Skip to main content Skip to footer site map
Updates

Risk Management Framework (RMF) Suggestions for Process Advancement : Carnegie Mellon University , July 29 , 2025

July 29, 2025

Carnegie Mellon University

Download PDF

From the document: "The following document captures the collective feedback from Carnegie Mellon University’s Software Engineering Institute (SEI) for the most recent United States Department of Defense (US DoD) Chief Information Officer request for information regarding the implementation of the Risk Management Framework.123 The Risk Management Framework (RMF) serves as the Department of Defense’s structured approach for managing cybersecurity risks across its systems. The implementation of RMF can be slow and cumbersome depending upon the organizational context, the scope of the system, the capabilities of the organization, and the risk appetite of the authorizing official. It follows that delays to the process may negatively impact the urgent demands to address modern cybersecurity threats and accelerate innovation to support the warfighter.

Authors - Tucker, Brett, Wray, Shawn

Subjects

Authors

Tucker, Brett, Wray, Shawn

Publishers

Carnegie Mellon University

Format

PDF - Download

Related Resources

s