# RMF Foundations: From Risk to Authorization (Self-Paced) (Coming Soon)

Canonical URL: <https://www.graduateschool.edu/courses/rmf-foundations-from-risk-to-authorization-self-paced>

## Overview

The NIST Risk Management Framework is the backbone of how federal information systems are secured and authorized to operate. This foundational course walks the complete RMF lifecycle as defined in NIST SP 800-37, connecting each step to the risk decision it supports. 

Learners move from the core concepts of risk and governance through the seven RMF steps (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor), ending with an integrated capstone that follows a system through the entire process. The course assumes no prior authorization experience and builds the shared vocabulary and mental model that every later course in the RMF track depends on.

## What you'll learn

- Explain the purpose of the NIST RMF and how it links risk to authorization
- Identify the key RMF roles and their responsibilities
- Categorize a system's impact level using FIPS 199
- Select and tailor a control baseline using NIST SP 800-53B
- Describe how controls are implemented, assessed, and documented
- Interpret an authorization decision and residual-risk acceptance
- Explain continuous monitoring's role in maintaining an authorization

## Curriculum

#### Module 1: RMF Orientation and Risk Fundamentals

- Explore why the Risk Management Framework exists and how it connects cybersecurity activities to organizational missions.

#### Module 2: RMF Governance, Risk Levels, and Participant Roles

- Examine the three risk tiers and the roles and responsibilities that support the RMF process.

#### Module 3: Prepare

- Review organization- and system-level activities that establish readiness for the RMF process.

#### Module 4: Categorize

- Determine system impact levels using Federal Information Processing Standard 199.

#### Module 5: Select

- Apply control baselines and tailoring guidance using NIST Special Publication 800-53B.

#### Module 6: Implement

- Put selected security controls in place and document how they have been implemented.

#### Module 7: Assess

- Produce and evaluate evidence to determine whether security controls are implemented correctly and operating effectively.

#### Module 8: Authorize

- Evaluate residual risk and support the issuance of an authorization decision.

#### Module 9: Monitor

- Maintain current information about control effectiveness, system changes, and organizational risk.

#### Module 10: Integrated RMF Capstone and Knowledge Check

- Apply the complete RMF process through an integrated capstone exercise and knowledge check.

## Instructors

### Wes Bryan — Instructor

Wes Bryan resides in Gainesville, Florida, and has built his career around technology, education, and helping others understand complex subjects. He values continuous learning, clear communication, and practical problem-solving. Outside of work, Wesley enjoys running, hiking, fishing, and spending time outdoors. He also has a strong interest in music and literature, enjoys reading both fiction and nonfiction, as well as playing guitar.

## Pricing

**Tuition:** $699
