← All seven chapters

PREPARE · RMF LIFECYCLE

Prepare

What are we protecting, and why does it matter?

Security and Risk Management Asset Security

Before we talk about controls, let’s talk about the work. What is this system supposed to help people accomplish? Who depends on it? You can have a room full of capable people and still get very different answers. Prepare gives us a reason to have that conversation early, whether we’re planning something new or taking a fresh look at something already running.

NIST’s Prepare guidance brings organizational priorities, risk tolerance, responsibilities, and system context into the same conversation. Preparation happens at both the organization and system levels, with security and privacy considered together. NIST’s Prepare step describes the expected outcomes.

Prepare / Visual guideBuild a shared picture before making decisions.
Mission & prioritiesWhat work must the organization accomplish?
StakeholdersWho depends on the system and understands the risk?
Scope & dependenciesWhat information, services, and boundaries matter?
Responsibilities & shared contextAgree who owns decisions, implements safeguards, and supplies evidence.

Preparation connects the mission, the people, and the scope of the work.

Start with the work people need to do

Try describing the mission without naming a product. “We need this platform” tells us what someone wants to buy. We still need to understand the service it will provide, the decisions it will support, and the people who would feel its loss. That explanation gives later security choices something concrete to answer to.

Bring in the people who do that work and the people responsible for the information. Ask what they rely on, where delays cause trouble, and what they would struggle to recover. You may find that the service everyone talks about depends on a much less visible process. That’s a useful discovery to make before the design starts hardening around an incomplete picture.

Put names behind the decisions

Someone needs to own the system, someone needs to explain the information, and someone needs the authority to accept risk. Security, privacy, assessment, and operations bring different questions to the table. Work out the responsibilities and required separation of duties before treating a job title as the whole answer.

Then talk about risk tolerance: how much risk is the organization willing to accept in pursuit of its mission? A team shouldn’t have to invent that position on its own. Get the organizational direction, applicable requirements, available resources, and escalation path clear enough that a disagreement can actually be resolved.

Find the edges of what you know

Trace the information the system will process, store, and exchange. Identify its assets, dependencies, and the responsibilities that sit outside its proposed authorization boundary. A boundary defines the scope of the authorization decision; dependencies can still matter even when another team owns them.

Ask which protections might be supplied as common controls and what remains the system’s responsibility. Consider suppliers and the potential effects of processing information about people. Keep unanswered questions visible, with someone responsible for resolving them. An assumption that everyone quietly repeats can start sounding like a fact surprisingly quickly.

Where SAP implementation comes in

Prepare helps us understand the mission, scope, responsibilities, and risk priorities. For a Special Access Program (SAP) network, those answers set the context for applying NIST’s security controls through JSIG’s policies, procedures, and implementation instructions. As we move through the series, we’ll connect each NIST decision to that SAP application.

Prepare itself comes from NIST SP 800-37 Revision 2. The public 2016 JSIG’s step sequence begins with Categorize.

Let’s talk it through

Pick a question and compare how you’d approach it. Ask what information would change your answer.

  • If the system owner and the people using the service describe its purpose differently, what would help them agree?
  • Which dependency would change our plans the most if we discovered it worked differently than expected?
  • Who can settle a disagreement about acceptable risk, and what would they need to hear from us?

What do we carry forward?

Take an agreed purpose, identified responsibilities, a working scope, and the open questions into Categorize. We can then talk about the consequences of losing the information or service with the people who understand those consequences. Revisit this groundwork whenever the mission or scope changes.

The Prepare section of Body of Evidence & Artifacts connects this work to the artifacts and body of evidence (BOE) you produce and maintain.