---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Use

# Use {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

To provide CAM services, you implement the seven steps defined by the NIST Risk Management Framework (RMF), implement controls and assessment objectives, and perform continuous authorization and
monitoring.
1. [RMF step 0 - Prepare the authorization package](https://servicenow-prod.fluidtopics.net/o6SOPSb4GfhXKroXfPM_9w "In the Prepare step, you set up authorization boundaries, control overlays, and information types, as well as create the actual authorization package.")

   In the Prepare step, you set up authorization boundaries, control overlays, and information types, as well as create the actual authorization package.
2. [RMF step 1 - Categorize the authorization package](https://servicenow-prod.fluidtopics.net/TU48BCxKS9Z~SSxAjw3yoA "In the Categorize step, you define the criticality or sensitivity of your information system according to potential worst-case scenarios. This involves selecting NIST information types for the package and using the information types to define the impact levels for the package.")

   In the Categorize step, you define the criticality or sensitivity of your information system according to potential worst-case scenarios.
   This involves selecting NIST information types for the package and using the information types to define the impact levels for the package.
3. [RMF step 2 - Select controls for an authorization package](https://servicenow-prod.fluidtopics.net/B_JXRWQun04ihCkxwx7xIA "When the impact levels for the package have been approved, it is time to select baseline controls.")

   When the impact levels for the package have been approved, it is time to select baseline controls.
4. [RMF step 3 - Implement controls](https://servicenow-prod.fluidtopics.net/OoLmpYXk~ahwg3ekT_QgDQ "After you have selected controls for implementation and performed any of the possible actions on them, you can implement the controls.")

   After you have selected controls for implementation and performed any of the possible actions on them, you can implement the controls.
5. [RMF steps 4, 5, and 6 - Assess, authorize, and monitor](https://servicenow-prod.fluidtopics.net/jjDBTKs8Q8M7W4KfHMQg~w "After you have implemented controls, you can assess internal and external controls, generate Plans of Action and Milestones (POA&M), and manage change requests and vulnerable items.")

   After you have implemented controls, you can assess internal and external controls, generate Plans of Action and Milestones (POA\&M), and manage change requests and vulnerable items.
6. [Implement controls and assessment objectives](https://servicenow-prod.fluidtopics.net/jOH3AvlbEUp2thXOwl5gNQ "NIST 800-53A – assessment objectives are included in the base system with the CAM application. The assessment objectives are mapped to revision 5 control objectives.")

   NIST 800-53A -- assessment objectives are included in the base system with the CAM application. The assessment objectives are mapped to revision 5 control objectives.
7. [Continuous authorization and monitoring tasks in the CAM Workspace](https://servicenow-prod.fluidtopics.net/Lyt~253dw3cefHLpxH6OiQ "The CAM Workspace is a centralized hub where you can continuously monitor and manage compliance with the NIST Risk Management Framework to ensure adherence to your security policies and guidelines.")

   The CAM Workspace is a centralized hub where you can continuously monitor and manage compliance with the NIST Risk Management Framework to ensure adherence to your security policies and guidelines.
{#using-grc-cam__cf-using-parent-steps-ol}

