Product · Continuous Monitoring

CertiField is often worth more after the ATO than during it.

Getting authorized is a project. Staying authorized is an operation — and it is the part that runs on spreadsheets, calendar reminders and the memory of whoever has been there longest. This is the part CertiField was built for.

  • Inventory drift
  • STIG applicability
  • Evidence continuity
  • Review campaigns
  • Planner
Ref
P-51
Kind
Entry
Import
eMASS baseline + POA&M

Bring the authorization you already have forward.

You do not start over. Import the current state from eMASS — control information, per-CCI test results, POA&M items and inventory — and CertiField holds it as the authorization record from that point on. Imported metadata is labeled as imported, including inheritance recorded upstream, so nobody mistakes somebody else's assertion for a determination made here.

  • Control information and implementation state
  • Per-CCI test results as assessed upstream
  • POA&M items keyed on their external identifier
  • Inventory as the first snapshot to measure drift against
Ref
P-52
Kind
Drift
Measured
snapshot to snapshot

Inventory drift, measured rather than noticed.

Each inventory snapshot is kept, and the delta between two of them is computed rather than eyeballed. What appeared, what disappeared, and what changed underneath a name that stayed the same — that last one being the category that reliably escapes a manual comparison.

Drift is the signal that turns into work: new technology means new STIG applicability, a removed component means evidence that no longer describes anything, and a changed version means a control implementation statement that may have just become untrue.

Ref
P-53
Kind
STIG
Source
DISA catalog sync
Offline
air-gap bundle

STIG applicability against the technologies you actually run.

CertiField syncs the DISA STIG catalog, then ranks applicability against the system's inventory and the technologies your team has recorded by hand. Updates merge into existing checklists rather than replacing them, so the work already done on a checklist survives the next catalog release.

Dismissals are recorded as decisions with a reason, not as a filter somebody applied and forgot. A STIG that does not apply to this system stays not-applicable, and the record says who decided that.

In a disconnected enclave

The catalog bundle carries AI-derived relevance profiles with it, so an enclave running with AI switched off still gets applicability ranking of the same quality. Isolation does not have to cost you the useful part.

Running disconnected →
STIG applicability suggestions ranked per technology. Windows Server, Red Hat Enterprise Linux, Windows 11, Microsoft Defender, Azure SQL Database, Docker Engine, Cisco Catalyst, Ubuntu Server and VMware ESXi each show a rule count broken down into high, medium and low severity, drawn from a relevance catalog of 283 profiles.
667 suggested STIG rules ranked against the 26 technologies this system actually runs, each broken down by severity and each awaiting a human decision to accept or dismiss. Ranking here was run against a local model. System · STIG Suggestions
Ref
P-54
Kind
Cadence
Planner
plans → occurrences → campaigns

Reviews on a cadence, not on a reminder.

A review plan schedules occurrences; an occurrence becomes a campaign; a campaign carries its impacts down to the controls and CCIs it touched. That chain is what turns "we review annually" into something an assessor can verify actually happened, at the granularity it happened at.

Evidence continuity runs alongside it: evidence that is ageing out, controls whose supporting artifacts no longer reflect the system, and determinations resting on both. Better to find that before the review than during it.

Ref
P-55
Kind
Assurance
Audit
hash-chained events
Checked
nightly

An audit record that can prove it was not edited.

Every data modification, privileged access and authentication event is written to an audit log where each row carries a hash of itself and of the row before it. Breaking the chain requires rewriting everything after the point of tampering, and the chain's integrity is verified on a nightly job rather than at the moment somebody asks.

Events carry the UTC timestamp, the actor, the action, the target, the result and a correlation identifier — and deliberately do not carry secrets or sensitive payloads, because an audit log that leaks is a different kind of finding.

Next step

See what your RMF process looks like when the package keeps up with the system.