operating system and applications.


300

Who is the CO?

Who is the Certifying Official?

400

What is Assess?


During this RMF step, assessors determine whether security controls are implemented correctly, operating as intended, and producing the desired outcome.


400

What is AU-06?

What is Audit Record Review, Analysis, and Reporting?

This control requires organizations to review and analyze audit records for indications of inappropriate or unusual activity.


400

What is an IRP (Incident Response Plan)?


What is a document that outlines the actions an organization will take to respond to cybersecurity incidents.


400

What is a Virtual Desktop?


This type of desktop runs on a remote server or cloud environment and is accessed from another device over a network.


400

Who is the AO?

Who is the Authorizing Official?

500

What is Authorize?


This RMF step involves the Authorizing Official reviewing the SSP, SAR, and POA&M to determine whether the system’s risk is acceptable for operation.


500

What is SI-02?


What is flaw remediation? 

An organization applies security patches after vulnerabilities are discovered during a scan. This control governs the remediation process.


500

What is a PIA (Privacy Impact Assessment)?


What is a document that evaluates how a system collects, maintains, uses, and disseminates personally identifiable information (PII).


500

What is Microsoft Azure?


This cloud provider offers services such as Azure Virtual Machines, Azure SQL, and Azure App Services.


500

What does SAR stand for?

What is a Security Assessment Report?