Product · Continuous Monitoring
CertiField is often worth more after the ATO than during it.
Getting authorized is a project. Staying authorized is an operation — and it is the part that runs on spreadsheets, calendar reminders and the memory of whoever has been there longest. This is the part CertiField was built for.
- Inventory drift
- STIG applicability
- Evidence continuity
- Review campaigns
- Planner
- Ref
- P-51
- Kind
- Entry
- Import
- eMASS baseline + POA&M
Bring the authorization you already have forward.
You do not start over. Import the current state from eMASS — control information, per-CCI test results, POA&M items and inventory — and CertiField holds it as the authorization record from that point on. Imported metadata is labeled as imported, including inheritance recorded upstream, so nobody mistakes somebody else's assertion for a determination made here.
- Control information and implementation state
- Per-CCI test results as assessed upstream
- POA&M items keyed on their external identifier
- Inventory as the first snapshot to measure drift against
- Ref
- P-52
- Kind
- Drift
- Measured
- snapshot to snapshot
Inventory drift, measured rather than noticed.
Each inventory snapshot is kept, and the delta between two of them is computed rather than eyeballed. What appeared, what disappeared, and what changed underneath a name that stayed the same — that last one being the category that reliably escapes a manual comparison.
Drift is the signal that turns into work: new technology means new STIG applicability, a removed component means evidence that no longer describes anything, and a changed version means a control implementation statement that may have just become untrue.
- Ref
- P-53
- Kind
- STIG
- Source
- DISA catalog sync
- Offline
- air-gap bundle
STIG applicability against the technologies you actually run.
CertiField syncs the DISA STIG catalog, then ranks applicability against the system's inventory and the technologies your team has recorded by hand. Updates merge into existing checklists rather than replacing them, so the work already done on a checklist survives the next catalog release.
Dismissals are recorded as decisions with a reason, not as a filter somebody applied and forgot. A STIG that does not apply to this system stays not-applicable, and the record says who decided that.
In a disconnected enclave
The catalog bundle carries AI-derived relevance profiles with it, so an enclave running with AI switched off still gets applicability ranking of the same quality. Isolation does not have to cost you the useful part.
Running disconnected →
- Ref
- P-54
- Kind
- Cadence
- Planner
- plans → occurrences → campaigns
Reviews on a cadence, not on a reminder.
A review plan schedules occurrences; an occurrence becomes a campaign; a campaign carries its impacts down to the controls and CCIs it touched. That chain is what turns "we review annually" into something an assessor can verify actually happened, at the granularity it happened at.
Evidence continuity runs alongside it: evidence that is ageing out, controls whose supporting artifacts no longer reflect the system, and determinations resting on both. Better to find that before the review than during it.
- Ref
- P-55
- Kind
- Assurance
- Audit
- hash-chained events
- Checked
- nightly
An audit record that can prove it was not edited.
Every data modification, privileged access and authentication event is written to an audit log where each row carries a hash of itself and of the row before it. Breaking the chain requires rewriting everything after the point of tampering, and the chain's integrity is verified on a nightly job rather than at the moment somebody asks.
Events carry the UTC timestamp, the actor, the action, the target, the result and a correlation identifier — and deliberately do not carry secrets or sensitive payloads, because an audit log that leaks is a different kind of finding.
Next step