Skip to main content Skip to footer site map
Updates

Request for Information (RFI) - Risk Management Framework (RMF) Revamp : Department of Defense , June 24 , 2025

June 24, 2025

Department of Defense

Download PDF

From the document: "Background: The DoD Chief Information Officer (CIO) is the Principal Staff Assistant (PSA) and senior advisor to the Secretary and Deputy Secretary of Defense for information technology (IT), including national security systems (NSS) and information resources management (IRM). The CIO oversees all matters related to information, IT, operational technology, Zero Trust, and the broader DoD information environment—encompassing command, control, and communications (C3), electromagnetic spectrum operations, network operations, IT portfolio management, cybersecurity, and positioning, navigation, and timing (PNT). In addition, the DoD CIO is responsible for developing and enforcing enterprise-wide IT and cybersecurity policies, ensuring alignment with technical standards and strategic priorities. The role includes oversight of key DoD agencies such as the Defense Information Systems Agency (DISA) and coordination with entities like the NSA’s Cybersecurity Directorate. The CIO also influences IT budget decisions and leads interagency and international coordination on technology and cyber matters, especially in support of defense missions and crisis response efforts.

The Risk Management Framework (RMF) is the Department of Defense's structured approach for managing cybersecurity risk across its systems. It is closely aligned with the National Institute of Standards and Technology (NIST) guidelines, which are used across the federal government, promoting consistency and interoperability in cybersecurity practices. Although RMF enhances security through continuous monitoring and risk-based decision-making, it’s often seen as slow and cumbersome. To meet the urgent demands of modern cyber threats and accelerate innovation, the DoD is working to streamline the RMF process—aiming for greater efficiency without compromising on security."

Authors - Chief Information Officer

Subjects

Authors

Chief Information Officer

Publishers

Department of Defense

Format

PDF - Download

Related Resources

s