<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DoW Cybersecurity Risk Management Construct (CRMC) in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/DoW-Cybersecurity-Risk-Management-Construct-CRMC/m-p/84249#M7641</link>
    <description>&lt;P&gt;&lt;A href="https://www.war.gov/News/Releases/Release/Article/4314411/department-of-war-announces-new-cybersecurity-risk-management-construct/" target="_blank" rel="noopener"&gt;https://www.war.gov/News/Releases/Release/Article/4314411/department-of-war-announces-new-cybersecurity-risk-management-construct/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have read that many feel that this is replacing RMF. I never read or heard anything about OMB Circular A-130 being modified. A-130 (which extends from FISMA) specifically states that all US federal agencies will follow the NIST RMF. Anyone with insight?&lt;/P&gt;</description>
    <pubDate>Tue, 30 Sep 2025 12:52:27 GMT</pubDate>
    <dc:creator>Until_then</dc:creator>
    <dc:date>2025-09-30T12:52:27Z</dc:date>
    <item>
      <title>DoW Cybersecurity Risk Management Construct (CRMC)</title>
      <link>https://community.isc2.org/t5/Industry-News/DoW-Cybersecurity-Risk-Management-Construct-CRMC/m-p/84249#M7641</link>
      <description>&lt;P&gt;&lt;A href="https://www.war.gov/News/Releases/Release/Article/4314411/department-of-war-announces-new-cybersecurity-risk-management-construct/" target="_blank" rel="noopener"&gt;https://www.war.gov/News/Releases/Release/Article/4314411/department-of-war-announces-new-cybersecurity-risk-management-construct/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have read that many feel that this is replacing RMF. I never read or heard anything about OMB Circular A-130 being modified. A-130 (which extends from FISMA) specifically states that all US federal agencies will follow the NIST RMF. Anyone with insight?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2025 12:52:27 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/DoW-Cybersecurity-Risk-Management-Construct-CRMC/m-p/84249#M7641</guid>
      <dc:creator>Until_then</dc:creator>
      <dc:date>2025-09-30T12:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: DoW Cybersecurity Risk Management Construct (CRMC)</title>
      <link>https://community.isc2.org/t5/Industry-News/DoW-Cybersecurity-Risk-Management-Construct-CRMC/m-p/84255#M7642</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/608348703"&gt;@Until_then&lt;/a&gt;&amp;nbsp; &amp;nbsp;Maybe they are trying to expand it?&amp;nbsp; This oddly pairs well with something that I read earlier today:&amp;nbsp;publications.armywarcollege.edu/News/Display/Article/4305189/who-is-in-charge-of-cyber-incidence-response-in-the-homeland&lt;/P&gt;</description>
      <pubDate>Fri, 26 Sep 2025 19:34:56 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/DoW-Cybersecurity-Risk-Management-Construct-CRMC/m-p/84255#M7642</guid>
      <dc:creator>nkeaton</dc:creator>
      <dc:date>2025-09-26T19:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: DoW Cybersecurity Risk Management Construct (CRMC)</title>
      <link>https://community.isc2.org/t5/Industry-News/DoW-Cybersecurity-Risk-Management-Construct-CRMC/m-p/84299#M7644</link>
      <description>&lt;P&gt;As I understand it, this NEW&amp;nbsp;Cybersecurity Risk Management Construct (CSRMC) is SEPARATE from RMF as it deals with software development.&lt;BR /&gt;&lt;BR /&gt;Oh, so you think something from the federal government, which the DOW is, is somehow "illegal"???&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 13:34:56 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/DoW-Cybersecurity-Risk-Management-Construct-CRMC/m-p/84299#M7644</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2025-09-29T13:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: DoW Cybersecurity Risk Management Construct (CRMC)</title>
      <link>https://community.isc2.org/t5/Industry-News/DoW-Cybersecurity-Risk-Management-Construct-CRMC/m-p/84323#M7645</link>
      <description>Agreed. Looks like an add-on to improve rather than replace.</description>
      <pubDate>Tue, 30 Sep 2025 12:44:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/DoW-Cybersecurity-Risk-Management-Construct-CRMC/m-p/84323#M7645</guid>
      <dc:creator>Until_then</dc:creator>
      <dc:date>2025-09-30T12:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: DoW Cybersecurity Risk Management Construct (CRMC)</title>
      <link>https://community.isc2.org/t5/Industry-News/DoW-Cybersecurity-Risk-Management-Construct-CRMC/m-p/84324#M7646</link>
      <description>DoD is part of the federal govt. It is not by itself the federal govt. I have heard there are US federal agencies out there that are not even following RMF which is against the FISMA and OMB A-130 mandate.</description>
      <pubDate>Tue, 30 Sep 2025 12:46:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/DoW-Cybersecurity-Risk-Management-Construct-CRMC/m-p/84324#M7646</guid>
      <dc:creator>Until_then</dc:creator>
      <dc:date>2025-09-30T12:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: DoW Cybersecurity Risk Management Construct (CRMC)</title>
      <link>https://community.isc2.org/t5/Industry-News/DoW-Cybersecurity-Risk-Management-Construct-CRMC/m-p/84341#M7647</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/608348703"&gt;@Until_then&lt;/a&gt;&amp;nbsp;wrote: "DoD is part of the federal govt. It is not by itself the federal govt."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, but CRMCS is an add-on to RMF, not a replacement.&amp;nbsp; This is little different then the creation of the CMMC within the DOD to address DFARS matters.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/608348703"&gt;@Until_then&lt;/a&gt;&amp;nbsp; "I have heard there are US federal agencies out there that are not even following RMF which is against the FISMA and OMB A-130 mandate."&lt;BR /&gt;&lt;BR /&gt;Yeah, because the RMF is a beast.&amp;nbsp; This is why many agencies are wanting to use the NIST CSF to get themselves to meeting RMF.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2025 18:36:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/DoW-Cybersecurity-Risk-Management-Construct-CRMC/m-p/84341#M7647</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2025-09-30T18:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: DoW Cybersecurity Risk Management Construct (CRMC)</title>
      <link>https://community.isc2.org/t5/Industry-News/DoW-Cybersecurity-Risk-Management-Construct-CRMC/m-p/84379#M7649</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;I’ve seen the same confusion, but as far as I know, OMB Circular A-130 hasn’t changed, and it still mandates NIST RMF under FISMA. A lot of the “replacement” talk seems to come from misunderstanding new frameworks or tools being introduced—not actual policy shifts. Took a break with &lt;A href="https://sprunki-retake.lol" target="_self"&gt;Sprunki Retake&lt;/A&gt;&amp;nbsp;while reading up on this, and it really helped me refocus!&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 03 Oct 2025 07:16:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/DoW-Cybersecurity-Risk-Management-Construct-CRMC/m-p/84379#M7649</guid>
      <dc:creator>SprunkiRetake</dc:creator>
      <dc:date>2025-10-03T07:16:04Z</dc:date>
    </item>
  </channel>
</rss>

