Operate the cross-cutting roles and functions defined throughout NIST SP 800-37 Rev 2 Chapter 2 (Fundamentals). Cross-cutting elements include (a) RMF Roles per Chapter 2 (Risk Executive Function + Chief Information Officer + Senior Agency Information Security Officer + Senior Agency Privacy Officer + Authorising Official + System Owner + Common Control Provider + Control Assessor + Information System Security Officer + Mission/Business Owner + Information Owner/Steward), (b) Risk Executive Function aggregating risk across systems for organisational risk decisions, (c) Automation enabling Ongoing Authorisation (OSCAL + configuration scanning + control inheritance evidence + continuous monitoring telemetry), (d) Privacy Integration with security in every step (joint SSPP + joint SAR + joint POAM where privacy controls apply), (e) Supply Chain Risk Management (SCRM) integration per NIST SP 800-161 with control selection (S-2) + assessment (A-4) + ongoing monitoring (M-1), (f) ATO maintenance covering ongoing authorisation + significant change re-authorisation + authorisation termination on disposal. These cross-cutting elements determine whether RMF execution is genuinely organisation-wide or limited to system-by-system paperwork.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.