Product

One authorization record. Everything else is an output of it.

CertiField is not a document generator with an RMF workflow attached. It holds the authorization record for a system — and the SSP, SAR, POA&M, OSCAL output and authorization package are what that record emits.

  • System authorization boundary
  • NIST SP 800-53 Rev 5
  • FIPS 199
  • OSCAL
  • DISA STIGs
  • eMASS
Ref
P-02
Kind
Lifecycle

Categorization through continuous monitoring.

CertiField covers the RMF steps a program actually operates day to day, and keeps one consistent record across all of them.

  1. Categorize

    FIPS 199 impact levels, the high-water mark, and the system narratives that describe what is being authorized.

  2. Select

    NIST SP 800-53 Rev 5 baselines seeded from the NIST OSCAL catalog, tailored into a per-system control set.

  3. Implement

    Implementation statements, evidence, STIG applicability and the engineering data behind each control.

  4. Assess

    Assessment procedures, per-CCI results, determinations and findings, each bound to what it was assessed against.

  5. Authorize

    SSP, SAR, POA&M and the authorization package, generated from the record rather than assembled beside it.

  6. Monitor

    Architecture change, inventory drift, evidence continuity and the reassessment scope each of them creates.

Next step

See what your RMF process looks like when the package keeps up with the system.