ABSTRACT

Processing Standard (FIPS 199 and FIPS 200) and NIST SP 800-53 ◾ The potential long-term application of a risk-based approach to control

formulation

9.1 Applying the NIST RMF The NIST RMF was developed by the NIST as a specific way to ensure standard compliance with various federal information assurance certification programs. The goal was to create a standardized basis for documenting the effectiveness of a range of assurance models such as the Department of Defense Information Assurance Certification and Accreditation Process (DIACAP), Department of Defense (DoD) Policy Series 8500, and FIPS 200. More specifically, the purpose of the NIST RMF was to provide the common life cycle basis for assessing the explicit compliance of federal government systems with the dictates of the FISMA.