The NIST Risk Management Framework (RMF) is a 7-step process that you can use to architect and engineer a security program for your IT systems and data. Though not prescriptive, the RMF suggests best practices your organization should follow to identify, categorize, and secure your information systems and to protect your data. This session will take the mystery (and fear) out of how an information security program is established. It will clarify roles and responsibilities and give you a number of steps to take to ensure that your systems are secure, your data is protected, and your clients' privacy is maintained. At the end of this session attendees will: Understand the fundamental NIST Risk Management Framework principle; Know EXACTLY where to begin to establish your new information security program; Know how to identify gaps in your existing information security program; Understand the roles and responsibilities involved in an Information Security program; Have a solid foundation on which you can justify, prioritize, and build your data security strategy; and Leave with actionable "Next Steps" and a list of resources to move you forward.