RMF Lifecycle Management: Minimum of 5–7 years of direct experience performing Information System Security Manager (ISSM) or Officer (ISSO) duties, specifically navigating the Risk Management Framework (RMF) steps 1–6. Valid certifications include: CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), CGRC / CAP (Certified in Governance, Risk, and Compliance), CASP+ (CompTIA Advanced Security Practitioner).