---
sourceDocument: Brazil Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/governance-risk-compliance

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Explore

# Explore {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of CAM Overview and RMF Workflow in ServiceNow Explore Release Brazil

The CAM (Cybersecurity Automation and Management) application in ServiceNow standardizes and automates the NIST Risk Management Framework (RMF) process.
It supports systematic risk management by guiding users through the RMF's seven phases, enabling informed decisions about an information system's security posture.
CAM is designed to help organizations comply with federal cybersecurity mandates and manage security risks effectively throughout the system lifecycle.
Show full answer Show less  

## Key Roles and Responsibilities

CAM defines specific roles to support various RMF tasks, ensuring clear accountability:

* **System Owner:** Oversees procurement, development, and maintenance of the information system.
* **Authorizing Official (AO):** Responsible for accepting the system into operation at an acceptable risk level, typically a CISO or deputy.
* **Authorizing Official Designated Representatives (AODR):** Assist the AO as designated representatives.
* **Security Control Assessors (SCA):** Conduct thorough assessments of security controls.
* **Information System Security Managers (ISSM):** Manage information system security activities.
* **Information System Security Officers (ISSO):** Maintain operational security posture.
* **Information Owners:** Hold statutory and operational authority over information.
* **System Users:** Perform tasks within the system environment.

## RMF Workflow Supported by CAM

The RMF process, mandated by the U.S. Federal government, consists of seven interconnected phases to manage information system security risks comprehensively. CAM automates and supports these phases:

* **Phase 1 - Prepare:** Define system boundaries, assign roles, and prepare for RMF.
* **Phase 2 - Categorize:** Determine system criticality and sensitivity based on potential adverse impacts.
* **Phase 3 - Select:** Choose baseline security controls and tailor them based on risk assessments.
* **Phase 4 - Implement:** Apply selected controls using sound engineering and configuration practices.
* **Phase 5 - Assess:** Evaluate the effectiveness of implemented controls.
* **Phase 6 - Authorize:** Decide on risk acceptance and authorize system operation.
* **Phase 7 - Monitor:** Continuously track system changes and reassess controls.

## What ServiceNow Customers Can Expect

By leveraging CAM, ServiceNow customers can automate and manage their RMF compliance lifecycle efficiently. CAM provides a structured, role-based approach to security risk management, enables continuous monitoring, and supports ongoing authorization tasks. This empowers organizations to maintain a robust security posture aligned with federal standards, reduce manual effort, and improve audit readiness.

## Next Steps

To fully utilize CAM capabilities, customers should explore detailed configuration and execution guidance for each RMF phase within CAM, including preparing authorization packages, categorizing systems, selecting and implementing controls, and performing assessment and continuous monitoring tasks through the CAM Workspace.  
Learn about the CAM benefits and workflows for users.

## CAM overview {#exploring-grc-cam__cf-exploring-parent-overview}

The CAM application applies a standardized approach to automating NIST's Risk Management Framework (RMF).

## CAM users {#exploring-grc-cam__cf-exploring-parent-users}

CAM roles that are required for particular tasks are listed in [CAM user roles](https://www.servicenow.com/docs/8ZBovEjMvOAH6fIUGoWIvQ "Assign users and groups with roles to prepare them to user the CAM application.").
{#exploring-grc-cam__id_wwd_mjx_hcc__entry__2}

| User / Role | Description |
|-|-|
| System owner | The individual responsible for procuring, developing, integrating, modifying, operating, and maintaining an information system. |
| Authorizing Official (AO) | The individual responsible for accepting an information system into an operational environment at a known risk level. Typically, this person is at the CISO or deputy CISO level. |
| Authorizing Official Designated Representatives (AODR) | One or more AODRs. |
| Security Control Assessors (SCA) | The individuals responsible for conducting a thorough assessment of the controls of an information system. |
| Information System Security Managers (ISSM) | The individuals responsible for conducting information system security management activities as designated by the ISSO. |
| Information System Security Officers (ISSO) | The individuals responsible for ensuring that the appropriate operational security posture is maintained for an information system. |
| Information owners | The individuals responsible for statutory, management, and operational authority. |
| System users | The users responsible for performing the actual work on the system. |
[Table 1. Roles and Responsibilities tab]

{#exploring-grc-cam__id_wwd_mjx_hcc}

## RMF workflow supported by CAM {#exploring-grc-cam__cf-exploring-parent-workflow}

RMF was mandated by the U.S. Federal government to provide the necessary resiliency to support the economic and national security interests of the United States. CAM employs the seven steps defined by the RMF to allow you to make better-informed decisions about your security posture.

The RMF System Life Cycle consists of seven interconnected phases that work together to provide a comprehensive approach to managing information system security risks. Each phase has a specific focus area and contributes to
the overall authorization and continuous monitoring of the system.

## RMF Phases

{#exploring-grc-cam__entry__22}

| Phase | Phase Name | Scope | Description |
|-|-|-|-|
| 1 | Prepare | Information System | Define the system boundary, assign roles, identify common controls, and prepare for the RMF process. |
| 2 | Categorize | Information System | Define criticality/sensitivity of information system according to potential worse case, adverse impact to mission/business. |
| 3 | Select | System Controls | Select baseline controls; apply tailoring guidance and supplement controls as needed based on risk assessments. |
| 4 | Implement | System Controls | Implement controls within enterprise architecture using sound systems engineering practices; apply configuration settings. |
| 5 | Assess | System Controls | Determine control effectiveness (that is, controls implemented correctly, operating as intended, meeting requirements for information system). |
| 6 | Authorize | Information System | Determine risk to organizational operations and assets, individuals, other organizations, and the Nation; if acceptable, authorize operation. |
| 7 | Monitor | System Controls | Continuously track changes to the information system that may affect security controls and reassess control effectiveness. |
[ ]

## What to explore next {#exploring-grc-cam__cf-exploring-parent-links}

To learn more about configuring and using CAM, see:

* [Configure](https://www.servicenow.com/docs/P~_SJ2~w7yodQx~8BE8y7w "Follow the steps in the checklist to download CAM from the ServiceNow Store and get it ready for operation.")
* [RMF step 0 - Prepare the authorization package](https://www.servicenow.com/docs/TSRu21uhSQl3ssZ2QsabHg "In the Prepare step, you set up authorization boundaries, control overlays, and information types, as well as create the actual authorization package.")
* [RMF step 1 - Categorize the authorization package](https://www.servicenow.com/docs/XQ66lCJJfc_~xtmErHid3w "In the Categorize step, you define the criticality or sensitivity of your information system according to potential worst-case scenarios. This involves selecting NIST information types for the package and using the information types to define the impact levels for the package.")
* [RMF step 2 - Select controls for an authorization package](https://www.servicenow.com/docs/Wox4XdsGD1rurBYF7v71rg "When the impact levels for the package have been approved, it is time to select baseline controls.")
* [RMF step 3 - Implement controls](https://www.servicenow.com/docs/5jCnF6~EJ67VNIjAuJ1Fqg "After you have selected controls for implementation and performed any of the possible actions on them, you can implement the controls.")
* [RMF steps 4, 5, and 6 - Assess, authorize, and monitor](https://www.servicenow.com/docs/ZYPQqZ9eZ9xbbzPC21WpNg "After you have implemented controls, you can assess internal and external controls, generate Plans of Action and Milestones (POA&M), and manage change requests and vulnerable items.")
* [Implement controls and assessment objectives](https://www.servicenow.com/docs/LZuHaX59GjIR895uh3WReA "NIST 800-53A – assessment objectives are included in the base system with the CAM application. The assessment objectives are mapped to revision 5 control objectives.")
* [Continuous authorization and monitoring tasks in the CAM Workspace](https://www.servicenow.com/docs/YsYX8QhdB7WPXf8ZYJJPiQ "The CAM Workspace is a centralized hub where you can continuously monitor and manage compliance with the NIST Risk Management Framework to ensure adherence to your security policies and guidelines.")
* [Reference](https://www.servicenow.com/docs/5J8o8LGrK9RXdvFqbQdIKw "Reference topics provide the detailed descriptions of tables, properties, forms, and roles that are installed with the CAM application.")
{#exploring-grc-cam__ul_lhr_ftp_hcc}

