May 11, 2026
DoD 8140 vs DoD 8570: What Federal IT Professionals Need to Know
Confused about the DoD 8570 to 8140 transition? Learn what changed, which certifications are required, and how to stay compliant in your federal IT role.
Read ArticleMay 11, 2026
Confused about the DoD 8570 to 8140 transition? Learn what changed, which certifications are required, and how to stay compliant in your federal IT role.
Read ArticleMay 24, 2024
IT Dojo's training programs were developed with the information systems professional in mind.
Read ArticleApril 17, 2024
In an era marked by evolving cyber threats and stringent security requirements, the Department of Defense (DoD) plays a pivotal role in safeguarding…
Read ArticleSeptember 27, 2023
In today's tech-driven world, safeguarding sensitive data and critical systems is a top priority, especially for government agencies, including the…
Read ArticleJune 28, 2023
JULY 2023, VOLUME 15, ISSUE 3 When it comes to the future of RMF, rumors abound but truth is hard to come by.
Read ArticleFebruary 8, 2022
Welcome to 2022! It’s now been well over a year since the release of NIST SP 800-53 Rev 5, yet Rev 4 remains the DoD standard.
Read ArticleMay 25, 2021
Recently our regional grocery store chain notified their employees and customers that they had a data breach involving some HR data and pharmacy records.
Read ArticleMay 25, 2021
More than ten years ago, RMF came into existence with the intention of becoming the “unified information security framework for the federal government”.
Read ArticleJanuary 12, 2021
Q. The Risk Management Framework (RMF) life cycle is comprised of how many steps? A. Oh, that’s easy, it’s six. Well … not so fast.
Read ArticleNovember 12, 2019
Dear Dr. RMF, I work in an Army program and I feel like I am getting the hang of RMF, but when the heck do I schedule an independent assessment (SCA-V)?
Read ArticleApril 15, 2019
Dear Dr. RMF, Government IT Security staff work with systems owners to make sure that all systems in the agency have implemented the proper Risk Management…
Read ArticleApril 15, 2019
CNSSI 4009 defines Security Control Inheritance as “a situation in which an information system or application receives protection from security controls (or…
Read ArticleJanuary 11, 2019
All of us who have spent time working with RMF have come to understand just what a time-consuming and resource-intensive process it can be.
Read ArticleOctober 9, 2018
Thanks to the work of the Joint Task Force, RMF is now the official information security life cycle process across all three “segments” of the Executive…
Read ArticleApril 17, 2018
The Defense Security Service (DSS) serves as an interface between the government and cleared industry.
Read ArticleOctober 17, 2017
By federal law, an information system will be designated as a National Security System (NSS) in accordance with the following definition: The term “national…
Read ArticleOctober 17, 2017
In July 2017, SolarWinds conducted an online survey via Market Connections aimed at approximately 200 federal government IT decision makers and influencers…
Read ArticleJuly 13, 2017
This article was written by Lon Berman, CISSP, RDRP of BAI Information Security Step 6 of the Risk Management Framework (RMF) is entitled “Monitor Security…
Read ArticleJuly 13, 2017
This article was written by Kathryn M. Daily, CISSP, RDRP of BAI Information Security.
Read ArticleSeptember 16, 2016
In this issue we will shine the spotlight on the Contingency Planning (CP) family of security controls.
Read ArticleSeptember 16, 2016
Like any complex process, RMF is not without its share of potential pitfalls. Now that we have the benefit of some more RMF projects under our belt, we…
Read ArticleSeptember 16, 2016
If you ask most system owners about the desired outcome of their RMF efforts, they will readily tell you “we are expecting the Authorizing Official (AO) to…
Read ArticleJune 8, 2016
I recently had the pleasure of consulting for a DoD program that successfully navigated the RMF process and received a full three year Authorization to…
Read ArticleJune 7, 2016
Let’s take a look at some strategies for reviewing the Security Control Baseline and creating “action plans” for implementation.
Read ArticleJune 1, 2016
Security Control Inheritance is one of the most powerful tools available to facilitate the RMF process.
Read ArticleMarch 1, 2016
The importance of the Authorizing Official (AO) in the RMF process is self evident.
Read ArticleNovember 23, 2015
Imagine this dialog between Edward, a System Owner, and Christine, his Information System Security Manager (ISSM): Edward (System Owner):“Now that we’ve…
Read ArticleMarch 13, 2015
The Beatles were comprised of how many musicians? Easy, right? They were called the “Fab Four”, so there were definitely 4.
Read ArticleMarch 11, 2015
It’s hard to believe it’s been a whole year since the publication of DoD Instruction (DoDI) 8510.01 in March of 2014, which officially began the transition…
Read ArticleJanuary 27, 2015
No longer just a technical issue, instead a strategic program to manage cybersecurity risk. Targeted cyber attacks are a strategic organizational problem.
Read ArticleNovember 13, 2014
In this issue’s “Spotlight”, we’re not going to focus on any specific controls or families, but rather on a comparison of RMF controls and DIACAP controls.
Read ArticleOctober 16, 2014
With the publication of revised DoD Instruction 8510.01, adoption of the Risk Management Framework (RMF) by DoD has begun.
Read ArticleJuly 21, 2014
Under RMF, NIST SP 800-53 is the primary source for security controls. If we compare these controls to the DoDI 8500.2 IA controls used in DIACAP, several…
Read ArticleJuly 18, 2014
Now that DoD has “officially” begun its adoption of “RMF for DoD IT”, let’s take a look at some of the things your organization can do to ensure a smooth…
Read ArticleApril 22, 2014
The Risk Management Framework (RMF) is a seven-step process defined by NIST SP 800-37 and mandated for all federal and DoD information systems.
Read ArticleApril 10, 2014
As DoD begins its transition from DIACAP to Risk Management Framework for DoD IT, everyone is naturally focused on all the things that will be…
Read ArticleApril 8, 2014
Now that DoD has “officially” begun its adoption of RMF, let’s take a look at some of the things that are “new”! 10. Cybersecurity.
Read ArticleApril 7, 2014
by Annette Leonard BAI Consulting Continuous Monitoring has long been recognized as a critical element in maintaining a strong security posture for any IT…
Read ArticleMay 20, 2011
The IANA (Internet Assigned Number Authority) distributes IPv6 address to RIR's (Regional Internet Registry's) around the world.
Read Article