Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Explore

Learn about the CAM benefits and workflows for users.

CAM overview

The CAM application applies a standardized approach to automating NIST's Risk Management Framework (RMF).

CAM users

CAM roles that are required for particular tasks are listed in CAM user roles.

User / RoleDescription
System ownerThe individual responsible for procuring, developing, integrating, modifying, operating, and maintaining an information system.
Authorizing Official (AO)The individual responsible for accepting an information system into an operational environment at a known risk level. Typically, this person is at the CISO or deputy CISO level.
Authorizing Official Designated Representatives (AODR)One or more AODRs.
Security Control Assessors (SCA)The individuals responsible for conducting a thorough assessment of the controls of an information system.
Information System Security Managers (ISSM)The individuals responsible for conducting information system security management activities as designated by the ISSO.
Information System Security Officers (ISSO)The individuals responsible for ensuring that the appropriate operational security posture is maintained for an information system.
Information ownersThe individuals responsible for statutory, management, and operational authority.
System usersThe users responsible for performing the actual work on the system.

RMF workflow supported by CAM

RMF was mandated by the U.S. Federal government to provide the necessary resiliency to support the economic and national security interests of the United States. CAM employs the seven steps defined by the RMF to allow you to make better-informed decisions about your security posture.

The RMF System Life Cycle consists of seven interconnected phases that work together to provide a comprehensive approach to managing information system security risks. Each phase has a specific focus area and contributes to the overall authorization and continuous monitoring of the system.

RMF Phases

PhasePhase NameScopeDescription
1PrepareInformation SystemDefine the system boundary, assign roles, identify common controls, and prepare for the RMF process.
2CategorizeInformation SystemDefine criticality/sensitivity of information system according to potential worse case, adverse impact to mission/business.
3SelectSystem ControlsSelect baseline controls; apply tailoring guidance and supplement controls as needed based on risk assessments.
4ImplementSystem ControlsImplement controls within enterprise architecture using sound systems engineering practices; apply configuration settings.
5AssessSystem ControlsDetermine control effectiveness (that is, controls implemented correctly, operating as intended, meeting requirements for information system).
6AuthorizeInformation SystemDetermine risk to organizational operations and assets, individuals, other organizations, and the Nation; if acceptable, authorize operation.
7MonitorSystem ControlsContinuously track changes to the information system that may affect security controls and reassess control effectiveness.

What to explore next

To learn more about configuring and using CAM, see: