Skip to content
Secure Open Solutions

Home / Details

RMF / ATO

Connect mission requirements and the system boundary to the selected control baseline, authorization evidence, and ongoing monitoring.

RMF / ATO reference diagram
Reference illustration. Select the image to send an inquiry or schedule an appointment. Service configuration and control responsibilities are validated for the actual deployment.

Authorization workstream

  • Define the system and its dependencies, categorization inputs, and authorization strategy.
  • Allocate internal, inherited, and shared responsibilities; tailor the baseline with the authorizing organization.
  • Prepare implementation narratives, assessment evidence, findings and POA&M records.

Deliverables

  • System boundary and control-responsibility mapping.
  • SSP, assessment preparation and authorization-package support.
  • eMASS workstream coordination and continuous-monitoring plan.

What SOS needs from the customer

A system owner, authorization stakeholders, existing package artifacts, provider inheritance evidence, and access to the personnel responsible for implementation.