DI-MGMT-82395
Risk Management Framework (RMF) Package for Air Force Intelligence Community (AF IC) Systems
Defines the RMF package body of evidence data required to satisfy Air Force Intelligence Community assessment and authorization procedures for obtaining an authorization to operate.
Approval DateAugust 25, 2022
AMSC NumberF10354
Preparing Activity19
Project NumberMGMT-2022-020
OPR—
DTIC ApplicableNo
GIDEP ApplicableNo
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The risk management framework (RMF) package data shall be used to satisfy the requirements of the Air Force (AF) Intelligence Community (IC) assessment and authorization procedures to obtain an authorization to operate (ATO).
This data item description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in the contract.
Preparation Instructions
1Reference Documents.None.
2Format.The RMF package body of evidence (BoE) shall be delivered in a format approved by the Government's Authorizing Official (AO), Designated Authorizing Official (DAO), or Information Systems Security Manager (ISSM).
3Content.The content of the RMF package shall contain the necessary BoE required by the AF IC AO, DAO, or ISSM to successfully achieve an interim authorization to test (IATT), or ATO. The RMF package shall include the following items or sections.
3.1Introduction.This section shall contain a narrative of the RMF package deliverable content.
3.2.1Provide updated authorization boundary diagrams
3.2.2Identify external data flows and outline authorization boundary within diagrams
3.2.3Diagrams must match hardware inventory.Use host names from hardware inventory to identify devices within the diagrams
3.2.4Identify where workstations, printers, scanners, and voice over internet protocols (VoIPs) are located
3.4Data flow diagram.The data flow diagram should be specific to the authorization boundary and include directional data flow information.
3.5Ports, Protocols, and Services Matrix (PPSM)
3.6Detailed hardware inventoryincluding host name, unique identifier, serial numbers, IP address, vendor, make, model, and network role (e.g., server).
3.7Detailed software inventoryincluding software title, vendor, version, type (e.g., vulnerability scanner, network monitor, and open source application container), and Certificate to Field (CtF) approval.
3.8ISSM appointment letter.
3.9SSO or SSR appointment letter.
3.10Sensitive compartmented information facility (SCIF) accreditation letter.Submit the SCIF accreditation letter for location of the project.
3.11Privileged user standard operating procedures (SOP).
3.12Construction security plan.This section is only applicable to SCIFs built after 2010 for location of the project.
3.13TEMPEST accreditation letter.Include the issue and expiration date for location of the project.
3.14Security controls traceability matrix (SCTM).The Government will provide the SCTM template for the contractor to answer.
3.1518 RMF control family documents.Answer how the SCTM was implemented.
3.16Continuous monitoring (ConMon) plan.
3.17Plan of Actions and Milestones (POAMs)
3.19Interconnect Security Agreement (ISA)including system name, ports, protocols, external IP address, internal IP address, direction (inbound/outbound/both), and description of connection.
Schema v3.0Community-maintained · Verify against ASSIST