Using CAM

  • Release version: Australia
  • Updated March 12, 2026
  • 1 minute to read
  • To provide CAM services, you implement the seven steps defined by the NIST Risk Management Framework (RMF), implement controls and assessment objectives, and perform continuous authorization and monitoring.

    1. RMF step 0 - Prepare the authorization package

      In the Prepare step, you set up authorization boundaries, control overlays, and information types, as well as create the actual authorization package.

    2. RMF step 1 - Categorize the authorization package

      In the Categorize step, you define the criticality or sensitivity of your information system according to potential worst-case scenarios. This involves selecting NIST information types for the package and using the information types to define the impact levels for the package.

    3. RMF step 2 - Select controls for an authorization package

      When the impact levels for the package have been approved, it is time to select baseline controls.

    4. RMF step 3 - Implement controls

      After you have selected controls for implementation and performed any of the possible actions on them, you can implement the controls.

    5. RMF steps 4, 5, and 6 - Assess, authorize, and monitor

      After you have implemented controls, you can assess internal and external controls, generate Plans of Action and Milestones (POA&M), and manage change requests and vulnerable items.

    6. Implementing controls and assessment objectives in CAM

      NIST 800-53A – assessment objectives are included in the base system with the CAM application. The assessment objectives are mapped to revision 5 control objectives.

    7. Continuous authorization and monitoring tasks in the CAM Workspace

      The CAM Workspace is a centralized hub where you can continuously monitor and manage compliance with the NIST Risk Management Framework to ensure adherence to your security policies and guidelines.