EP 83: Automating NIST Risk Management Framework with Rebecca Onuskanich

Published: Nov. 11, 2022, 10 a.m.

https://www.yourcyberpath.com/83/

\n\n

In this episode, we go more in depth with the NIST RMF, answering extremely important questions about the different steps of the process and the checklist mentality that can be developed when implementing RMF.

\n\n

Rebecca Onuskanich, CEO of the International Cyber Institute, is here to share with us some of her knowledge gained throughout her 20 years of experience with security compliance and how eMASS is used to implement RMF and its real-world adaptation.

\n\n

Alongside Kip, Rebecca goes over her experience with RMF discussing how different backgrounds can influence the implementation and that a lot of people will have to get over the rigid mentality of RMF in favor of a more technical, real-world, viable approach.

\n\n

Especially when facing the challenge of implementing RMF with different systems, including legacy systems.

\n\n

They also unpack eMASS, who can use it, what are the requirements to use eMASS, what are its limitations, how it helps support the process, and if there are any other ways to implement RMF, highlighting that the current direction is to emphasize resilience and survivability and always put the mission first.

\n\n

What You\u2019ll Learn

\n\n

\u25cf How is RMF adapted in the real world?

\n\n

\u25cf How to make the best use of RMF?

\n\n

\u25cf\xa0\xa0\xa0\xa0 How do the NIST CSF and the RMF compare to one another?

\n\n

\u25cf\xa0\xa0\xa0\xa0 What is eMASS?

\n\n

Relevant Websites For This Episode

\n\n

\u25cf\xa0\xa0\xa0\xa0\xa0www.YourCyberPath.com

\n\n

\u25cf\xa0\xa0\xa0 www.nist.gov

\n\n

Other Relevant Episodes

\n\n

\u25cf\xa0\xa0\xa0 Episode 80 - Risk Management Framework with Drew Church

\n\n

\u25cf\xa0\xa0 \xa0Episode 62 - The NIST Cybersecurity Framework

\n\n

\u25cf\xa0 Episode 56 - Cybersecurity careers in the Defense sector