---
sourceDocument: Xanadu Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/governance-risk-compliance

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Exploring CAM

# Exploring CAM {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 7, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Learn about the CAM benefits and workflows for users.

## CAM overview {#exploring-grc-cam__cf-exploring-parent-overview}

The CAM application applies a standardized approach to automating NIST's Risk Management Framework (RMF).

## CAM users {#exploring-grc-cam__cf-exploring-parent-users}

CAM roles that are required for particular tasks are listed in [CAM user roles](https://www.servicenow.com/docs/gn27Wdc7RfdfNvBBr5nQJQ "Assign users and groups with roles to prepare them to user the CAM application.").
{#exploring-grc-cam__id_wwd_mjx_hcc__entry__2}

| Role | Responsibilities |
|-|-|
| System owner | The individual responsible for procuring, developing, integrating, modifying, operating, and maintaining an information system. |
| Authorizing Official (AO) | The individual responsible for accepting an information system into an operational environment at a known risk level. Typically, this person is at the CISO or deputy CISO level. |
| Authorizing Official Designated Representatives (AODR) | One or more AODRs. |
| Security Control Assessors (SCA) | The individuals responsible for conducting a thorough assessment of the controls of an information system. |
| Information System Security Managers (ISSM) | The individuals responsible for conducting information system security management activities as designated by the ISSO. |
| Information System Security Officers (ISSO) | The individuals responsible for ensuring that the appropriate operational security posture is maintained for an information system. |
| Information owners | The individuals responsible for statutory, management, and operational authority. |
| System users | The users responsible for performing the actual work on the system. |
[Table 1. Roles and Responsibilities tab]

{#exploring-grc-cam__id_wwd_mjx_hcc}

## RMF workflow supported by CAM {#exploring-grc-cam__cf-exploring-parent-workflow}

RMF was mandated by the U.S. Federal government to provide the necessary resiliency to support the economic and national security interests of the United States. CAM employs the seven steps defined by the RMF to allow you to make better-informed decisions about your security posture.  
RMF consists of the seven steps illustrated here.Figure 1. RMF security life cycle

## What to explore next {#exploring-grc-cam__cf-exploring-parent-links}

To learn more about configuring and using CAM, see:

* [Configuring CAM](https://www.servicenow.com/docs/kmOdXUMkQPU6c5Y~rb1uiA "Follow the steps in the checklist to download CAM from the ServiceNow Store and get it ready for operation.")
* [RMF step 0 - Prepare the authorization package](https://www.servicenow.com/docs/C5uCRiFTa9PhIHi~1bNiRg "In the Prepare step, you set up authorization boundaries, control overlays, and information types, as well as create the actual authorization package.")
* [RMF step 1 - Categorize the authorization package](https://www.servicenow.com/docs/CLhdZrml1M~KnRbnz6fp7w "In the Categorize step, you define the criticality or sensitivity of your information system according to potential worst-case scenarios. This involves selecting NIST information types for the package and using the information types to define the impact levels for the package.")
* [RMF step 2 - Select controls for an authorization package](https://www.servicenow.com/docs/Vx0cadYMddAFJSH3N4OdrA "When the impact levels for the package have been approved, it is time to select baseline controls.")
* [RMF step 3 - Implement controls](https://www.servicenow.com/docs/3WZPjNdsvaFDTAyWC6GODg "After you have selected controls for implementation and performed any of the possible actions on them, you can implement the controls.")
* [RMF steps 4, 5, and 6 - Assess, authorize, and monitor](https://www.servicenow.com/docs/wqrnLyRHxS~lnmly6ifsgQ "After you have implemented controls, you can assess internal and external controls, generate Plans of Action and Milestones (POA&M), and manage change requests and vulnerable items.")
* [Implementing controls and assessment objectives in CAM](https://www.servicenow.com/docs/ByMCHZhSfEYZMACy~sxKLQ "NIST 800-53A – assessment objectives are included in the base system with the CAM application. The assessment objectives are mapped to revision 5 control objectives.")
* [Continuous authorization and monitoring tasks in the CAM Workspace](https://www.servicenow.com/docs/fDYWmTF8SyWLJshBfvP16Q "The CAM Workspace is a centralized hub where you can continuously monitor and manage compliance with the NIST Risk Management Framework to ensure adherence to your security policies and guidelines.")
* [CAM reference](https://www.servicenow.com/docs/SNITGhM6G88RXQwl_DN~3Q "Reference topics provide the detailed descriptions of tables, properties, forms, and roles that are installed with the CAM application.")
{#exploring-grc-cam__ul_lhr_ftp_hcc}

