Based upon the Program and Technical Baselining review results, Federal organizational management will be able to make well-informed, risk-based decisions regarding CS&P-related activities....
The first step toward increasing maturity is understanding the current state of a CS&P program, project, or system and identifying what the current (as-is) and target (to-be) state looks like....
To be effective in this operational environment, Federal D&As must employ CS&P programs that focus on operating in cyberspace instead of just reacting to it....
Consideration and implementation of these actions will greatly enhance and smooth the integration of the RMF with the CSF and privacy at the Federal department and agency cybersecurity and privacy...