workflow

NIST RMF System Authorization (ATO) Cycle

Runs the seven NIST SP 800-37r2 RMF phases — Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor — against a single information system to reach and then sustain an authorization-to-operate (ATO) decision. The cycle is anchored on an Audit item created per authorization ("RMF ATO Cycle — <system> <year>", audit_type=it_audit, scope=the authorization boundary, period_start/period_end=the AO decision calendar); the information system itself is enriched as an existing Process item (process_type=security_process). Studio has no System/Asset type, so the RMF-specific facts (FIPS 199 categorization, selected baseline, ATO decision, authorization-termination date) live in the phase documents and on the Audit anchor rather than in dedicated fields. In scope: the defined authorization boundary and its inherited, hybrid, and system-specific controls (existing Control items). Out of scope: enterprise-wide common-control-provider programs and standalone penetration testing, which run as their own engagements and are consumed here only as assessment evidence. Named deliverables: the FIPS 199 categorization memo, the System Security Plan (SSP), the Security Assessment Report (SAR), the Plan of Action & Milestones (POA&M), and the signed ATO letter — assembled into one authorization package for the authorizing official. No upstream workflow feeds this cycle; it originates at Prepare. Downstream it hands off to itself: the Monitor phase's reauthorization triggers re-instantiate this template against the same system, and the Monitor phase's closing export is the authorization record the next cycle's Prepare consumes.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
controls
department
it
lineOfDefense
monitor

Details

teams
  • it
  • compliance-legal
domains
  • controls
standards
  • nist-800-53
sourceTemplateId
workflow-library:controls-rmf-system-authorization-ato
releaseId
sha256:fb1370c15e42a8a84603dd92914c3f91d5edd898296476d2cafb967d88ebb215
canonicalUrl
https://workflow-library.com/all/?w=controls-rmf-system-authorization-ato
capabilities
    mappingStatus
    mapped
    lineOfDefense
    monitor
    controls
    • UC-AUDIT-26
    • UC-RISK-18
    • UC-GOV-16
    • UC-GOV-18
    • UC-AUDIT-21
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:fb1370c15e42a8a84603dd92914c3f91d5edd898296476d2cafb967d88ebb215

            Connections