RMF, ATO and continuous authorization
How do you get a federal system to an Authority to Operate, and keep it there?
Through the Risk Management Framework in NIST SP 800-37: prepare, categorize the system, select and implement controls from NIST SP 800-53, assess them, obtain authorization and monitor continuously. We lead that work for federal programs and integrators, including national security systems under CNSS 1253.
RMF, ATO and continuous authorization leadership for federal programs and integrators, across NIST SP 800-53 and CNSS 1253.
Book a 30 minute callWhat does the engagement include?
- System categorization and boundary definition
- Control selection and tailoring from NIST SP 800-53 and CNSS 1253
- System Security Plan authorship
- Assessment support against NIST SP 800-53A
- An authorization package for the authorizing official
- Continuous monitoring, vulnerability management and STIG management
Who is this for?
Federal program offices and the integrators supporting them that need to authorize a new system, recover a stalled ATO or move to continuous authorization.
What do you get?
How does the engagement run?
- A 30 minute call about your contracts, your deadline and where your sensitive data lives.
- A written scope that names the deliverables, the schedule and who does what.
- A kickoff with your leadership and your IT provider, then regular progress briefings until the deliverables are accepted.
No consultant can promise the outcome of an assessment or authorization. The assessor or authorizing official decides it.
What else do buyers ask?
What is the difference between RMF and CMMC?
RMF is how federal agencies authorize their own systems, using NIST SP 800-53 controls and an authorizing official's decision. CMMC verifies that contractors protect CUI on their own systems, using NIST SP 800-171. Some integrators need both.
What is continuous authorization?
Instead of reauthorizing a system on a fixed cycle, the organization monitors its controls continuously and reports to the authorizing official, so the authorization stays current. It depends on a mature continuous monitoring program.
Which control baselines do you work with?
NIST SP 800-53 and SP 800-53A, CNSS 1253 for national security systems, and FISMA reporting requirements.
Ready to talk it through?
BOOK A CALLPick a time for a 30 minute call with the practice.
What happens in 30 minutes
- We learn about your company, the contracts you hold or are bidding on, and what is driving your timeline.
- We talk through where you stand and which engagement fits, if any does.
- If there is a fit, we follow up with a written scope. No slides.