NIST Risk Management Framework
The authorization is a risk decision. Our job is to make it an easy one.
FISMA requires federal agencies (and the organizations that run systems on their behalf) to operate under the NIST Risk Management Framework. An Authorizing Official grants an Authorization to Operate based on three things: what the System Security Plan claims, what the Security Assessment Report found, and what the Plan of Action & Milestones commits to fixing.
DASATECH performs the independent assessment and produces those artifacts. We begin with a preliminary review to establish where you actually stand against the selected baseline, then execute the assessment against NIST SP 800-53A procedures (examination, interview and test), documenting each control as satisfied or other than satisfied with the evidence to back it.
Where the RMF cycle has stalled partway through, we join it at the current step rather than restarting it.
- Is the system boundary defined, and does the architecture diagram match it?
- Which FIPS 199 impact level applies, and was it derived from SP 800-60 information types?
- Has the Rev. 5 baseline been tailored, and is the tailoring justified in writing?
- Are inherited controls documented with a current customer responsibility matrix?
- Does an existing POA&M have owners, dates and remediation detail?
Steps 1 to 6 run once per authorization. Step 7 never stops, and it is what keeps the ATO valid.
How it runs
Engagement sequence
Preliminary gap review
We review existing documentation and architecture against the selected baseline to establish a starting position and identify the controls most likely to fail.
Assessment planning
Scope, sampling approach, test procedures and evidence requests are agreed in the Security Assessment Plan before any testing begins.
Control testing
Examination of artifacts, interviews with control owners and technical testing against SP 800-53A procedures, with weekly status on emerging findings.
Reporting
Findings are documented in the SAR, risk-rated, and translated into a POA&M with practical remediation recommendations rather than restated control text.
Authorization support
We brief the AO, answer reviewer questions, and support remediation and retest of findings that block the decision.
Deliverables
What you receive
Every document is produced in the template the receiving party expects, and is written to be read by an assessor rather than filed.
- SAPSecurity Assessment Plan, delivered and agreed before assessment kickoff
- SARSecurity Assessment Report with per-control results and supporting evidence
- POA&MPlan of Action & Milestones with remediation recommendations for every other-than-satisfied control and scan finding
- RTMRequirements traceability matrix mapping controls to evidence
- BRIEFExecutive risk briefing prepared for the Authorizing Official
- SSPSystem Security Plan development or remediation, where required
Example values. What the shape shows is real practice: findings are raised as they emerge, so remediation starts before the SAR is issued.
Outcome
What changes after the engagement
- You hold a defensible, evidence-backed assessment rather than a self-attestation
- The AO receives the three artifacts the decision actually requires, in the expected form
- Remediation work is prioritized by risk, not by control number
- Your security posture improves in the places that were genuinely weak
- Agencies and primes see an organization that can operate inside federal expectations
Tell us what the contract requires. We’ll tell you what it takes.
A 30-minute scoping call is usually enough to size the gap, name the deliverables and give you a realistic date for authorization.
