The phase out of the Department of Defense (DOD) Information Assurance Certification and Accreditation Process (DIACAP) is leading to a new process called Risk Management Framework (RMF). This new process was mandated by DOD Instruction 8500.01, which also mandated the adoption of the term “cybersecurity� to be used throughout DOD instead of the term “information assurance (IA).� RMF will follow a set of security controls inherited from the National Institute of Standards and Technology (NIST). These controls are specifically located in the Special Publication (SP) 800-53. The NIST SP 800-53 controls will replace the existing DOD Instruction (DODI) 8500.2 controls and have been updated to reflect the evolving technologies while addressing new cybersecurity threats. Given the transition, there are a number of implications for the training and simulation community for ensuring training systems comply with these new controls and maintain their information security posture. Guidance for the transition has been developing gradually and each of the DOD agencies are handling it individually at the implementation level. The Program Executive Office for Simulation, Training, and Instrumentation (PEO STRI) is following DOD and specifically Army guidance to ensure the NIST control implementation gets executed in the most efficient manner possible.
This paper will first provide some background on the legacy DOD 8500.2 controls and an overview of the transition to the NIST SP 800-53 controls. It will then discuss the formal requirements, new terminology, implementation and guidance driving this transition. This paper will analyze the framework of the NIST SP 800-53 RMF controls and how they compare to DIACAP controls. It will discuss the security control overlays, and the assessment procedures. To conclude, this paper will describe the transition impacts for PEO STRI stakeholders, which include DOD contractors, system users, and Project Managers (PM). This paper will layout the fundamental idea and challenges PEO STRI faced on a particular use