uscensusbureau / fismatic

https://github.com/uscensusbureau/fismatic/projects/1
Other
11 stars 10 forks source link

confirm terminology of various stakeholders #18

Open afeld opened 5 years ago

afeld commented 5 years ago

What are the official terms for these groups?

I thought I knew, but after talking with @trevorbryant, it seems our terminology wasn't consistent. Therefore, I'm questioning my assumptions. Places to check:

trevorbryant commented 5 years ago

With the understanding that NIST allows guidance for each agency to be flexible in their implementation of the Risk Management Framework, the below are what I've learned in other agencies. Keep in mind that this is not the same for every agency.

Keep in mind that terminology and processes differ between agency. Agencies can redefine words to fit their needs and that just needs an explanation so everybody is on the same page. You'll see above that the process I've described is very waterfall. With automation introduced this can be adaptable to being Agile and speedy. I've gone a bit beyond the quick and simple scope of the original questions, but RMF is a complex effort / project in itself.