workflow
NIST RMF System Authorization (ATO) Cycle
Runs the seven NIST SP 800-37r2 RMF phases — Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor — against a single information system to reach and then sustain an authorization-to-operate (ATO) decision. The cycle is anchored on an Audit item created per authorization ("RMF ATO Cycle — <system> <year>", audit_type=it_audit, scope=the authorization boundary, period_start/period_end=the AO decision calendar); the information system itself is enriched as an existing Process item (process_type=security_process). Studio has no System/Asset type, so the RMF-specific facts (FIPS 199 categorization, selected baseline, ATO decision, authorization-termination date) live in the phase documents and on the Audit anchor rather than in dedicated fields. In scope: the defined authorization boundary and its inherited, hybrid, and system-specific controls (existing Control items). Out of scope: enterprise-wide common-control-provider programs and standalone penetration testing, which run as their own engagements and are consumed here only as assessment evidence. Named deliverables: the FIPS 199 categorization memo, the System Security Plan (SSP), the Security Assessment Report (SAR), the Plan of Action & Milestones (POA&M), and the signed ATO letter — assembled into one authorization package for the authorizing official. No upstream workflow feeds this cycle; it originates at Prepare. Downstream it hands off to itself: the Monitor phase's reauthorization triggers re-instantiate this template against the same system, and the Monitor phase's closing export is the authorization record the next cycle's Prepare consumes.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- it
- lineOfDefense
- monitor
Details
- teams
- it
- compliance-legal
- domains
- controls
- standards
- nist-800-53
- sourceTemplateId
- workflow-library:controls-rmf-system-authorization-ato
- releaseId
- sha256:fb1370c15e42a8a84603dd92914c3f91d5edd898296476d2cafb967d88ebb215
- canonicalUrl
- https://workflow-library.com/all/?w=controls-rmf-system-authorization-ato
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- monitor
- controls
- UC-AUDIT-26
- UC-RISK-18
- UC-GOV-16
- UC-GOV-18
- UC-AUDIT-21
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:fb1370c15e42a8a84603dd92914c3f91d5edd898296476d2cafb967d88ebb215
Connections
- NIST RMF System Authorization (ATO) Cycle oversees UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- NIST RMF System Authorization (ATO) Cycle oversees UC-GOV-16 — Select and tailor a risk-based control baseline
- NIST RMF System Authorization (ATO) Cycle oversees UC-RISK-18 — Categorize systems and components by impact and criticality
- NIST RMF System Authorization (ATO) Cycle oversees UC-AUDIT-26 — Authorize systems and internal connections before operation
- NIST RMF System Authorization (ATO) Cycle oversees UC-GOV-18 — Document and approve system security and privacy plans