{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:fb1370c15e42a8a84603dd92914c3f91d5edd898296476d2cafb967d88ebb215","slug":"controls-rmf-system-authorization-ato","url":"/assets/agent_workflow-controls-rmf-system-authorization-ato-533f851a.5258df8c3bdda0df.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"monitor"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-rmf-system-authorization-ato","description":"Runs the seven NIST SP 800-37r2 RMF phases — Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor — against a single information system to reach and then sustain an authorization-to-operate (ATO) decision. The cycle is anchored on an Audit item created per authorization (\"RMF ATO Cycle — <system> <year>\", audit_type=it_audit, scope=the authorization boundary, period_start/period_end=the AO decision calendar); the information system itself is enriched as an existing Process item (process_type=security_process). Studio has no System/Asset type, so the RMF-specific facts (FIPS 199 categorization, selected baseline, ATO decision, authorization-termination date) live in the phase documents and on the Audit anchor rather than in dedicated fields. In scope: the defined authorization boundary and its inherited, hybrid, and system-specific controls (existing Control items). Out of scope: enterprise-wide common-control-provider programs and standalone penetration testing, which run as their own engagements and are consumed here only as assessment evidence. Named deliverables: the FIPS 199 categorization memo, the System Security Plan (SSP), the Security Assessment Report (SAR), the Plan of Action & Milestones (POA&M), and the signed ATO letter — assembled into one authorization package for the authorizing official. No upstream workflow feeds this cycle; it originates at Prepare. Downstream it hands off to itself: the Monitor phase's reauthorization triggers re-instantiate this template against the same system, and the Monitor phase's closing export is the authorization record the next cycle's Prepare consumes.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-rmf-system-authorization-ato","capabilities":[],"controls":["UC-AUDIT-26","UC-RISK-18","UC-GOV-16","UC-GOV-18","UC-AUDIT-21"],"domains":["controls"],"lineOfDefense":"monitor","mappingStatus":"mapped","releaseId":"sha256:fb1370c15e42a8a84603dd92914c3f91d5edd898296476d2cafb967d88ebb215","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-rmf-system-authorization-ato","standards":["nist-800-53"],"teams":["it","compliance-legal"]},"id":"wf:C8","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC8","slug":"controls-rmf-system-authorization-ato","sourceIds":["cobit-2019","coso-ic","nist-800-53","soc2","sox"],"sourceUrl":null,"title":"NIST RMF System Authorization (ATO) Cycle","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7ba3e9072ed91dfeb660e6a18b40a5be5ecf201999fd6b8d0e1fb5f2078b346a","properties":{},"sourceDetailPath":"/data/v1/records/wf-c8-5634a289.json","sourceId":"wf:C8","targetDetailPath":"/data/v1/records/uc-uc-audit-21-6406caa4.json","targetId":"uc:UC-AUDIT-21","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8dd535accf8acac48be78be5022ebf3653a4328f2935c9447d4ee66333c0bc93","properties":{},"sourceDetailPath":"/data/v1/records/wf-c8-5634a289.json","sourceId":"wf:C8","targetDetailPath":"/data/v1/records/uc-uc-gov-16-694834ac.json","targetId":"uc:UC-GOV-16","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:caaafc8ae2efca7395f7a592060cdb4c5314ba5fc9dcbc1d32bd7f17d44b39e3","properties":{},"sourceDetailPath":"/data/v1/records/wf-c8-5634a289.json","sourceId":"wf:C8","targetDetailPath":"/data/v1/records/uc-uc-risk-18-23752e70.json","targetId":"uc:UC-RISK-18","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e956d7c0c0a232e3f93b04e9035118e5d4aa77ac7f0195f32b78164a5751de2e","properties":{},"sourceDetailPath":"/data/v1/records/wf-c8-5634a289.json","sourceId":"wf:C8","targetDetailPath":"/data/v1/records/uc-uc-audit-26-3a91d068.json","targetId":"uc:UC-AUDIT-26","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fe2957ce765e5a57e0909a847061718ef86bdf9a97229035ad1a67b34ee9e93d","properties":{},"sourceDetailPath":"/data/v1/records/wf-c8-5634a289.json","sourceId":"wf:C8","targetDetailPath":"/data/v1/records/uc-uc-gov-18-680359d2.json","targetId":"uc:UC-GOV-18","type":"oversees"}],"schemaVersion":1}
