The department has implemented the NIST Risk Management Framework (RMF) and requires information security expertise to assist with creating, revising, and managing RMF-related documentation, as well as preparing for independent system assessments. The information system is audited by the Social Security Administration and other entities to ensure appropriate security controls are in place to protect sensitive information.