Skip to main content

Military Health System

Test of Sitewide Banner

This is a test of the sitewide banner capability. In the case of an emergency, site visitors would be able to visit the news page for addition information.

Risk Management Framework

The Defense Health Agency has a process called the Risk Management Framework (RMF). This process is provided by the Risk Management Executive Division for Information System (IS) and Platform IT (PIT) Systems. 

The RMF provides a structured process. It combines IS security and risk management activities into the system development lifecycle. It also authorizes their use within DOD and DHA. It provides you the capabilities to effectively manage information security risks. This includes ever-increasing system vulnerabilities and sophisticated cyber threats in diverse environments. 

We established the DHA RMF Portal to give guidance, templates, and training to the Information System Security Managers (ISSMs).

The RMF Interactive Workflow Diagram shows the requirements for assessment and authorization. This is a high level guide. It works with other DHA RMF guides available to ISSMs. 


You also may be interested in...

Risk Management Framework Process Workflow


The RMF is the process that the Information System Security Managers use to get and maintain an Authority To Operate (ATO).

DODI 8510.01: Risk Management Framework (RMF) for DoD Information Technology (IT)


This Instruction reissues and renames DOD Instruction (DODI) 8510.01 in accordance with the authority in DOD Directive (DODD) 5144.02. It also establishes the RMF for DoD IT (referred to in this Instruction as “the RMF”), establishing associated cybersecurity policy, and assigning responsibilities for executing and maintaining the RMF.

Page 1 of 1 , showing items 1 - 2
Last Updated: September 02, 2022
Follow us on Instagram Follow us on LinkedIn Follow us on Facebook Follow us on Twitter Follow us on YouTube Sign up on GovDelivery