<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>RMF Archives - Corsec Security, Inc.®</title>
	<atom:link href="https://www.corsec.com/tag/rmf/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.corsec.com/tag/rmf/</link>
	<description>Corsec helps companies complete security certifications and validations like FIPS 140-3, Common Criteria, CSfC, &#38; the DoDIN APL / UC APL.</description>
	<lastBuildDate>Thu, 20 Nov 2025 22:30:45 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.corsec.com/wp-content/uploads/cropped-Corsec-Logo-SiteMap-32x32.png</url>
	<title>RMF Archives - Corsec Security, Inc.®</title>
	<link>https://www.corsec.com/tag/rmf/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Fed Roundup: July 2024</title>
		<link>https://www.corsec.com/fed-july24/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Tue, 06 Aug 2024 15:31:47 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[DISA]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[NIAP]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Protection Profile]]></category>
		<category><![CDATA[RMF]]></category>
		<category><![CDATA[STIG]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=20783</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/fed-july24/">Fed Roundup: July 2024</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.disa.mil/newsandevents">DISA News</a></strong></h5>
<h5 style="padding-left: 30px;"><span style="color: #000000;">Announcements:</span></h5>
<ul>
<li><a href="https://www.disa.mil/NewsandEvents/2024/AFCEA-TechNet-DOD-CIO">The Office of the DoD CIO has outlined news strategies to drive change</a></li>
<li><a href="https://www.disa.mil/NewsandEvents/2024/AFCEA-TechNet-Dir-keynote-address">DISA Director Lt. Gen. Robert J. Skinner speaks on the need to partner with industry to protect the DoD&#8217;s network</a></li>
</ul>
<h5 style="padding-left: 30px;"><span style="color: #000000;"><a style="color: #000000;" href="https://public.cyber.mil/stigs/">Security Technical Implementation Guide Updates:</a></span></h5>
<ul>
<li><a href="https://public.cyber.mil/announcement/july-2024-quarterly-release-rev-5-stig-update/">July 2024 Quarterly Release Rev. 5 STIG Update</a></li>
<li><a href="https://public.cyber.mil/announcement/disa-releases-updates-to-the-vmware-vsphere-8-0-security-technical-implementation-guide/">Updates to the VMware vSphere 8.0 STIG</a></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://csrc.nist.gov/News">NIST News</a></strong></h5>
<h5 style="padding-left: 30px;"><span style="color: #000000;">Updates &amp; Announcements:</span></h5>
<ul>
<li><a href="https://csrc.nist.gov/News/2024/introducing-rmf-small-enterprise-quick-start-guide">Risk Management Framework (RMF) Small Enterprise Quick Start Guide</a></li>
</ul>
<h5 style="padding-left: 30px;"><span style="color: #000000;">Special Publications &amp; Interagency Reports:</span></h5>
<ul>
<li><a href="https://csrc.nist.gov/News/2024/bugs-framework-nist-publishes-sp-800231">SP 800-231, Bugs Framework (BF): Formalizing Cybersecurity Weaknesses and Vulnerabilities</a></li>
<li><a href="https://csrc.nist.gov/News/2024/nist-releases-sp-800201">SP 800-201, NIST Cloud Computing Forensic Reference Architecture</a></li>
<li><a href="https://csrc.nist.gov/News/2024/nist-publishes-sp-800218a">SP 800-218A, Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile</a></li>
<li><a href="https://csrc.nist.gov/News/2024/draft-sp-800233-available-for-public-comment">SP 800-233, Service Mesh Proxy Models for Cloud-Native Applications</a></li>
<li><a href="https://csrc.nist.gov/News/2024/nist-revises-sp-80073-and-sp-80078">SP 800-73-5: Parts 1–3 &amp; SP 800-78-5</a></li>
<li><a href="https://csrc.nist.gov/News/2024/4th-draft-nist-sp-80090c-available-public-comment">Draft SP 800-90C, Recommendation for Random Bit Generator (RBG) Constructions</a></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.niap-ccevs.org/announcements">NIAP News</a></strong></h5>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;"><span style="color: #000000;">Updates &amp; Announcements:</span></h5>
<ul>
<li>Call for Participants in the Transport Layer Security (TLS) TC</li>
<li><a href="https://www.niap-ccevs.org/Documents_and_Guidance/2024NIAPQ1_Final%20Quarterly%20Report.pdf">NIAP First Quarter Progress Report</a></li>
</ul>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;"><span style="color: #000000;">Protection Profile Announcements:</span></h5>
<ul>
<li>None</li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_black wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe"><span style="color: #0000ff;">Subscribe</span></a></p>
</div>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/contact-us/">Press Contact:</a></strong></h5>
<p><strong>Jake Nelson</strong><br />
Dir of Marketing<br />
Jnelson@corsec.com</p>
</div>

		</div>
	</div>
</div></div></div></div>
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "><a href="https://www.linkedin.com/company/corsec-security"><img decoding="async" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img decoding="async" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img decoding="async" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/fed-july24/">Fed Roundup: July 2024</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FED ROUNDUP: JANUARY 2019</title>
		<link>https://www.corsec.com/fed-jan19/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Wed, 30 Jan 2019 20:33:16 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[UC APL]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DISA]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[NIAP]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[RMF]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=16921</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/fed-jan19/">FED ROUNDUP: JANUARY 2019</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5 style="text-align: left;"><span style="color: #000000;"><strong><a style="color: #000000;" href="http://sitdev.disa.mil/newsandevents">DISA’s January News</a></strong></span></h5>
<ul>
<li><a href="https://sitdev.disa.mil/NewsandEvents/2019/Mission_Partner_Engagement_Forum_frequency"><span style="color: #0000ff;">DISA&#8217;s Mission Partner Engagement Office (MPEO) increases forum frequency</span></a></li>
</ul>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://csrc.nist.gov/News">NIST’s January News</a></strong></h5>
<h5 style="padding-left: 30px;">Announcement:</h5>
<ul>
<li><a href="https://csrc.nist.gov/News/2019/pqc-standardization-process-2nd-round-candidates"><span style="color: #0000ff;"><span style="color: #0000ff;">NIST PQC Standardization Process Candidates Announced</span></span></a></li>
</ul>
<h5 style="padding-left: 30px;">Releases &amp; Special Publications:</h5>
<ul>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://csrc.nist.gov/News/2018/nist-releases-draft-nistir-8196-for-comment">Draft NISTIR 8196, &#8220;Security Analysis of First Responder Mobile and Wearable Devices</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://csrc.nist.gov/News/2018/nist-publishes-nistir-8011-vol-3">NISTIR 8011 Volume 3, &#8220;Automation Support for Security Control Assessments: Software Asset Management</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://csrc.nist.gov/News/2018/nist-releases-draft-sp-800-189-for-comment">Draft Special Publication 800-189, &#8220;Secure Interdomain Traffic Exchange: BGP Robustness and DDoS Mitigation</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://csrc.nist.gov/News/2018/rmf-update-nist-publishes-sp-800-37-rev-2">Risk Management Framework (RMF) updated &#8211; specification in NIST Special Publication (SP) 800-37 Revision 2</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://csrc.nist.gov/publications/detail/nistir/8240/final">NIST Internal Report (NISTIR) 8240, Status Report on the First Round of the NIST Post-Quantum Cryptography Standardization Process</a></span></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.niap-ccevs.org/Announcements/Announcements.cfm">NIAP’s January News</a></strong></h5>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Updates:</h5>
<ul>
<li><span style="color: #0000ff;">None</span></li>
</ul>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Protection Profile Posting:</h5>
<ul>
<li class="wpb_wrapper" style="text-align: left;"><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://sitdev.niap-ccevs.org/Profile/Info.cfm?PPID=426&amp;id=426">Functional Package for Transport Layer Security (TLS) Version 1.0 Published</a></span></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <span style="color: #0000ff;"><a style="color: #0000ff;" href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></span></p>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_black wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div>
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_text_column wpb_content_element "><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "><a href="https://sitdev.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/fed-jan19/">FED ROUNDUP: JANUARY 2019</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>RMF: Is It Replacing the DoDIN APL and other Security Certifications?</title>
		<link>https://www.corsec.com/rmf/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Mon, 18 May 2015 20:14:10 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[UC APL]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[RMF]]></category>
		<guid isPermaLink="false">http://www.corsec.com/?p=4318</guid>

					<description><![CDATA[<p>As companies tap into the growing addressable markets for Commercial and FED, they are confronted with a litany of standards, acronyms and security validations they must overcome in order to stay relevant. The list is daunting, and making sense of this has been our singular focus for the past 18 years. In that time, we...</p>
<p>The post <a href="https://www.corsec.com/rmf/">RMF: Is It Replacing the DoDIN APL and other Security Certifications?</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>As companies tap into the growing addressable markets for Commercial and FED, they are confronted with a litany of standards, acronyms and security validations they must overcome in order to stay relevant.&nbsp;&nbsp; The list is daunting, and making sense of this has been our singular focus for the past 18 years. In that time, we have worked with over&nbsp;400 products and our customers&nbsp;have come to us as they experienced strong growth, or interest in products from the Commercial and FED sectors, but have to overcome the list of security requirements as a pre-requisite to Market entry. Today, that list now includes RMF and companies that come to us are trying to figure out what RMF means, how it affects their go to market readiness and how it can help differentiate their product offerings in the market place.</p>
<p>Corsec’s Kathleen Moyer discusses the myths and nuances of RMF and how companies can leverage it to create competitive advantages. Kathleen addresses the key questions from some of the companies that have come to us.</p>
<h2><span style="text-decoration: underline; color: #993300;"><strong>What is RMF and How Does It Affect My Business?</strong></span></h2>
<p>RMF, the Risk Management Framework, is laid out in the Federal mandate DODI 8500.01. As part of the current implementation of the Federal Information Security Management Act (FISMA), RMF instructs DISA to develop and maintain SRGs, STIGs, and usage guides that are consistent with DOD cybersecurity policies. In addition, it states that DISA shall oversee and maintain the connection approval process (“provides existing and potential NIPRNET, DATMS-U, and OSD Commercial Internet Waiver subscribers with connectivity requirements that must be followed” &#8211; DISA). There are <a style="text-decoration: underline;" href="http://csrc.nist.gov/groups/SMA/fisma/Risk-Management-Framework/index.html">six steps</a> inherent to RMF: categorize, select, implement, assess, authorize, and monitor.</p>
<p>In terms that industry can understand, RMF provides a structured approach to managing the risk associated with the incorporation of information systems into an organization. If an organization wants to sell its security product to the DoD, it needs to follow RMF. Therefore, if a company wants to penetrate any of the following US DoD markets: Air Force, Army, Marines, Navy, or National Guard, then it must ensure its security solutions adhere to the guidelines laid out in RMF.</p>
<h2><span style="color: #993300;"><strong><u>Where Is the DoDIN APL In This?</u></strong></span></h2>
<p>DoDIN APL (Information Network Approved Product List) is a component of RMF; it is the connection approval process as defined by DoD 8100.04. Below are the four requirements for RMF:</p>
<ol>
<li>Unified capability products will receive unified capability certification for cyber security products in accordance with DoD 8100.04 (<strong>this is <a href="https://www.corsec.com/dodin-apl/">DoDIN APL</a></strong>).</li>
<li>Products that protect classified information must comply with CNSSP 11 (this calls for <strong><a href="http://www.corsec.com/capabilities/practices/fips-140-2/">FIPS 140-2</a></strong> and <strong><a href="http://www.corsec.com/capabilities/practices/common-criteria/">Common Criteria</a></strong>).</li>
<li>Products must meet security configuration guidance in accordance with Chapter 113 and comply with the connection approval process established in Chairman of the Joint Chiefs of Staff Instruction 6211.02D (calls out DISA &#8220;connect approval&#8221; i.e. <strong>DoDIN APL</strong>, as well as <strong>FIPS</strong>, <strong>Common Criteria</strong>, and Suite B)</li>
<li>Products will comply with the requirements of DoD 5200.44 (covers supply chain management), as applicable.</li>
</ol>
<p>Companies going through the DoDIN APL Government Testing will get a SAR (Self Assessment Report) from the Test Center, which comes with a DIACAP Scorecard and 8500.2 IA Controls.&nbsp; As JTIC tests the STIG/SRG requirements they are also testing these areas.&nbsp; Vendors often do not see the filled out DIACAP Scorecard or 8500.2 IA Controls as it is can be buried in the plethora of forms that face them.</p>
<p>RMF is a replacement for DIACAP; UC APL testing provides a mapping to the old DIACAP scorecard. The STIGs and SRGs that are used in DoDIN APL form a major piece of RMF. As the transition to RMF continues, the DoDIN APL process will be modified to support RMF. The Test Reports, Plans of Action and Milestones, IA and IO certification’s received through the DoDIN APL can be used to support the RMF process. The DIACAP scorecard will be replaced with a RMF Security Assessment Report (SAR). As a part of the DoDIN APL process the vendor receives an IO Authorization from the DoD CIO. As a result, RMF also sets guidelines for FIPS, Common Criteria and Suite B.</p>
<p><span style="color: #993300;"><strong><u>How Does This Impact Certifications In-flight?</u></strong></span></p>
<p>Every company’s approach to certifications and security validations is unique. Corsec reviews the ever-changing requirements and advises companies on what changes need to be made, and the implications in the broader landscape.</p>
<p><span style="color: #993300;"><strong><u>Conforming to RMF is Just One Piece of The Puzzle</u></strong></span></p>
<p>If you have not started the process yet and are being asked to comply with RMF, perhaps we can help.</p>
<p><strong><a href="http://www.corsec.com/contact-us/">Contact us</a> </strong>and help us understand how RMF is impacting you and how we can assist you.</p>
<p>The post <a href="https://www.corsec.com/rmf/">RMF: Is It Replacing the DoDIN APL and other Security Certifications?</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
