You are on page 1of 2

MODULE 2 – APPLIED STANDARDS AND

CYBERSECURITY RISK MANAGEMENT


RISK MANAGEMENT FRAMEWORK AND NIST STANDARDS

LAB SOLUTIONS: APPLICATION OF RMF STEPS 1 AND 2

LAB EXERCISE

INFORMATION TYPES
1. Disaster monitoring and prediction
2. Disaster preparedness and planning
3. Disaster repair and restoration
4. Emergency response
5. Ground transportation
6. Water resource management

Other

7. Energy supply
8. Environmental remediation
9. Key asset and critical infrastructure
10. Water transportation
11. Energy resource management
12. Crime prevention

Security Controls

1. Access control
2. Privacy authorization
3. Risk assessment
4. Personnel security

Other

5. Assessment, authorization, and monitoring


6. Planning

Page | 1

This document is licensed with a Creative Commons Attribution 4.0 International License ©2017
7. Program management
8. Physical and environmental protection

Feedback to students: Application of DoD RMF is very contextual as shown in this


scenario. The steps performed in this Lab exercise would be similar to other
possible scenarios (e.g. other than disaster response and recovery). However, the
particular security controls will be determined by types of information particular to
the scenario.

Page | 2

This document is licensed with a Creative Commons Attribution 4.0 International License ©2017 Catalyzing Computing and Cybersecurity in
Community Colleges (C5).

You might also like