Using CAM

  • Release version: Zurich
  • Updated July 31, 2025
  • 1 minute to read
  • To provide CAM services, you implement the seven steps defined by the NIST Risk Management Framework (RMF), implement controls and assessment objectives, and perform continuous authorization and monitoring.

    1. Risk Management Framework (RMF) step 0 - Prepare the authorization package

      In the Prepare step, you set up authorization boundaries, control overlays, and information types, as well as create the actual authorization package.

    2. Risk Management Framework (RMF) step 1 - Categorize the authorization package

      In the Categorize step, you define the criticality or sensitivity of your information system according to potential worst-case scenarios. This involves selecting NIST information types for the package and using the information types to define the impact levels for the package.

    3. Risk Management Framework (RMF) step 2 - Select controls for an authorization package

      When the impact levels for the package have been approved, it is time to select baseline controls.

    4. Risk Management Framework (RMF) step 3 - Implement controls

      After you have selected controls for implementation and performed any of the possible actions on them, you can implement the controls.

    5. Risk Management Framework (RMF) step 4 - Assess implemented controls and document findings

      After you have implemented controls, you can assess internal and external controls, generate Plans of Action and Milestones (POA&M), and manage change requests and vulnerable items.

    6. Implementing controls and assessment objectives in CAM

      NIST 800-53A – assessment objectives are included in the base system with the CAM application. The assessment objectives are mapped to revision 5 control objectives.

    7. Continuous authorization and monitoring tasks in the CAM Workspace

      The CAM Workspace is a centralized hub where you can continuously monitor and manage compliance with the NIST Risk Management Framework to ensure adherence to your security policies and guidelines.