Integrations

Keep your systems of record. Make them easier to feed.

CertiField is the operational layer between the systems producing security evidence and the systems receiving authorization data. It is not trying to replace either end, and it does not ask your program to abandon the repository it is already required to use.

  • eMASS round-trip
  • GitHub · GitLab
  • Jira
  • DISA STIG catalog
  • CycloneDX SBOM
  • OSCAL
Ref
I-01
Kind
Position

Upstream of your authorization repository. Downstream of your engineering.

System reality

What engineering actually produces

  • Architecture
  • Inventory
  • DISA STIGs
  • Scan results
  • SBOMs
  • CI/CD pipelines
  • Evidence

CertiField

The operational RMF layer

  • Controls
  • Evidence
  • Assessments
  • Determinations
  • Findings
  • POA&M

Authorization

What reviewers and systems receive

  • SSP
  • SAR
  • POA&M
  • Authorization package
  • OSCAL
  • eMASS

Next step

See what your RMF process looks like when the package keeps up with the system.