430 W5 DQ1 UG

430 W5 DQ1

Briefly describe the purpose and application of the Risk Management Framework. How does this differ from the Cyber Security Framework? Which would you recommend and why?

Reply to responses.

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

A Aaron

Evening,

The Risk Management Framework (RMF) was first intended for federal agencies but soon was adopted by organization that were in the private sector. A business can’t operate with out exposing themselves to so sort of risks like IT problems, Litigation and Loss of Capitol (Posey, 2021). The RMF is made up of five components, that are Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance. The Identification stage is to identify the risks that an organization might have, and this process is not a one-time thing as these risks might change over time. Measurement and assessment are when you create a risk profile for each that was identified in the first step and the measurement can be in the form of how much capital could be lost. Mitigation is by examining the risks and determining which risks should be eliminated and which risks are acceptable. Reporting and monitoring involves reexamining the risks to make sure the mitigation strategies the organization have adopted are serving their purposes. Governance is the process of making sure the adoption of the mitigation strategies is in place and that the employees are following the policies. RMF is more targeted towards the federal government and CSF was originally developed for critical infrastructure but has been recommended for use in organizations. CSF is aimed towards the private sector more than the federal government and does not have any Authorizing Officials (AOs) or an Authority to Operate (ATO) which RMF has ATOs to determine the authorized periods required for approval by and AO. NIST recommends that the CSF be used to strengthen the RMF. I would say that I would use the RMF to first get the framework in place then start implementing the CSF. Both of the frameworks have two entirely different end goals.

Posey, B. (2021) What is risk management and why is it important? Retrieved from 

https://www.techtarget.com/searchcio/definition/Risk-Management-Framework-RMF#:

~:text=The%20Risk%20Management%20Framework%20is,of%20the%20United%20States%20government

.

430 W5 DQ1 RESPONSES CONTINUATION

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

B Cody

Hello everyone,

“The Risk Management Framework is a template and guideline used by companies to identify, eliminate and minimize risks. It was originally developed by the National Institute of Standards and Technology to help protect the information systems of the United States government” (Posey, 2021). The Risk Management Framework is simply used periodically to identify and organize risks to an organization. The National Institute of Standards and Technology also created the Cybersecurity Framework. “The Framework integrates industry standards and best practices to help organizations manage their cybersecurity risks” (Swenson, 2022). These are very similar in that they both were created by NIST to help organizations identify, categorize, and to help mitigate risks but they are different in that The Risk Management Framework deals with more overarching risks regarding organizations and the Cybersecurity Framework deals only specifically with cybersecurity threats. I would recommend for an organization to use all of these frameworks since the Cybersecurity Framework would deal with cybersecurity threats and the RMF would cover strategic, legal, operational, and privacy risks.

C Jacob

Good evening Professor Ligon and class,

Risk Management Framework (RMF) is an established set of components (Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance) and steps (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor) that help companies to identify, eliminate, and minimize risks. These guidelines were originally created by the National Institute of Standards and Technology (NIST) to help protect information systems within the U.S. “Businesses cannot exist without exposing themselves to risks such as IT problems, litigation, and loss of capital” (Posey, 2021). No risk can be totally gotten rid of, there will always be a need for risks. All we can do is mitigate them. This concept benefits businesses by minimizing the risks that are out there which in end lowers the legal spotlight and increases profits.   

Cyber Security Framework (CSF) and RMF are often mixed around when IT professionals are discussing them. When RMF was originally created by NIST, its target audience was the federal government. This is still true today, although private organizations have seen the benefits of RMF and have started to incorporate the guideline into their IT plans. CSF has been created for more critical infrastructures, such as transportation or public utilities. CSF is also suitable for an “Organization of any size, degree of cybersecurity risk, or cybersecurity sophistication” (Webb, 2017). CSF has not been created to replace RMF, it is another tool that organizations have at their disposal to deal with risks associated with the IT field.

430 W5 DQ1

Briefly describe the purpose and application of the Risk Management Framework. How does this differ from the Cyber Security Framework? Which would you recommend and why?

Reply to responses.

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

A Aaron

Evening,

The Risk Management Framework (RMF) was first intended for federal agencies but soon was adopted by organization that were in the private sector. A business can’t operate with out exposing themselves to so sort of risks like IT problems, Litigation and Loss of Capitol (Posey, 2021). The RMF is made up of five components, that are Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance. The Identification stage is to identify the risks that an organization might have, and this process is not a one-time thing as these risks might change over time. Measurement and assessment are when you create a risk profile for each that was identified in the first step and the measurement can be in the form of how much capital could be lost. Mitigation is by examining the risks and determining which risks should be eliminated and which risks are acceptable. Reporting and monitoring involves reexamining the risks to make sure the mitigation strategies the organization have adopted are serving their purposes. Governance is the process of making sure the adoption of the mitigation strategies is in place and that the employees are following the policies. RMF is more targeted towards the federal government and CSF was originally developed for critical infrastructure but has been recommended for use in organizations. CSF is aimed towards the private sector more than the federal government and does not have any Authorizing Officials (AOs) or an Authority to Operate (ATO) which RMF has ATOs to determine the authorized periods required for approval by and AO. NIST recommends that the CSF be used to strengthen the RMF. I would say that I would use the RMF to first get the framework in place then start implementing the CSF. Both of the frameworks have two entirely different end goals.

Posey, B. (2021) What is risk management and why is it important? Retrieved from 

https://www.techtarget.com/searchcio/definition/Risk-Management-Framework-RMF#:

~:text=The%20Risk%20Management%20Framework%20is,of%20the%20United%20States%20government

.

430 W5 DQ1 RESPONSES CONTINUATION

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

B Cody

Hello everyone,

“The Risk Management Framework is a template and guideline used by companies to identify, eliminate and minimize risks. It was originally developed by the National Institute of Standards and Technology to help protect the information systems of the United States government” (Posey, 2021). The Risk Management Framework is simply used periodically to identify and organize risks to an organization. The National Institute of Standards and Technology also created the Cybersecurity Framework. “The Framework integrates industry standards and best practices to help organizations manage their cybersecurity risks” (Swenson, 2022). These are very similar in that they both were created by NIST to help organizations identify, categorize, and to help mitigate risks but they are different in that The Risk Management Framework deals with more overarching risks regarding organizations and the Cybersecurity Framework deals only specifically with cybersecurity threats. I would recommend for an organization to use all of these frameworks since the Cybersecurity Framework would deal with cybersecurity threats and the RMF would cover strategic, legal, operational, and privacy risks.

C Jacob

Good evening Professor Ligon and class,

Risk Management Framework (RMF) is an established set of components (Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance) and steps (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor) that help companies to identify, eliminate, and minimize risks. These guidelines were originally created by the National Institute of Standards and Technology (NIST) to help protect information systems within the U.S. “Businesses cannot exist without exposing themselves to risks such as IT problems, litigation, and loss of capital” (Posey, 2021). No risk can be totally gotten rid of, there will always be a need for risks. All we can do is mitigate them. This concept benefits businesses by minimizing the risks that are out there which in end lowers the legal spotlight and increases profits.   

Cyber Security Framework (CSF) and RMF are often mixed around when IT professionals are discussing them. When RMF was originally created by NIST, its target audience was the federal government. This is still true today, although private organizations have seen the benefits of RMF and have started to incorporate the guideline into their IT plans. CSF has been created for more critical infrastructures, such as transportation or public utilities. CSF is also suitable for an “Organization of any size, degree of cybersecurity risk, or cybersecurity sophistication” (Webb, 2017). CSF has not been created to replace RMF, it is another tool that organizations have at their disposal to deal with risks associated with the IT field.

430 W5 DQ1

Briefly describe the purpose and application of the Risk Management Framework. How does this differ from the Cyber Security Framework? Which would you recommend and why?

Reply to responses.

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

A Aaron

Evening,

The Risk Management Framework (RMF) was first intended for federal agencies but soon was adopted by organization that were in the private sector. A business can’t operate with out exposing themselves to so sort of risks like IT problems, Litigation and Loss of Capitol (Posey, 2021). The RMF is made up of five components, that are Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance. The Identification stage is to identify the risks that an organization might have, and this process is not a one-time thing as these risks might change over time. Measurement and assessment are when you create a risk profile for each that was identified in the first step and the measurement can be in the form of how much capital could be lost. Mitigation is by examining the risks and determining which risks should be eliminated and which risks are acceptable. Reporting and monitoring involves reexamining the risks to make sure the mitigation strategies the organization have adopted are serving their purposes. Governance is the process of making sure the adoption of the mitigation strategies is in place and that the employees are following the policies. RMF is more targeted towards the federal government and CSF was originally developed for critical infrastructure but has been recommended for use in organizations. CSF is aimed towards the private sector more than the federal government and does not have any Authorizing Officials (AOs) or an Authority to Operate (ATO) which RMF has ATOs to determine the authorized periods required for approval by and AO. NIST recommends that the CSF be used to strengthen the RMF. I would say that I would use the RMF to first get the framework in place then start implementing the CSF. Both of the frameworks have two entirely different end goals.

Posey, B. (2021) What is risk management and why is it important? Retrieved from 

https://www.techtarget.com/searchcio/definition/Risk-Management-Framework-RMF#:

~:text=The%20Risk%20Management%20Framework%20is,of%20the%20United%20States%20government

.

430 W5 DQ1 RESPONSES CONTINUATION

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

B Cody

Hello everyone,

“The Risk Management Framework is a template and guideline used by companies to identify, eliminate and minimize risks. It was originally developed by the National Institute of Standards and Technology to help protect the information systems of the United States government” (Posey, 2021). The Risk Management Framework is simply used periodically to identify and organize risks to an organization. The National Institute of Standards and Technology also created the Cybersecurity Framework. “The Framework integrates industry standards and best practices to help organizations manage their cybersecurity risks” (Swenson, 2022). These are very similar in that they both were created by NIST to help organizations identify, categorize, and to help mitigate risks but they are different in that The Risk Management Framework deals with more overarching risks regarding organizations and the Cybersecurity Framework deals only specifically with cybersecurity threats. I would recommend for an organization to use all of these frameworks since the Cybersecurity Framework would deal with cybersecurity threats and the RMF would cover strategic, legal, operational, and privacy risks.

C Jacob

Good evening Professor Ligon and class,

Risk Management Framework (RMF) is an established set of components (Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance) and steps (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor) that help companies to identify, eliminate, and minimize risks. These guidelines were originally created by the National Institute of Standards and Technology (NIST) to help protect information systems within the U.S. “Businesses cannot exist without exposing themselves to risks such as IT problems, litigation, and loss of capital” (Posey, 2021). No risk can be totally gotten rid of, there will always be a need for risks. All we can do is mitigate them. This concept benefits businesses by minimizing the risks that are out there which in end lowers the legal spotlight and increases profits.   

Cyber Security Framework (CSF) and RMF are often mixed around when IT professionals are discussing them. When RMF was originally created by NIST, its target audience was the federal government. This is still true today, although private organizations have seen the benefits of RMF and have started to incorporate the guideline into their IT plans. CSF has been created for more critical infrastructures, such as transportation or public utilities. CSF is also suitable for an “Organization of any size, degree of cybersecurity risk, or cybersecurity sophistication” (Webb, 2017). CSF has not been created to replace RMF, it is another tool that organizations have at their disposal to deal with risks associated with the IT field.

430 W5 DQ1

Briefly describe the purpose and application of the Risk Management Framework. How does this differ from the Cyber Security Framework? Which would you recommend and why?

Reply to responses.

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

A Aaron

Evening,

The Risk Management Framework (RMF) was first intended for federal agencies but soon was adopted by organization that were in the private sector. A business can’t operate with out exposing themselves to so sort of risks like IT problems, Litigation and Loss of Capitol (Posey, 2021). The RMF is made up of five components, that are Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance. The Identification stage is to identify the risks that an organization might have, and this process is not a one-time thing as these risks might change over time. Measurement and assessment are when you create a risk profile for each that was identified in the first step and the measurement can be in the form of how much capital could be lost. Mitigation is by examining the risks and determining which risks should be eliminated and which risks are acceptable. Reporting and monitoring involves reexamining the risks to make sure the mitigation strategies the organization have adopted are serving their purposes. Governance is the process of making sure the adoption of the mitigation strategies is in place and that the employees are following the policies. RMF is more targeted towards the federal government and CSF was originally developed for critical infrastructure but has been recommended for use in organizations. CSF is aimed towards the private sector more than the federal government and does not have any Authorizing Officials (AOs) or an Authority to Operate (ATO) which RMF has ATOs to determine the authorized periods required for approval by and AO. NIST recommends that the CSF be used to strengthen the RMF. I would say that I would use the RMF to first get the framework in place then start implementing the CSF. Both of the frameworks have two entirely different end goals.

Posey, B. (2021) What is risk management and why is it important? Retrieved from 

https://www.techtarget.com/searchcio/definition/Risk-Management-Framework-RMF#:

~:text=The%20Risk%20Management%20Framework%20is,of%20the%20United%20States%20government

.

430 W5 DQ1 RESPONSES CONTINUATION

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

B Cody

Hello everyone,

“The Risk Management Framework is a template and guideline used by companies to identify, eliminate and minimize risks. It was originally developed by the National Institute of Standards and Technology to help protect the information systems of the United States government” (Posey, 2021). The Risk Management Framework is simply used periodically to identify and organize risks to an organization. The National Institute of Standards and Technology also created the Cybersecurity Framework. “The Framework integrates industry standards and best practices to help organizations manage their cybersecurity risks” (Swenson, 2022). These are very similar in that they both were created by NIST to help organizations identify, categorize, and to help mitigate risks but they are different in that The Risk Management Framework deals with more overarching risks regarding organizations and the Cybersecurity Framework deals only specifically with cybersecurity threats. I would recommend for an organization to use all of these frameworks since the Cybersecurity Framework would deal with cybersecurity threats and the RMF would cover strategic, legal, operational, and privacy risks.

C Jacob

Good evening Professor Ligon and class,

Risk Management Framework (RMF) is an established set of components (Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance) and steps (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor) that help companies to identify, eliminate, and minimize risks. These guidelines were originally created by the National Institute of Standards and Technology (NIST) to help protect information systems within the U.S. “Businesses cannot exist without exposing themselves to risks such as IT problems, litigation, and loss of capital” (Posey, 2021). No risk can be totally gotten rid of, there will always be a need for risks. All we can do is mitigate them. This concept benefits businesses by minimizing the risks that are out there which in end lowers the legal spotlight and increases profits.   

Cyber Security Framework (CSF) and RMF are often mixed around when IT professionals are discussing them. When RMF was originally created by NIST, its target audience was the federal government. This is still true today, although private organizations have seen the benefits of RMF and have started to incorporate the guideline into their IT plans. CSF has been created for more critical infrastructures, such as transportation or public utilities. CSF is also suitable for an “Organization of any size, degree of cybersecurity risk, or cybersecurity sophistication” (Webb, 2017). CSF has not been created to replace RMF, it is another tool that organizations have at their disposal to deal with risks associated with the IT field.

430 W5 DQ1

Briefly describe the purpose and application of the Risk Management Framework. How does this differ from the Cyber Security Framework? Which would you recommend and why?

Reply to responses.

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

A Aaron

Evening,

The Risk Management Framework (RMF) was first intended for federal agencies but soon was adopted by organization that were in the private sector. A business can’t operate with out exposing themselves to so sort of risks like IT problems, Litigation and Loss of Capitol (Posey, 2021). The RMF is made up of five components, that are Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance. The Identification stage is to identify the risks that an organization might have, and this process is not a one-time thing as these risks might change over time. Measurement and assessment are when you create a risk profile for each that was identified in the first step and the measurement can be in the form of how much capital could be lost. Mitigation is by examining the risks and determining which risks should be eliminated and which risks are acceptable. Reporting and monitoring involves reexamining the risks to make sure the mitigation strategies the organization have adopted are serving their purposes. Governance is the process of making sure the adoption of the mitigation strategies is in place and that the employees are following the policies. RMF is more targeted towards the federal government and CSF was originally developed for critical infrastructure but has been recommended for use in organizations. CSF is aimed towards the private sector more than the federal government and does not have any Authorizing Officials (AOs) or an Authority to Operate (ATO) which RMF has ATOs to determine the authorized periods required for approval by and AO. NIST recommends that the CSF be used to strengthen the RMF. I would say that I would use the RMF to first get the framework in place then start implementing the CSF. Both of the frameworks have two entirely different end goals.

Posey, B. (2021) What is risk management and why is it important? Retrieved from 

https://www.techtarget.com/searchcio/definition/Risk-Management-Framework-RMF#:

~:text=The%20Risk%20Management%20Framework%20is,of%20the%20United%20States%20government

.

430 W5 DQ1 RESPONSES CONTINUATION

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

B Cody

Hello everyone,

“The Risk Management Framework is a template and guideline used by companies to identify, eliminate and minimize risks. It was originally developed by the National Institute of Standards and Technology to help protect the information systems of the United States government” (Posey, 2021). The Risk Management Framework is simply used periodically to identify and organize risks to an organization. The National Institute of Standards and Technology also created the Cybersecurity Framework. “The Framework integrates industry standards and best practices to help organizations manage their cybersecurity risks” (Swenson, 2022). These are very similar in that they both were created by NIST to help organizations identify, categorize, and to help mitigate risks but they are different in that The Risk Management Framework deals with more overarching risks regarding organizations and the Cybersecurity Framework deals only specifically with cybersecurity threats. I would recommend for an organization to use all of these frameworks since the Cybersecurity Framework would deal with cybersecurity threats and the RMF would cover strategic, legal, operational, and privacy risks.

C Jacob

Good evening Professor Ligon and class,

Risk Management Framework (RMF) is an established set of components (Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance) and steps (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor) that help companies to identify, eliminate, and minimize risks. These guidelines were originally created by the National Institute of Standards and Technology (NIST) to help protect information systems within the U.S. “Businesses cannot exist without exposing themselves to risks such as IT problems, litigation, and loss of capital” (Posey, 2021). No risk can be totally gotten rid of, there will always be a need for risks. All we can do is mitigate them. This concept benefits businesses by minimizing the risks that are out there which in end lowers the legal spotlight and increases profits.   

Cyber Security Framework (CSF) and RMF are often mixed around when IT professionals are discussing them. When RMF was originally created by NIST, its target audience was the federal government. This is still true today, although private organizations have seen the benefits of RMF and have started to incorporate the guideline into their IT plans. CSF has been created for more critical infrastructures, such as transportation or public utilities. CSF is also suitable for an “Organization of any size, degree of cybersecurity risk, or cybersecurity sophistication” (Webb, 2017). CSF has not been created to replace RMF, it is another tool that organizations have at their disposal to deal with risks associated with the IT field.

430 W5 DQ1

Briefly describe the purpose and application of the Risk Management Framework. How does this differ from the Cyber Security Framework? Which would you recommend and why?

Reply to responses.

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

A Aaron

Evening,

The Risk Management Framework (RMF) was first intended for federal agencies but soon was adopted by organization that were in the private sector. A business can’t operate with out exposing themselves to so sort of risks like IT problems, Litigation and Loss of Capitol (Posey, 2021). The RMF is made up of five components, that are Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance. The Identification stage is to identify the risks that an organization might have, and this process is not a one-time thing as these risks might change over time. Measurement and assessment are when you create a risk profile for each that was identified in the first step and the measurement can be in the form of how much capital could be lost. Mitigation is by examining the risks and determining which risks should be eliminated and which risks are acceptable. Reporting and monitoring involves reexamining the risks to make sure the mitigation strategies the organization have adopted are serving their purposes. Governance is the process of making sure the adoption of the mitigation strategies is in place and that the employees are following the policies. RMF is more targeted towards the federal government and CSF was originally developed for critical infrastructure but has been recommended for use in organizations. CSF is aimed towards the private sector more than the federal government and does not have any Authorizing Officials (AOs) or an Authority to Operate (ATO) which RMF has ATOs to determine the authorized periods required for approval by and AO. NIST recommends that the CSF be used to strengthen the RMF. I would say that I would use the RMF to first get the framework in place then start implementing the CSF. Both of the frameworks have two entirely different end goals.

Posey, B. (2021) What is risk management and why is it important? Retrieved from 

https://www.techtarget.com/searchcio/definition/Risk-Management-Framework-RMF#:

~:text=The%20Risk%20Management%20Framework%20is,of%20the%20United%20States%20government

.

430 W5 DQ1 RESPONSES CONTINUATION

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

B Cody

Hello everyone,

“The Risk Management Framework is a template and guideline used by companies to identify, eliminate and minimize risks. It was originally developed by the National Institute of Standards and Technology to help protect the information systems of the United States government” (Posey, 2021). The Risk Management Framework is simply used periodically to identify and organize risks to an organization. The National Institute of Standards and Technology also created the Cybersecurity Framework. “The Framework integrates industry standards and best practices to help organizations manage their cybersecurity risks” (Swenson, 2022). These are very similar in that they both were created by NIST to help organizations identify, categorize, and to help mitigate risks but they are different in that The Risk Management Framework deals with more overarching risks regarding organizations and the Cybersecurity Framework deals only specifically with cybersecurity threats. I would recommend for an organization to use all of these frameworks since the Cybersecurity Framework would deal with cybersecurity threats and the RMF would cover strategic, legal, operational, and privacy risks.

C Jacob

Good evening Professor Ligon and class,

Risk Management Framework (RMF) is an established set of components (Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance) and steps (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor) that help companies to identify, eliminate, and minimize risks. These guidelines were originally created by the National Institute of Standards and Technology (NIST) to help protect information systems within the U.S. “Businesses cannot exist without exposing themselves to risks such as IT problems, litigation, and loss of capital” (Posey, 2021). No risk can be totally gotten rid of, there will always be a need for risks. All we can do is mitigate them. This concept benefits businesses by minimizing the risks that are out there which in end lowers the legal spotlight and increases profits.   

Cyber Security Framework (CSF) and RMF are often mixed around when IT professionals are discussing them. When RMF was originally created by NIST, its target audience was the federal government. This is still true today, although private organizations have seen the benefits of RMF and have started to incorporate the guideline into their IT plans. CSF has been created for more critical infrastructures, such as transportation or public utilities. CSF is also suitable for an “Organization of any size, degree of cybersecurity risk, or cybersecurity sophistication” (Webb, 2017). CSF has not been created to replace RMF, it is another tool that organizations have at their disposal to deal with risks associated with the IT field.

430 W5 DQ1

Briefly describe the purpose and application of the Risk Management Framework. How does this differ from the Cyber Security Framework? Which would you recommend and why?

Reply to responses.

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

A Aaron

Evening,

The Risk Management Framework (RMF) was first intended for federal agencies but soon was adopted by organization that were in the private sector. A business can’t operate with out exposing themselves to so sort of risks like IT problems, Litigation and Loss of Capitol (Posey, 2021). The RMF is made up of five components, that are Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance. The Identification stage is to identify the risks that an organization might have, and this process is not a one-time thing as these risks might change over time. Measurement and assessment are when you create a risk profile for each that was identified in the first step and the measurement can be in the form of how much capital could be lost. Mitigation is by examining the risks and determining which risks should be eliminated and which risks are acceptable. Reporting and monitoring involves reexamining the risks to make sure the mitigation strategies the organization have adopted are serving their purposes. Governance is the process of making sure the adoption of the mitigation strategies is in place and that the employees are following the policies. RMF is more targeted towards the federal government and CSF was originally developed for critical infrastructure but has been recommended for use in organizations. CSF is aimed towards the private sector more than the federal government and does not have any Authorizing Officials (AOs) or an Authority to Operate (ATO) which RMF has ATOs to determine the authorized periods required for approval by and AO. NIST recommends that the CSF be used to strengthen the RMF. I would say that I would use the RMF to first get the framework in place then start implementing the CSF. Both of the frameworks have two entirely different end goals.

Posey, B. (2021) What is risk management and why is it important? Retrieved from 

https://www.techtarget.com/searchcio/definition/Risk-Management-Framework-RMF#:

~:text=The%20Risk%20Management%20Framework%20is,of%20the%20United%20States%20government

.

430 W5 DQ1 RESPONSES CONTINUATION

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

B Cody

Hello everyone,

“The Risk Management Framework is a template and guideline used by companies to identify, eliminate and minimize risks. It was originally developed by the National Institute of Standards and Technology to help protect the information systems of the United States government” (Posey, 2021). The Risk Management Framework is simply used periodically to identify and organize risks to an organization. The National Institute of Standards and Technology also created the Cybersecurity Framework. “The Framework integrates industry standards and best practices to help organizations manage their cybersecurity risks” (Swenson, 2022). These are very similar in that they both were created by NIST to help organizations identify, categorize, and to help mitigate risks but they are different in that The Risk Management Framework deals with more overarching risks regarding organizations and the Cybersecurity Framework deals only specifically with cybersecurity threats. I would recommend for an organization to use all of these frameworks since the Cybersecurity Framework would deal with cybersecurity threats and the RMF would cover strategic, legal, operational, and privacy risks.

C Jacob

Good evening Professor Ligon and class,

Risk Management Framework (RMF) is an established set of components (Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance) and steps (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor) that help companies to identify, eliminate, and minimize risks. These guidelines were originally created by the National Institute of Standards and Technology (NIST) to help protect information systems within the U.S. “Businesses cannot exist without exposing themselves to risks such as IT problems, litigation, and loss of capital” (Posey, 2021). No risk can be totally gotten rid of, there will always be a need for risks. All we can do is mitigate them. This concept benefits businesses by minimizing the risks that are out there which in end lowers the legal spotlight and increases profits.   

Cyber Security Framework (CSF) and RMF are often mixed around when IT professionals are discussing them. When RMF was originally created by NIST, its target audience was the federal government. This is still true today, although private organizations have seen the benefits of RMF and have started to incorporate the guideline into their IT plans. CSF has been created for more critical infrastructures, such as transportation or public utilities. CSF is also suitable for an “Organization of any size, degree of cybersecurity risk, or cybersecurity sophistication” (Webb, 2017). CSF has not been created to replace RMF, it is another tool that organizations have at their disposal to deal with risks associated with the IT field.

430 W5 DQ1

Briefly describe the purpose and application of the Risk Management Framework. How does this differ from the Cyber Security Framework? Which would you recommend and why?

Reply to responses.

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

A Aaron

Evening,

The Risk Management Framework (RMF) was first intended for federal agencies but soon was adopted by organization that were in the private sector. A business can’t operate with out exposing themselves to so sort of risks like IT problems, Litigation and Loss of Capitol (Posey, 2021). The RMF is made up of five components, that are Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance. The Identification stage is to identify the risks that an organization might have, and this process is not a one-time thing as these risks might change over time. Measurement and assessment are when you create a risk profile for each that was identified in the first step and the measurement can be in the form of how much capital could be lost. Mitigation is by examining the risks and determining which risks should be eliminated and which risks are acceptable. Reporting and monitoring involves reexamining the risks to make sure the mitigation strategies the organization have adopted are serving their purposes. Governance is the process of making sure the adoption of the mitigation strategies is in place and that the employees are following the policies. RMF is more targeted towards the federal government and CSF was originally developed for critical infrastructure but has been recommended for use in organizations. CSF is aimed towards the private sector more than the federal government and does not have any Authorizing Officials (AOs) or an Authority to Operate (ATO) which RMF has ATOs to determine the authorized periods required for approval by and AO. NIST recommends that the CSF be used to strengthen the RMF. I would say that I would use the RMF to first get the framework in place then start implementing the CSF. Both of the frameworks have two entirely different end goals.

Posey, B. (2021) What is risk management and why is it important? Retrieved from 

https://www.techtarget.com/searchcio/definition/Risk-Management-Framework-RMF#:

~:text=The%20Risk%20Management%20Framework%20is,of%20the%20United%20States%20government

.

430 W5 DQ1 RESPONSES CONTINUATION

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

B Cody

Hello everyone,

“The Risk Management Framework is a template and guideline used by companies to identify, eliminate and minimize risks. It was originally developed by the National Institute of Standards and Technology to help protect the information systems of the United States government” (Posey, 2021). The Risk Management Framework is simply used periodically to identify and organize risks to an organization. The National Institute of Standards and Technology also created the Cybersecurity Framework. “The Framework integrates industry standards and best practices to help organizations manage their cybersecurity risks” (Swenson, 2022). These are very similar in that they both were created by NIST to help organizations identify, categorize, and to help mitigate risks but they are different in that The Risk Management Framework deals with more overarching risks regarding organizations and the Cybersecurity Framework deals only specifically with cybersecurity threats. I would recommend for an organization to use all of these frameworks since the Cybersecurity Framework would deal with cybersecurity threats and the RMF would cover strategic, legal, operational, and privacy risks.

C Jacob

Good evening Professor Ligon and class,

Risk Management Framework (RMF) is an established set of components (Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance) and steps (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor) that help companies to identify, eliminate, and minimize risks. These guidelines were originally created by the National Institute of Standards and Technology (NIST) to help protect information systems within the U.S. “Businesses cannot exist without exposing themselves to risks such as IT problems, litigation, and loss of capital” (Posey, 2021). No risk can be totally gotten rid of, there will always be a need for risks. All we can do is mitigate them. This concept benefits businesses by minimizing the risks that are out there which in end lowers the legal spotlight and increases profits.   

Cyber Security Framework (CSF) and RMF are often mixed around when IT professionals are discussing them. When RMF was originally created by NIST, its target audience was the federal government. This is still true today, although private organizations have seen the benefits of RMF and have started to incorporate the guideline into their IT plans. CSF has been created for more critical infrastructures, such as transportation or public utilities. CSF is also suitable for an “Organization of any size, degree of cybersecurity risk, or cybersecurity sophistication” (Webb, 2017). CSF has not been created to replace RMF, it is another tool that organizations have at their disposal to deal with risks associated with the IT field.

430 W5 DQ1

Briefly describe the purpose and application of the Risk Management Framework. How does this differ from the Cyber Security Framework? Which would you recommend and why?

Reply to responses.

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

A Aaron

Evening,

The Risk Management Framework (RMF) was first intended for federal agencies but soon was adopted by organization that were in the private sector. A business can’t operate with out exposing themselves to so sort of risks like IT problems, Litigation and Loss of Capitol (Posey, 2021). The RMF is made up of five components, that are Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance. The Identification stage is to identify the risks that an organization might have, and this process is not a one-time thing as these risks might change over time. Measurement and assessment are when you create a risk profile for each that was identified in the first step and the measurement can be in the form of how much capital could be lost. Mitigation is by examining the risks and determining which risks should be eliminated and which risks are acceptable. Reporting and monitoring involves reexamining the risks to make sure the mitigation strategies the organization have adopted are serving their purposes. Governance is the process of making sure the adoption of the mitigation strategies is in place and that the employees are following the policies. RMF is more targeted towards the federal government and CSF was originally developed for critical infrastructure but has been recommended for use in organizations. CSF is aimed towards the private sector more than the federal government and does not have any Authorizing Officials (AOs) or an Authority to Operate (ATO) which RMF has ATOs to determine the authorized periods required for approval by and AO. NIST recommends that the CSF be used to strengthen the RMF. I would say that I would use the RMF to first get the framework in place then start implementing the CSF. Both of the frameworks have two entirely different end goals.

Posey, B. (2021) What is risk management and why is it important? Retrieved from 

https://www.techtarget.com/searchcio/definition/Risk-Management-Framework-RMF#:

~:text=The%20Risk%20Management%20Framework%20is,of%20the%20United%20States%20government

.

430 W5 DQ1 RESPONSES CONTINUATION

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

B Cody

Hello everyone,

“The Risk Management Framework is a template and guideline used by companies to identify, eliminate and minimize risks. It was originally developed by the National Institute of Standards and Technology to help protect the information systems of the United States government” (Posey, 2021). The Risk Management Framework is simply used periodically to identify and organize risks to an organization. The National Institute of Standards and Technology also created the Cybersecurity Framework. “The Framework integrates industry standards and best practices to help organizations manage their cybersecurity risks” (Swenson, 2022). These are very similar in that they both were created by NIST to help organizations identify, categorize, and to help mitigate risks but they are different in that The Risk Management Framework deals with more overarching risks regarding organizations and the Cybersecurity Framework deals only specifically with cybersecurity threats. I would recommend for an organization to use all of these frameworks since the Cybersecurity Framework would deal with cybersecurity threats and the RMF would cover strategic, legal, operational, and privacy risks.

C Jacob

Good evening Professor Ligon and class,

Risk Management Framework (RMF) is an established set of components (Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance) and steps (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor) that help companies to identify, eliminate, and minimize risks. These guidelines were originally created by the National Institute of Standards and Technology (NIST) to help protect information systems within the U.S. “Businesses cannot exist without exposing themselves to risks such as IT problems, litigation, and loss of capital” (Posey, 2021). No risk can be totally gotten rid of, there will always be a need for risks. All we can do is mitigate them. This concept benefits businesses by minimizing the risks that are out there which in end lowers the legal spotlight and increases profits.   

Cyber Security Framework (CSF) and RMF are often mixed around when IT professionals are discussing them. When RMF was originally created by NIST, its target audience was the federal government. This is still true today, although private organizations have seen the benefits of RMF and have started to incorporate the guideline into their IT plans. CSF has been created for more critical infrastructures, such as transportation or public utilities. CSF is also suitable for an “Organization of any size, degree of cybersecurity risk, or cybersecurity sophistication” (Webb, 2017). CSF has not been created to replace RMF, it is another tool that organizations have at their disposal to deal with risks associated with the IT field.

430 W5 DQ1

Briefly describe the purpose and application of the Risk Management Framework. How does this differ from the Cyber Security Framework? Which would you recommend and why?

Reply to responses.

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

A Aaron

Evening,

The Risk Management Framework (RMF) was first intended for federal agencies but soon was adopted by organization that were in the private sector. A business can’t operate with out exposing themselves to so sort of risks like IT problems, Litigation and Loss of Capitol (Posey, 2021). The RMF is made up of five components, that are Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance. The Identification stage is to identify the risks that an organization might have, and this process is not a one-time thing as these risks might change over time. Measurement and assessment are when you create a risk profile for each that was identified in the first step and the measurement can be in the form of how much capital could be lost. Mitigation is by examining the risks and determining which risks should be eliminated and which risks are acceptable. Reporting and monitoring involves reexamining the risks to make sure the mitigation strategies the organization have adopted are serving their purposes. Governance is the process of making sure the adoption of the mitigation strategies is in place and that the employees are following the policies. RMF is more targeted towards the federal government and CSF was originally developed for critical infrastructure but has been recommended for use in organizations. CSF is aimed towards the private sector more than the federal government and does not have any Authorizing Officials (AOs) or an Authority to Operate (ATO) which RMF has ATOs to determine the authorized periods required for approval by and AO. NIST recommends that the CSF be used to strengthen the RMF. I would say that I would use the RMF to first get the framework in place then start implementing the CSF. Both of the frameworks have two entirely different end goals.

Posey, B. (2021) What is risk management and why is it important? Retrieved from 

https://www.techtarget.com/searchcio/definition/Risk-Management-Framework-RMF#:

~:text=The%20Risk%20Management%20Framework%20is,of%20the%20United%20States%20government

.

430 W5 DQ1 RESPONSES CONTINUATION

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

B Cody

Hello everyone,

“The Risk Management Framework is a template and guideline used by companies to identify, eliminate and minimize risks. It was originally developed by the National Institute of Standards and Technology to help protect the information systems of the United States government” (Posey, 2021). The Risk Management Framework is simply used periodically to identify and organize risks to an organization. The National Institute of Standards and Technology also created the Cybersecurity Framework. “The Framework integrates industry standards and best practices to help organizations manage their cybersecurity risks” (Swenson, 2022). These are very similar in that they both were created by NIST to help organizations identify, categorize, and to help mitigate risks but they are different in that The Risk Management Framework deals with more overarching risks regarding organizations and the Cybersecurity Framework deals only specifically with cybersecurity threats. I would recommend for an organization to use all of these frameworks since the Cybersecurity Framework would deal with cybersecurity threats and the RMF would cover strategic, legal, operational, and privacy risks.

C Jacob

Good evening Professor Ligon and class,

Risk Management Framework (RMF) is an established set of components (Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance) and steps (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor) that help companies to identify, eliminate, and minimize risks. These guidelines were originally created by the National Institute of Standards and Technology (NIST) to help protect information systems within the U.S. “Businesses cannot exist without exposing themselves to risks such as IT problems, litigation, and loss of capital” (Posey, 2021). No risk can be totally gotten rid of, there will always be a need for risks. All we can do is mitigate them. This concept benefits businesses by minimizing the risks that are out there which in end lowers the legal spotlight and increases profits.   

Cyber Security Framework (CSF) and RMF are often mixed around when IT professionals are discussing them. When RMF was originally created by NIST, its target audience was the federal government. This is still true today, although private organizations have seen the benefits of RMF and have started to incorporate the guideline into their IT plans. CSF has been created for more critical infrastructures, such as transportation or public utilities. CSF is also suitable for an “Organization of any size, degree of cybersecurity risk, or cybersecurity sophistication” (Webb, 2017). CSF has not been created to replace RMF, it is another tool that organizations have at their disposal to deal with risks associated with the IT field.

430 W5 DQ1

Briefly describe the purpose and application of the Risk Management Framework. How does this differ from the Cyber Security Framework? Which would you recommend and why?

Reply to responses.

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

A Aaron

Evening,

The Risk Management Framework (RMF) was first intended for federal agencies but soon was adopted by organization that were in the private sector. A business can’t operate with out exposing themselves to so sort of risks like IT problems, Litigation and Loss of Capitol (Posey, 2021). The RMF is made up of five components, that are Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance. The Identification stage is to identify the risks that an organization might have, and this process is not a one-time thing as these risks might change over time. Measurement and assessment are when you create a risk profile for each that was identified in the first step and the measurement can be in the form of how much capital could be lost. Mitigation is by examining the risks and determining which risks should be eliminated and which risks are acceptable. Reporting and monitoring involves reexamining the risks to make sure the mitigation strategies the organization have adopted are serving their purposes. Governance is the process of making sure the adoption of the mitigation strategies is in place and that the employees are following the policies. RMF is more targeted towards the federal government and CSF was originally developed for critical infrastructure but has been recommended for use in organizations. CSF is aimed towards the private sector more than the federal government and does not have any Authorizing Officials (AOs) or an Authority to Operate (ATO) which RMF has ATOs to determine the authorized periods required for approval by and AO. NIST recommends that the CSF be used to strengthen the RMF. I would say that I would use the RMF to first get the framework in place then start implementing the CSF. Both of the frameworks have two entirely different end goals.

Posey, B. (2021) What is risk management and why is it important? Retrieved from 

https://www.techtarget.com/searchcio/definition/Risk-Management-Framework-RMF#:

~:text=The%20Risk%20Management%20Framework%20is,of%20the%20United%20States%20government

.

430 W5 DQ1 RESPONSES CONTINUATION

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

B Cody

Hello everyone,

“The Risk Management Framework is a template and guideline used by companies to identify, eliminate and minimize risks. It was originally developed by the National Institute of Standards and Technology to help protect the information systems of the United States government” (Posey, 2021). The Risk Management Framework is simply used periodically to identify and organize risks to an organization. The National Institute of Standards and Technology also created the Cybersecurity Framework. “The Framework integrates industry standards and best practices to help organizations manage their cybersecurity risks” (Swenson, 2022). These are very similar in that they both were created by NIST to help organizations identify, categorize, and to help mitigate risks but they are different in that The Risk Management Framework deals with more overarching risks regarding organizations and the Cybersecurity Framework deals only specifically with cybersecurity threats. I would recommend for an organization to use all of these frameworks since the Cybersecurity Framework would deal with cybersecurity threats and the RMF would cover strategic, legal, operational, and privacy risks.

C Jacob

Good evening Professor Ligon and class,

Risk Management Framework (RMF) is an established set of components (Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance) and steps (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor) that help companies to identify, eliminate, and minimize risks. These guidelines were originally created by the National Institute of Standards and Technology (NIST) to help protect information systems within the U.S. “Businesses cannot exist without exposing themselves to risks such as IT problems, litigation, and loss of capital” (Posey, 2021). No risk can be totally gotten rid of, there will always be a need for risks. All we can do is mitigate them. This concept benefits businesses by minimizing the risks that are out there which in end lowers the legal spotlight and increases profits.   

Cyber Security Framework (CSF) and RMF are often mixed around when IT professionals are discussing them. When RMF was originally created by NIST, its target audience was the federal government. This is still true today, although private organizations have seen the benefits of RMF and have started to incorporate the guideline into their IT plans. CSF has been created for more critical infrastructures, such as transportation or public utilities. CSF is also suitable for an “Organization of any size, degree of cybersecurity risk, or cybersecurity sophistication” (Webb, 2017). CSF has not been created to replace RMF, it is another tool that organizations have at their disposal to deal with risks associated with the IT field.

430 W5 DQ1

Briefly describe the purpose and application of the Risk Management Framework. How does this differ from the Cyber Security Framework? Which would you recommend and why?

Reply to responses.

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

A Aaron

Evening,

The Risk Management Framework (RMF) was first intended for federal agencies but soon was adopted by organization that were in the private sector. A business can’t operate with out exposing themselves to so sort of risks like IT problems, Litigation and Loss of Capitol (Posey, 2021). The RMF is made up of five components, that are Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance. The Identification stage is to identify the risks that an organization might have, and this process is not a one-time thing as these risks might change over time. Measurement and assessment are when you create a risk profile for each that was identified in the first step and the measurement can be in the form of how much capital could be lost. Mitigation is by examining the risks and determining which risks should be eliminated and which risks are acceptable. Reporting and monitoring involves reexamining the risks to make sure the mitigation strategies the organization have adopted are serving their purposes. Governance is the process of making sure the adoption of the mitigation strategies is in place and that the employees are following the policies. RMF is more targeted towards the federal government and CSF was originally developed for critical infrastructure but has been recommended for use in organizations. CSF is aimed towards the private sector more than the federal government and does not have any Authorizing Officials (AOs) or an Authority to Operate (ATO) which RMF has ATOs to determine the authorized periods required for approval by and AO. NIST recommends that the CSF be used to strengthen the RMF. I would say that I would use the RMF to first get the framework in place then start implementing the CSF. Both of the frameworks have two entirely different end goals.

Posey, B. (2021) What is risk management and why is it important? Retrieved from 

https://www.techtarget.com/searchcio/definition/Risk-Management-Framework-RMF#:

~:text=The%20Risk%20Management%20Framework%20is,of%20the%20United%20States%20government

.

430 W5 DQ1 RESPONSES CONTINUATION

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

B Cody

Hello everyone,

“The Risk Management Framework is a template and guideline used by companies to identify, eliminate and minimize risks. It was originally developed by the National Institute of Standards and Technology to help protect the information systems of the United States government” (Posey, 2021). The Risk Management Framework is simply used periodically to identify and organize risks to an organization. The National Institute of Standards and Technology also created the Cybersecurity Framework. “The Framework integrates industry standards and best practices to help organizations manage their cybersecurity risks” (Swenson, 2022). These are very similar in that they both were created by NIST to help organizations identify, categorize, and to help mitigate risks but they are different in that The Risk Management Framework deals with more overarching risks regarding organizations and the Cybersecurity Framework deals only specifically with cybersecurity threats. I would recommend for an organization to use all of these frameworks since the Cybersecurity Framework would deal with cybersecurity threats and the RMF would cover strategic, legal, operational, and privacy risks.

C Jacob

Good evening Professor Ligon and class,

Risk Management Framework (RMF) is an established set of components (Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance) and steps (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor) that help companies to identify, eliminate, and minimize risks. These guidelines were originally created by the National Institute of Standards and Technology (NIST) to help protect information systems within the U.S. “Businesses cannot exist without exposing themselves to risks such as IT problems, litigation, and loss of capital” (Posey, 2021). No risk can be totally gotten rid of, there will always be a need for risks. All we can do is mitigate them. This concept benefits businesses by minimizing the risks that are out there which in end lowers the legal spotlight and increases profits.   

Cyber Security Framework (CSF) and RMF are often mixed around when IT professionals are discussing them. When RMF was originally created by NIST, its target audience was the federal government. This is still true today, although private organizations have seen the benefits of RMF and have started to incorporate the guideline into their IT plans. CSF has been created for more critical infrastructures, such as transportation or public utilities. CSF is also suitable for an “Organization of any size, degree of cybersecurity risk, or cybersecurity sophistication” (Webb, 2017). CSF has not been created to replace RMF, it is another tool that organizations have at their disposal to deal with risks associated with the IT field.

430 W5 DQ1

Briefly describe the purpose and application of the Risk Management Framework. How does this differ from the Cyber Security Framework? Which would you recommend and why?

Reply to responses.

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

A Aaron

Evening,

The Risk Management Framework (RMF) was first intended for federal agencies but soon was adopted by organization that were in the private sector. A business can’t operate with out exposing themselves to so sort of risks like IT problems, Litigation and Loss of Capitol (Posey, 2021). The RMF is made up of five components, that are Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance. The Identification stage is to identify the risks that an organization might have, and this process is not a one-time thing as these risks might change over time. Measurement and assessment are when you create a risk profile for each that was identified in the first step and the measurement can be in the form of how much capital could be lost. Mitigation is by examining the risks and determining which risks should be eliminated and which risks are acceptable. Reporting and monitoring involves reexamining the risks to make sure the mitigation strategies the organization have adopted are serving their purposes. Governance is the process of making sure the adoption of the mitigation strategies is in place and that the employees are following the policies. RMF is more targeted towards the federal government and CSF was originally developed for critical infrastructure but has been recommended for use in organizations. CSF is aimed towards the private sector more than the federal government and does not have any Authorizing Officials (AOs) or an Authority to Operate (ATO) which RMF has ATOs to determine the authorized periods required for approval by and AO. NIST recommends that the CSF be used to strengthen the RMF. I would say that I would use the RMF to first get the framework in place then start implementing the CSF. Both of the frameworks have two entirely different end goals.

Posey, B. (2021) What is risk management and why is it important? Retrieved from 

https://www.techtarget.com/searchcio/definition/Risk-Management-Framework-RMF#:

~:text=The%20Risk%20Management%20Framework%20is,of%20the%20United%20States%20government

.

430 W5 DQ1 RESPONSES CONTINUATION

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

B Cody

Hello everyone,

“The Risk Management Framework is a template and guideline used by companies to identify, eliminate and minimize risks. It was originally developed by the National Institute of Standards and Technology to help protect the information systems of the United States government” (Posey, 2021). The Risk Management Framework is simply used periodically to identify and organize risks to an organization. The National Institute of Standards and Technology also created the Cybersecurity Framework. “The Framework integrates industry standards and best practices to help organizations manage their cybersecurity risks” (Swenson, 2022). These are very similar in that they both were created by NIST to help organizations identify, categorize, and to help mitigate risks but they are different in that The Risk Management Framework deals with more overarching risks regarding organizations and the Cybersecurity Framework deals only specifically with cybersecurity threats. I would recommend for an organization to use all of these frameworks since the Cybersecurity Framework would deal with cybersecurity threats and the RMF would cover strategic, legal, operational, and privacy risks.

C Jacob

Good evening Professor Ligon and class,

Risk Management Framework (RMF) is an established set of components (Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance) and steps (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor) that help companies to identify, eliminate, and minimize risks. These guidelines were originally created by the National Institute of Standards and Technology (NIST) to help protect information systems within the U.S. “Businesses cannot exist without exposing themselves to risks such as IT problems, litigation, and loss of capital” (Posey, 2021). No risk can be totally gotten rid of, there will always be a need for risks. All we can do is mitigate them. This concept benefits businesses by minimizing the risks that are out there which in end lowers the legal spotlight and increases profits.   

Cyber Security Framework (CSF) and RMF are often mixed around when IT professionals are discussing them. When RMF was originally created by NIST, its target audience was the federal government. This is still true today, although private organizations have seen the benefits of RMF and have started to incorporate the guideline into their IT plans. CSF has been created for more critical infrastructures, such as transportation or public utilities. CSF is also suitable for an “Organization of any size, degree of cybersecurity risk, or cybersecurity sophistication” (Webb, 2017). CSF has not been created to replace RMF, it is another tool that organizations have at their disposal to deal with risks associated with the IT field.

430 W5 DQ1

Briefly describe the purpose and application of the Risk Management Framework. How does this differ from the Cyber Security Framework? Which would you recommend and why?

Reply to responses.

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

A Aaron

Evening,

The Risk Management Framework (RMF) was first intended for federal agencies but soon was adopted by organization that were in the private sector. A business can’t operate with out exposing themselves to so sort of risks like IT problems, Litigation and Loss of Capitol (Posey, 2021). The RMF is made up of five components, that are Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance. The Identification stage is to identify the risks that an organization might have, and this process is not a one-time thing as these risks might change over time. Measurement and assessment are when you create a risk profile for each that was identified in the first step and the measurement can be in the form of how much capital could be lost. Mitigation is by examining the risks and determining which risks should be eliminated and which risks are acceptable. Reporting and monitoring involves reexamining the risks to make sure the mitigation strategies the organization have adopted are serving their purposes. Governance is the process of making sure the adoption of the mitigation strategies is in place and that the employees are following the policies. RMF is more targeted towards the federal government and CSF was originally developed for critical infrastructure but has been recommended for use in organizations. CSF is aimed towards the private sector more than the federal government and does not have any Authorizing Officials (AOs) or an Authority to Operate (ATO) which RMF has ATOs to determine the authorized periods required for approval by and AO. NIST recommends that the CSF be used to strengthen the RMF. I would say that I would use the RMF to first get the framework in place then start implementing the CSF. Both of the frameworks have two entirely different end goals.

Posey, B. (2021) What is risk management and why is it important? Retrieved from 

https://www.techtarget.com/searchcio/definition/Risk-Management-Framework-RMF#:

~:text=The%20Risk%20Management%20Framework%20is,of%20the%20United%20States%20government

.

430 W5 DQ1 RESPONSES CONTINUATION

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

B Cody

Hello everyone,

“The Risk Management Framework is a template and guideline used by companies to identify, eliminate and minimize risks. It was originally developed by the National Institute of Standards and Technology to help protect the information systems of the United States government” (Posey, 2021). The Risk Management Framework is simply used periodically to identify and organize risks to an organization. The National Institute of Standards and Technology also created the Cybersecurity Framework. “The Framework integrates industry standards and best practices to help organizations manage their cybersecurity risks” (Swenson, 2022). These are very similar in that they both were created by NIST to help organizations identify, categorize, and to help mitigate risks but they are different in that The Risk Management Framework deals with more overarching risks regarding organizations and the Cybersecurity Framework deals only specifically with cybersecurity threats. I would recommend for an organization to use all of these frameworks since the Cybersecurity Framework would deal with cybersecurity threats and the RMF would cover strategic, legal, operational, and privacy risks.

C Jacob

Good evening Professor Ligon and class,

Risk Management Framework (RMF) is an established set of components (Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance) and steps (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor) that help companies to identify, eliminate, and minimize risks. These guidelines were originally created by the National Institute of Standards and Technology (NIST) to help protect information systems within the U.S. “Businesses cannot exist without exposing themselves to risks such as IT problems, litigation, and loss of capital” (Posey, 2021). No risk can be totally gotten rid of, there will always be a need for risks. All we can do is mitigate them. This concept benefits businesses by minimizing the risks that are out there which in end lowers the legal spotlight and increases profits.   

Cyber Security Framework (CSF) and RMF are often mixed around when IT professionals are discussing them. When RMF was originally created by NIST, its target audience was the federal government. This is still true today, although private organizations have seen the benefits of RMF and have started to incorporate the guideline into their IT plans. CSF has been created for more critical infrastructures, such as transportation or public utilities. CSF is also suitable for an “Organization of any size, degree of cybersecurity risk, or cybersecurity sophistication” (Webb, 2017). CSF has not been created to replace RMF, it is another tool that organizations have at their disposal to deal with risks associated with the IT field.

430 W5 DQ1

Briefly describe the purpose and application of the Risk Management Framework. How does this differ from the Cyber Security Framework? Which would you recommend and why?

Reply to responses.

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

A Aaron

Evening,

The Risk Management Framework (RMF) was first intended for federal agencies but soon was adopted by organization that were in the private sector. A business can’t operate with out exposing themselves to so sort of risks like IT problems, Litigation and Loss of Capitol (Posey, 2021). The RMF is made up of five components, that are Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance. The Identification stage is to identify the risks that an organization might have, and this process is not a one-time thing as these risks might change over time. Measurement and assessment are when you create a risk profile for each that was identified in the first step and the measurement can be in the form of how much capital could be lost. Mitigation is by examining the risks and determining which risks should be eliminated and which risks are acceptable. Reporting and monitoring involves reexamining the risks to make sure the mitigation strategies the organization have adopted are serving their purposes. Governance is the process of making sure the adoption of the mitigation strategies is in place and that the employees are following the policies. RMF is more targeted towards the federal government and CSF was originally developed for critical infrastructure but has been recommended for use in organizations. CSF is aimed towards the private sector more than the federal government and does not have any Authorizing Officials (AOs) or an Authority to Operate (ATO) which RMF has ATOs to determine the authorized periods required for approval by and AO. NIST recommends that the CSF be used to strengthen the RMF. I would say that I would use the RMF to first get the framework in place then start implementing the CSF. Both of the frameworks have two entirely different end goals.

Posey, B. (2021) What is risk management and why is it important? Retrieved from 

https://www.techtarget.com/searchcio/definition/Risk-Management-Framework-RMF#:

~:text=The%20Risk%20Management%20Framework%20is,of%20the%20United%20States%20government

.

430 W5 DQ1 RESPONSES CONTINUATION

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

B Cody

Hello everyone,

“The Risk Management Framework is a template and guideline used by companies to identify, eliminate and minimize risks. It was originally developed by the National Institute of Standards and Technology to help protect the information systems of the United States government” (Posey, 2021). The Risk Management Framework is simply used periodically to identify and organize risks to an organization. The National Institute of Standards and Technology also created the Cybersecurity Framework. “The Framework integrates industry standards and best practices to help organizations manage their cybersecurity risks” (Swenson, 2022). These are very similar in that they both were created by NIST to help organizations identify, categorize, and to help mitigate risks but they are different in that The Risk Management Framework deals with more overarching risks regarding organizations and the Cybersecurity Framework deals only specifically with cybersecurity threats. I would recommend for an organization to use all of these frameworks since the Cybersecurity Framework would deal with cybersecurity threats and the RMF would cover strategic, legal, operational, and privacy risks.

C Jacob

Good evening Professor Ligon and class,

Risk Management Framework (RMF) is an established set of components (Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance) and steps (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor) that help companies to identify, eliminate, and minimize risks. These guidelines were originally created by the National Institute of Standards and Technology (NIST) to help protect information systems within the U.S. “Businesses cannot exist without exposing themselves to risks such as IT problems, litigation, and loss of capital” (Posey, 2021). No risk can be totally gotten rid of, there will always be a need for risks. All we can do is mitigate them. This concept benefits businesses by minimizing the risks that are out there which in end lowers the legal spotlight and increases profits.   

Cyber Security Framework (CSF) and RMF are often mixed around when IT professionals are discussing them. When RMF was originally created by NIST, its target audience was the federal government. This is still true today, although private organizations have seen the benefits of RMF and have started to incorporate the guideline into their IT plans. CSF has been created for more critical infrastructures, such as transportation or public utilities. CSF is also suitable for an “Organization of any size, degree of cybersecurity risk, or cybersecurity sophistication” (Webb, 2017). CSF has not been created to replace RMF, it is another tool that organizations have at their disposal to deal with risks associated with the IT field.

430 W5 DQ1

Briefly describe the purpose and application of the Risk Management Framework. How does this differ from the Cyber Security Framework? Which would you recommend and why?

Reply to responses.

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

A Aaron

Evening,

The Risk Management Framework (RMF) was first intended for federal agencies but soon was adopted by organization that were in the private sector. A business can’t operate with out exposing themselves to so sort of risks like IT problems, Litigation and Loss of Capitol (Posey, 2021). The RMF is made up of five components, that are Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance. The Identification stage is to identify the risks that an organization might have, and this process is not a one-time thing as these risks might change over time. Measurement and assessment are when you create a risk profile for each that was identified in the first step and the measurement can be in the form of how much capital could be lost. Mitigation is by examining the risks and determining which risks should be eliminated and which risks are acceptable. Reporting and monitoring involves reexamining the risks to make sure the mitigation strategies the organization have adopted are serving their purposes. Governance is the process of making sure the adoption of the mitigation strategies is in place and that the employees are following the policies. RMF is more targeted towards the federal government and CSF was originally developed for critical infrastructure but has been recommended for use in organizations. CSF is aimed towards the private sector more than the federal government and does not have any Authorizing Officials (AOs) or an Authority to Operate (ATO) which RMF has ATOs to determine the authorized periods required for approval by and AO. NIST recommends that the CSF be used to strengthen the RMF. I would say that I would use the RMF to first get the framework in place then start implementing the CSF. Both of the frameworks have two entirely different end goals.

Posey, B. (2021) What is risk management and why is it important? Retrieved from 

https://www.techtarget.com/searchcio/definition/Risk-Management-Framework-RMF#:

~:text=The%20Risk%20Management%20Framework%20is,of%20the%20United%20States%20government

.

430 W5 DQ1 RESPONSES CONTINUATION

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

B Cody

Hello everyone,

“The Risk Management Framework is a template and guideline used by companies to identify, eliminate and minimize risks. It was originally developed by the National Institute of Standards and Technology to help protect the information systems of the United States government” (Posey, 2021). The Risk Management Framework is simply used periodically to identify and organize risks to an organization. The National Institute of Standards and Technology also created the Cybersecurity Framework. “The Framework integrates industry standards and best practices to help organizations manage their cybersecurity risks” (Swenson, 2022). These are very similar in that they both were created by NIST to help organizations identify, categorize, and to help mitigate risks but they are different in that The Risk Management Framework deals with more overarching risks regarding organizations and the Cybersecurity Framework deals only specifically with cybersecurity threats. I would recommend for an organization to use all of these frameworks since the Cybersecurity Framework would deal with cybersecurity threats and the RMF would cover strategic, legal, operational, and privacy risks.

C Jacob

Good evening Professor Ligon and class,

Risk Management Framework (RMF) is an established set of components (Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance) and steps (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor) that help companies to identify, eliminate, and minimize risks. These guidelines were originally created by the National Institute of Standards and Technology (NIST) to help protect information systems within the U.S. “Businesses cannot exist without exposing themselves to risks such as IT problems, litigation, and loss of capital” (Posey, 2021). No risk can be totally gotten rid of, there will always be a need for risks. All we can do is mitigate them. This concept benefits businesses by minimizing the risks that are out there which in end lowers the legal spotlight and increases profits.   

Cyber Security Framework (CSF) and RMF are often mixed around when IT professionals are discussing them. When RMF was originally created by NIST, its target audience was the federal government. This is still true today, although private organizations have seen the benefits of RMF and have started to incorporate the guideline into their IT plans. CSF has been created for more critical infrastructures, such as transportation or public utilities. CSF is also suitable for an “Organization of any size, degree of cybersecurity risk, or cybersecurity sophistication” (Webb, 2017). CSF has not been created to replace RMF, it is another tool that organizations have at their disposal to deal with risks associated with the IT field.

430 W5 DQ1

Briefly describe the purpose and application of the Risk Management Framework. How does this differ from the Cyber Security Framework? Which would you recommend and why?

Reply to responses.

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

A Aaron

Evening,

The Risk Management Framework (RMF) was first intended for federal agencies but soon was adopted by organization that were in the private sector. A business can’t operate with out exposing themselves to so sort of risks like IT problems, Litigation and Loss of Capitol (Posey, 2021). The RMF is made up of five components, that are Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance. The Identification stage is to identify the risks that an organization might have, and this process is not a one-time thing as these risks might change over time. Measurement and assessment are when you create a risk profile for each that was identified in the first step and the measurement can be in the form of how much capital could be lost. Mitigation is by examining the risks and determining which risks should be eliminated and which risks are acceptable. Reporting and monitoring involves reexamining the risks to make sure the mitigation strategies the organization have adopted are serving their purposes. Governance is the process of making sure the adoption of the mitigation strategies is in place and that the employees are following the policies. RMF is more targeted towards the federal government and CSF was originally developed for critical infrastructure but has been recommended for use in organizations. CSF is aimed towards the private sector more than the federal government and does not have any Authorizing Officials (AOs) or an Authority to Operate (ATO) which RMF has ATOs to determine the authorized periods required for approval by and AO. NIST recommends that the CSF be used to strengthen the RMF. I would say that I would use the RMF to first get the framework in place then start implementing the CSF. Both of the frameworks have two entirely different end goals.

Posey, B. (2021) What is risk management and why is it important? Retrieved from 

https://www.techtarget.com/searchcio/definition/Risk-Management-Framework-RMF#:

~:text=The%20Risk%20Management%20Framework%20is,of%20the%20United%20States%20government

.

430 W5 DQ1 RESPONSES CONTINUATION

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

B Cody

Hello everyone,

“The Risk Management Framework is a template and guideline used by companies to identify, eliminate and minimize risks. It was originally developed by the National Institute of Standards and Technology to help protect the information systems of the United States government” (Posey, 2021). The Risk Management Framework is simply used periodically to identify and organize risks to an organization. The National Institute of Standards and Technology also created the Cybersecurity Framework. “The Framework integrates industry standards and best practices to help organizations manage their cybersecurity risks” (Swenson, 2022). These are very similar in that they both were created by NIST to help organizations identify, categorize, and to help mitigate risks but they are different in that The Risk Management Framework deals with more overarching risks regarding organizations and the Cybersecurity Framework deals only specifically with cybersecurity threats. I would recommend for an organization to use all of these frameworks since the Cybersecurity Framework would deal with cybersecurity threats and the RMF would cover strategic, legal, operational, and privacy risks.

C Jacob

Good evening Professor Ligon and class,

Risk Management Framework (RMF) is an established set of components (Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance) and steps (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor) that help companies to identify, eliminate, and minimize risks. These guidelines were originally created by the National Institute of Standards and Technology (NIST) to help protect information systems within the U.S. “Businesses cannot exist without exposing themselves to risks such as IT problems, litigation, and loss of capital” (Posey, 2021). No risk can be totally gotten rid of, there will always be a need for risks. All we can do is mitigate them. This concept benefits businesses by minimizing the risks that are out there which in end lowers the legal spotlight and increases profits.   

Cyber Security Framework (CSF) and RMF are often mixed around when IT professionals are discussing them. When RMF was originally created by NIST, its target audience was the federal government. This is still true today, although private organizations have seen the benefits of RMF and have started to incorporate the guideline into their IT plans. CSF has been created for more critical infrastructures, such as transportation or public utilities. CSF is also suitable for an “Organization of any size, degree of cybersecurity risk, or cybersecurity sophistication” (Webb, 2017). CSF has not been created to replace RMF, it is another tool that organizations have at their disposal to deal with risks associated with the IT field.

430 W5 DQ1

Briefly describe the purpose and application of the Risk Management Framework. How does this differ from the Cyber Security Framework? Which would you recommend and why?

Reply to responses.

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

A Aaron

Evening,

The Risk Management Framework (RMF) was first intended for federal agencies but soon was adopted by organization that were in the private sector. A business can’t operate with out exposing themselves to so sort of risks like IT problems, Litigation and Loss of Capitol (Posey, 2021). The RMF is made up of five components, that are Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance. The Identification stage is to identify the risks that an organization might have, and this process is not a one-time thing as these risks might change over time. Measurement and assessment are when you create a risk profile for each that was identified in the first step and the measurement can be in the form of how much capital could be lost. Mitigation is by examining the risks and determining which risks should be eliminated and which risks are acceptable. Reporting and monitoring involves reexamining the risks to make sure the mitigation strategies the organization have adopted are serving their purposes. Governance is the process of making sure the adoption of the mitigation strategies is in place and that the employees are following the policies. RMF is more targeted towards the federal government and CSF was originally developed for critical infrastructure but has been recommended for use in organizations. CSF is aimed towards the private sector more than the federal government and does not have any Authorizing Officials (AOs) or an Authority to Operate (ATO) which RMF has ATOs to determine the authorized periods required for approval by and AO. NIST recommends that the CSF be used to strengthen the RMF. I would say that I would use the RMF to first get the framework in place then start implementing the CSF. Both of the frameworks have two entirely different end goals.

Posey, B. (2021) What is risk management and why is it important? Retrieved from 

https://www.techtarget.com/searchcio/definition/Risk-Management-Framework-RMF#:

~:text=The%20Risk%20Management%20Framework%20is,of%20the%20United%20States%20government

.

430 W5 DQ1 RESPONSES CONTINUATION

Please read before replying to responses. 100-150 words.

Response Requirements

Reminder, each response must be a paragraph which is seven sentences. In addition, I am reminding all students not to lose points moving forward, that the responses for participation need to follow the ABC method. Acknowledge what your classmate has said, build on the content (do not just state, I agree with how you said this, or I like how you said that), and close with a question (an open-ended question). You may send me a message in the private forum with any questions. You must have supporting in-text citations and references to support your discussions posts. Blessings with wisdom and academic growth! Cheers, Professor Ligon Blessings and prayers

B Cody

Hello everyone,

“The Risk Management Framework is a template and guideline used by companies to identify, eliminate and minimize risks. It was originally developed by the National Institute of Standards and Technology to help protect the information systems of the United States government” (Posey, 2021). The Risk Management Framework is simply used periodically to identify and organize risks to an organization. The National Institute of Standards and Technology also created the Cybersecurity Framework. “The Framework integrates industry standards and best practices to help organizations manage their cybersecurity risks” (Swenson, 2022). These are very similar in that they both were created by NIST to help organizations identify, categorize, and to help mitigate risks but they are different in that The Risk Management Framework deals with more overarching risks regarding organizations and the Cybersecurity Framework deals only specifically with cybersecurity threats. I would recommend for an organization to use all of these frameworks since the Cybersecurity Framework would deal with cybersecurity threats and the RMF would cover strategic, legal, operational, and privacy risks.

C Jacob

Good evening Professor Ligon and class,

Risk Management Framework (RMF) is an established set of components (Identification, Measurement and Assessment, Mitigation, Reporting and Monitoring, and Governance) and steps (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor) that help companies to identify, eliminate, and minimize risks. These guidelines were originally created by the National Institute of Standards and Technology (NIST) to help protect information systems within the U.S. “Businesses cannot exist without exposing themselves to risks such as IT problems, litigation, and loss of capital” (Posey, 2021). No risk can be totally gotten rid of, there will always be a need for risks. All we can do is mitigate them. This concept benefits businesses by minimizing the risks that are out there which in end lowers the legal spotlight and increases profits.   

Cyber Security Framework (CSF) and RMF are often mixed around when IT professionals are discussing them. When RMF was originally created by NIST, its target audience was the federal government. This is still true today, although private organizations have seen the benefits of RMF and have started to incorporate the guideline into their IT plans. CSF has been created for more critical infrastructures, such as transportation or public utilities. CSF is also suitable for an “Organization of any size, degree of cybersecurity risk, or cybersecurity sophistication” (Webb, 2017). CSF has not been created to replace RMF, it is another tool that organizations have at their disposal to deal with risks associated with the IT field.

Course Scholar
Calculate your paper price
Pages (550 words)
Approximate price: -

Why Work with Us

Top Quality and Well-Researched Papers

We always make sure that writers follow all your instructions precisely. You can choose your academic level: high school, college/university or professional, and we will assign a writer who has a respective degree.

Professional and Experienced Academic Writers

We have a team of professional writers with experience in academic and business writing. Many are native speakers and able to perform any task for which you need help.

Free Unlimited Revisions

If you think we missed something, send your order for a free revision. You have 10 days to submit the order for review after you have received the final document. You can do this yourself after logging into your personal account or by contacting our support.

Prompt Delivery and 100% Money-Back-Guarantee

All papers are always delivered on time. In case we need more time to master your paper, we may contact you regarding the deadline extension. In case you cannot provide us with more time, a 100% refund is guaranteed.

Original & Confidential

We use several writing tools checks to ensure that all documents you receive are free from plagiarism. Our editors carefully review all quotations in the text. We also promise maximum confidentiality in all of our services.

24/7 Customer Support

Our support agents are available 24 hours a day 7 days a week and committed to providing you with the best customer experience. Get in touch whenever you need any assistance.

Try it now!

Calculate the price of your order

Total price:
$0.00

How it works?

Follow these simple steps to get your paper done

Place your order

Fill in the order form and provide all details of your assignment.

Proceed with the payment

Choose the payment system that suits you most.

Receive the final file

Once your paper is ready, we will email it to you.

Our Services

No need to work on your paper at night. Sleep tight, we will cover your back. We offer all kinds of writing services.

Essays

Essay Writing Service

No matter what kind of academic paper you need and how urgent you need it, you are welcome to choose your academic level and the type of your paper at an affordable price. We take care of all your paper needs and give a 24/7 customer care support system.

Admissions

Admission Essays & Business Writing Help

An admission essay is an essay or other written statement by a candidate, often a potential student enrolling in a college, university, or graduate school. You can be rest assurred that through our service we will write the best admission essay for you.

Reviews

Editing Support

Our academic writers and editors make the necessary changes to your paper so that it is polished. We also format your document by correctly quoting the sources and creating reference lists in the formats APA, Harvard, MLA, Chicago / Turabian.

Reviews

Revision Support

If you think your paper could be improved, you can request a review. In this case, your paper will be checked by the writer or assigned to an editor. You can use this option as many times as you see fit. This is free because we want you to be completely satisfied with the service offered.