ISO/IEC 17020 accredited inspection body · Cleared facility (FCL)
Home / Services / FISMA Assessment & Authorization

FISMA · Risk Management Framework

FISMA Security Assessment & Authorization

Independent assessment of your control implementation, and the package that turns it into an authorization decision.

NIST Risk Management Framework

The authorization is a risk decision. Our job is to make it an easy one.

FISMA requires federal agencies (and the organizations that run systems on their behalf) to operate under the NIST Risk Management Framework. An Authorizing Official grants an Authorization to Operate based on three things: what the System Security Plan claims, what the Security Assessment Report found, and what the Plan of Action & Milestones commits to fixing.

DASATECH performs the independent assessment and produces those artifacts. We begin with a preliminary review to establish where you actually stand against the selected baseline, then execute the assessment against NIST SP 800-53A procedures (examination, interview and test), documenting each control as satisfied or other than satisfied with the evidence to back it.

Where the RMF cycle has stalled partway through, we join it at the current step rather than restarting it.

Common scoping questions
  • Is the system boundary defined, and does the architecture diagram match it?
  • Which FIPS 199 impact level applies, and was it derived from SP 800-60 information types?
  • Has the Rev. 5 baseline been tailored, and is the tailoring justified in writing?
  • Are inherited controls documented with a current customer responsibility matrix?
  • Does an existing POA&M have owners, dates and remediation detail?
1PREPARE2CATEGORIZE3SELECT4IMPLEMENT5ASSESS6AUTHORIZE7MONITORRMFSP 800-37 REV. 2STEP 7 IS CONTINUOUS
The seven-step Risk Management Framework. DASATECH executes the full cycle, or joins a stalled one at its current step.

Steps 1 to 6 run once per authorization. Step 7 never stops, and it is what keeps the ATO valid.

How it runs

Engagement sequence

Preliminary gap review

1–2 weeks

We review existing documentation and architecture against the selected baseline to establish a starting position and identify the controls most likely to fail.

Assessment planning

1 week

Scope, sampling approach, test procedures and evidence requests are agreed in the Security Assessment Plan before any testing begins.

Control testing

3–5 weeks

Examination of artifacts, interviews with control owners and technical testing against SP 800-53A procedures, with weekly status on emerging findings.

Reporting

1–2 weeks

Findings are documented in the SAR, risk-rated, and translated into a POA&M with practical remediation recommendations rather than restated control text.

Authorization support

As needed

We brief the AO, answer reviewer questions, and support remediation and retest of findings that block the decision.

Deliverables

What you receive

Every document is produced in the template the receiving party expects, and is written to be read by an assessor rather than filed.

  • SAPSecurity Assessment Plan, delivered and agreed before assessment kickoff
  • SARSecurity Assessment Report with per-control results and supporting evidence
  • POA&MPlan of Action & Milestones with remediation recommendations for every other-than-satisfied control and scan finding
  • RTMRequirements traceability matrix mapping controls to evidence
  • BRIEFExecutive risk briefing prepared for the Authorizing Official
  • SSPSystem Security Plan development or remediation, where required
0204060 SAR ISSUEDRETESTW0W4W8W12W16 OPEN FINDINGS BY ENGAGEMENT WEEK
POA&M burndown across a typical sixteen-week engagement.

Example values. What the shape shows is real practice: findings are raised as they emerge, so remediation starts before the SAR is issued.

Outcome

What changes after the engagement

  • You hold a defensible, evidence-backed assessment rather than a self-attestation
  • The AO receives the three artifacts the decision actually requires, in the expected form
  • Remediation work is prioritized by risk, not by control number
  • Your security posture improves in the places that were genuinely weak
  • Agencies and primes see an organization that can operate inside federal expectations

Tell us what the contract requires. We’ll tell you what it takes.

A 30-minute scoping call is usually enough to size the gap, name the deliverables and give you a realistic date for authorization.