Good point. However, RMF if done correctly can help justify security budget requests. Downplaying risks or not identifying the right risks can have catastrophic outcomes. In addition, NIST also provides guidance in selecting the right information and information system categorization in SP 800-60 Vol1 and Vol2. Once the security categorization is done right, risk based control baseline tailoring is another critical step that requires a good mindset.