Exploring Effective Approaches to the Risk Management Framework (RMF) in the Republic of Korea: A Study

As the world undergoes rapid digitalization, individuals and objects are becoming more extensively connected through the advancement of Internet networks. This phenomenon has been observed in governmental and military domains as well, accompanied by a rise in cyber threats consequently. The United S...

Full description

Bibliographic Details
Main Authors: Giseok Jeong, Kookjin Kim, Sukjoon Yoon, Dongkyoo Shin, Jiwon Kang
Format: Article
Language:English
Published: MDPI AG 2023-10-01
Series:Information
Subjects:
Online Access:https://www.mdpi.com/2078-2489/14/10/561
_version_ 1797573573445943296
author Giseok Jeong
Kookjin Kim
Sukjoon Yoon
Dongkyoo Shin
Jiwon Kang
author_facet Giseok Jeong
Kookjin Kim
Sukjoon Yoon
Dongkyoo Shin
Jiwon Kang
author_sort Giseok Jeong
collection DOAJ
description As the world undergoes rapid digitalization, individuals and objects are becoming more extensively connected through the advancement of Internet networks. This phenomenon has been observed in governmental and military domains as well, accompanied by a rise in cyber threats consequently. The United States (U.S.), in response to this, has been strongly urging its allies to adhere to the RMF standard to bolster the security of primary defense systems. An agreement has been signed between the Republic of Korea and the U.S. to collaboratively operate major defense systems and cooperate on cyber threats. However, the methodologies and tools required for RMF implementation have not yet been fully provided to several allied countries, including the Republic of Korea, causing difficulties in its implementation. In this study, the U.S. RMF process was applied to a specific system of the Republic of Korea Ministry of National Defense, and the outcomes were analyzed. Emphasis was placed on the initial two stages of the RMF: ‘system categorization’ and ‘security control selection’, presenting actual application cases. Additionally, a detailed description of the methodology used by the Republic of Korea Ministry of National Defense for RMF implementation in defense systems is provided, introducing a keyword-based overlay application methodology. An introduction to the K-RMF Baseline, Overlay, and Tailoring Tool is also given. The methodologies and tools presented are expected to serve as valuable references for ally countries, including the U.S., in effectively implementing the RMF. It is anticipated that the results of this research will contribute to enhancing cyber security and threat management among allies.
first_indexed 2024-03-10T21:11:00Z
format Article
id doaj.art-9da26a7e9ba7491fb7ccaa0a817e6622
institution Directory Open Access Journal
issn 2078-2489
language English
last_indexed 2024-03-10T21:11:00Z
publishDate 2023-10-01
publisher MDPI AG
record_format Article
series Information
spelling doaj.art-9da26a7e9ba7491fb7ccaa0a817e66222023-11-19T16:48:12ZengMDPI AGInformation2078-24892023-10-01141056110.3390/info14100561Exploring Effective Approaches to the Risk Management Framework (RMF) in the Republic of Korea: A StudyGiseok Jeong0Kookjin Kim1Sukjoon Yoon2Dongkyoo Shin3Jiwon Kang4Maritime Guided Weapon Program Team, Defense Acquisition Program Administration, Gwacheon 13809, Republic of KoreaCyber Warfare Research Institute, Sejong University, Seoul 05006, Republic of KoreaCyber Warfare Research Institute, Sejong University, Seoul 05006, Republic of KoreaDepartment of Computer Engineering, Sejong University, Seoul 05006, Republic of KoreaDepartment of Computer Engineering, Sejong University, Seoul 05006, Republic of KoreaAs the world undergoes rapid digitalization, individuals and objects are becoming more extensively connected through the advancement of Internet networks. This phenomenon has been observed in governmental and military domains as well, accompanied by a rise in cyber threats consequently. The United States (U.S.), in response to this, has been strongly urging its allies to adhere to the RMF standard to bolster the security of primary defense systems. An agreement has been signed between the Republic of Korea and the U.S. to collaboratively operate major defense systems and cooperate on cyber threats. However, the methodologies and tools required for RMF implementation have not yet been fully provided to several allied countries, including the Republic of Korea, causing difficulties in its implementation. In this study, the U.S. RMF process was applied to a specific system of the Republic of Korea Ministry of National Defense, and the outcomes were analyzed. Emphasis was placed on the initial two stages of the RMF: ‘system categorization’ and ‘security control selection’, presenting actual application cases. Additionally, a detailed description of the methodology used by the Republic of Korea Ministry of National Defense for RMF implementation in defense systems is provided, introducing a keyword-based overlay application methodology. An introduction to the K-RMF Baseline, Overlay, and Tailoring Tool is also given. The methodologies and tools presented are expected to serve as valuable references for ally countries, including the U.S., in effectively implementing the RMF. It is anticipated that the results of this research will contribute to enhancing cyber security and threat management among allies.https://www.mdpi.com/2078-2489/14/10/561risk management framework (RMF)cyber riskcyber securitysystem classificationsecurity control selectionoverlay
spellingShingle Giseok Jeong
Kookjin Kim
Sukjoon Yoon
Dongkyoo Shin
Jiwon Kang
Exploring Effective Approaches to the Risk Management Framework (RMF) in the Republic of Korea: A Study
Information
risk management framework (RMF)
cyber risk
cyber security
system classification
security control selection
overlay
title Exploring Effective Approaches to the Risk Management Framework (RMF) in the Republic of Korea: A Study
title_full Exploring Effective Approaches to the Risk Management Framework (RMF) in the Republic of Korea: A Study
title_fullStr Exploring Effective Approaches to the Risk Management Framework (RMF) in the Republic of Korea: A Study
title_full_unstemmed Exploring Effective Approaches to the Risk Management Framework (RMF) in the Republic of Korea: A Study
title_short Exploring Effective Approaches to the Risk Management Framework (RMF) in the Republic of Korea: A Study
title_sort exploring effective approaches to the risk management framework rmf in the republic of korea a study
topic risk management framework (RMF)
cyber risk
cyber security
system classification
security control selection
overlay
url https://www.mdpi.com/2078-2489/14/10/561
work_keys_str_mv AT giseokjeong exploringeffectiveapproachestotheriskmanagementframeworkrmfintherepublicofkoreaastudy
AT kookjinkim exploringeffectiveapproachestotheriskmanagementframeworkrmfintherepublicofkoreaastudy
AT sukjoonyoon exploringeffectiveapproachestotheriskmanagementframeworkrmfintherepublicofkoreaastudy
AT dongkyooshin exploringeffectiveapproachestotheriskmanagementframeworkrmfintherepublicofkoreaastudy
AT jiwonkang exploringeffectiveapproachestotheriskmanagementframeworkrmfintherepublicofkoreaastudy