Explore
Summarize
Summary of CAM Overview and RMF Workflow in Explore Release (Australia)
The CAM (Cybersecurity Authorization Management) application automates the NIST Risk Management Framework (RMF) within ServiceNow, providing a standardized approach to managing information system security risks. It supports security authorization and continuous monitoring processes, helping organizations maintain a robust security posture aligned with federal mandates.
Show less
Key Roles and Responsibilities
- System Owner: Responsible for procuring, developing, operating, and maintaining the information system.
- Authorizing Official (AO): Responsible for accepting the system into operation at an accepted risk level, typically a CISO or deputy CISO.
- Authorizing Official Designated Representatives (AODR): Assist the AO in authorization tasks.
- Security Control Assessors (SCA): Conduct thorough assessments of system security controls.
- Information System Security Managers (ISSM): Manage security activities as designated by ISSO.
- Information System Security Officers (ISSO): Ensure operational security posture is maintained.
- Information Owners: Hold statutory and management authority over information.
- System Users: Perform daily operational work on the system.
RMF Workflow Supported by CAM
CAM supports the seven RMF phases, mandated by the U.S. Federal government to ensure resilient information system security and risk management. These phases guide users through a lifecycle approach to authorize and continuously monitor systems:
- Prepare: Define system boundaries, assign roles, identify common controls, and prepare for RMF processes.
- Categorize: Assess the system’s criticality and sensitivity based on potential adverse impacts.
- Select Controls: Choose baseline controls, tailor them, and supplement as needed based on risk.
- Implement Controls: Apply controls within the system architecture, including configuration settings.
- Assess Controls: Evaluate effectiveness and compliance of implemented controls.
- Authorize: Decide if system risk is acceptable and approve system operation.
- Monitor: Continuously track system changes affecting security and reassess controls.
Next Steps for ServiceNow Customers
To effectively use CAM for RMF implementation, customers can explore detailed configuration and usage guides within ServiceNow, including:
- Preparing the authorization package (Step 0)
- Categorizing the authorization package (Step 1)
- Selecting controls for authorization (Step 2)
- Implementing controls (Step 3)
- Assessing, authorizing, and monitoring controls (Steps 4, 5, and 6)
- Managing continuous authorization and monitoring tasks within the CAM Workspace
These resources enable practical application of RMF within your organization using ServiceNow’s CAM to streamline security authorization processes and maintain compliance.
Learn about the CAM benefits and workflows for users.
CAM overview
The CAM application applies a standardized approach to automating NIST's Risk Management Framework (RMF).
CAM users
CAM roles that are required for particular tasks are listed in CAM user roles.
| User / Role | Description |
|---|---|
| System owner | The individual responsible for procuring, developing, integrating, modifying, operating, and maintaining an information system. |
| Authorizing Official (AO) | The individual responsible for accepting an information system into an operational environment at a known risk level. Typically, this person is at the CISO or deputy CISO level. |
| Authorizing Official Designated Representatives (AODR) | One or more AODRs. |
| Security Control Assessors (SCA) | The individuals responsible for conducting a thorough assessment of the controls of an information system. |
| Information System Security Managers (ISSM) | The individuals responsible for conducting information system security management activities as designated by the ISSO. |
| Information System Security Officers (ISSO) | The individuals responsible for ensuring that the appropriate operational security posture is maintained for an information system. |
| Information owners | The individuals responsible for statutory, management, and operational authority. |
| System users | The users responsible for performing the actual work on the system. |
RMF workflow supported by CAM
RMF was mandated by the U.S. Federal government to provide the necessary resiliency to support the economic and national security interests of the United States. CAM employs the seven steps defined by the RMF to allow you to make better-informed decisions about your security posture.
The RMF System Life Cycle consists of seven interconnected phases that work together to provide a comprehensive approach to managing information system security risks. Each phase has a specific focus area and contributes to the overall authorization and continuous monitoring of the system.
RMF Phases
| Phase | Phase Name | Scope | Description |
|---|---|---|---|
| 1 | Prepare | Information System | Define the system boundary, assign roles, identify common controls, and prepare for the RMF process. |
| 2 | Categorize | Information System | Define criticality/sensitivity of information system according to potential worse case, adverse impact to mission/business. |
| 3 | Select | System Controls | Select baseline controls; apply tailoring guidance and supplement controls as needed based on risk assessments. |
| 4 | Implement | System Controls | Implement controls within enterprise architecture using sound systems engineering practices; apply configuration settings. |
| 5 | Assess | System Controls | Determine control effectiveness (that is, controls implemented correctly, operating as intended, meeting requirements for information system). |
| 6 | Authorize | Information System | Determine risk to organizational operations and assets, individuals, other organizations, and the Nation; if acceptable, authorize operation. |
| 7 | Monitor | System Controls | Continuously track changes to the information system that may affect security controls and reassess control effectiveness. |
What to explore next
- Configure
- RMF step 0 - Prepare the authorization package
- RMF step 1 - Categorize the authorization package
- RMF step 2 - Select controls for an authorization package
- RMF step 3 - Implement controls
- RMF steps 4, 5, and 6 - Assess, authorize, and monitor
- Implement controls and assessment objectives
- Continuous authorization and monitoring tasks in the CAM Workspace
- Reference