ISSO & NIST RMF Bootcamp
Do the real ISSO job: RMF, the ATO, and the continuous-monitoring work that actually fills your week.
Tuition
$2,000
Intermediate
Level
6
Modules
28
Lessons
6
Graded quizzes
6
Assignments
24 hours
Estimated time
What you will be able to do
- Explain the ISSO role and the 7 steps of the NIST Risk Management Framework
- Categorize a system with FIPS 199 and select an 800-53 control baseline
- Document control implementation in an SSP and read a SAR
- Build the authorization package and explain the ATO decision and its variants
- Run continuous monitoring: pen-test reviews, baseline reviews and ISA reviews
- Create and manage a POA&M with an estimated completion date and evidence
- Work a real continuous-monitoring ticket end to end, the way the job is done
What is inside
6 modules, 28 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
The ISSO Role & the Risk Management Framework
Before you touch a single artifact, you need to understand who the ISSO is, who they answer to, and the framework that organizes everything they do. This module walks you through what an Information System Security Officer actually does day to day, the roles they work with, why every federal system needs an ATO under FISMA, the seven steps of the NIST RMF at a high level, and how most of an ISSO's week is really a steady stream of continuous-monitoring tickets. You finish by writing a day-in-the-life memo for a fictional mid-size federal system called Atlas.
5 lessons · 18 quiz questions · assignment
- 02
RMF Categorize & Select: FIPS 199 and the 800-53 Baseline
Every ATO package starts with two decisions that shape everything after them: how sensitive is this system, and which controls must protect it? In this module you learn to categorize a system with FIPS 199 across confidentiality, integrity, and availability, apply the high-water mark, read out the resulting NIST SP 800-53 control baseline, and tailor that baseline so it fits the system you actually have. You finish by categorizing and tailoring the fictional Atlas system end to end.
5 lessons · 16 quiz questions · assignment
- 03
RMF Implement & Assess: SSP, Assessment Methods, SAR & Findings
Two RMF steps, one continuous thread of evidence. In Implement you write down how each control actually works on the system in the System Security Plan and track it in a GRC tool. In Assess an independent assessor examines, interviews, and tests those controls, writes the Security Assessment Report, and turns every weakness into a finding that feeds the POA&M. You will learn what a strong control-implementation statement contains, the three assessment methods, how a SAR finding is built, and you will practise on a fictional federal system called Atlas.
4 lessons · 16 quiz questions · assignment
- 04
RMF Step 6, Authorize: The Package, the Risk Decision, and the ATO
Assess is finished and the controls have been tested. Now someone in authority has to look at the residual risk and decide, in writing, whether the system is allowed to operate. This module teaches the Authorize step end to end: how the SSP, SAR, and POA&M come together into an authorization package, how the Authorizing Official makes a risk-based decision, why open POA&M items do not automatically block an ATO, and the difference between a full ATO, an ATO with conditions, and a denial. You finish by writing a one-page authorization recommendation for a fictional federal system, Atlas.
4 lessons · 16 quiz questions · assignment
- 05
Continuous Monitoring: the ISSO's Daily Work
This is the heart of the ISSO job. After a system gets its ATO, the work does not stop. It becomes a monthly rhythm called Continuous Monitoring (ConMon), RMF Step 7. You will learn the parent-story / child-subtask ticket pattern ISSOs actually live in, how to review pen-test findings and map each one to a POA&M with an Estimated Completion Date, how to track security baseline and ISA signatures and expirations, what a strong POA&M entry contains, and how to close a ticket with the correct resolution. Everything is taught on a fictional mid-size agency system called Atlas so you understand the task before you ever touch a real one.
5 lessons · 16 quiz questions · assignment
- 06
The ISSO Toolkit & Capstone
This is where the whole course comes together. You will assemble the ISSO's working toolkit: evidence discipline, the POA&M as the spine of the job, working a ticket queue, the monthly ConMon report, and clean resolution hygiene. Then you tour the recurring ConMon task types so you can recognise any one on sight. You finish by working a real (anonymized) continuous-monitoring ticket end to end against the fictional Atlas system, and you can rehearse your interview answers in the AI Interview Coach along the way.
5 lessons · 16 quiz questions · assignment