Skip to content
Cloud WaypointCloud modernization & authorization preparation

Detailed reference · framework navigator

One spine. Different paths to confidence.

Follow the RMF lifecycle and open a governing path at each stage to see the people, process, technology, artifacts and examples.

← Back to The Process · Read the lifecycle guide →

NIST RMF seven-step crosswalk

The nine-stage Cloud Waypoint spine adds delivery detail without creating another framework. These links show where each NIST RMF step is prepared; the governing organization retains tailoring, assessment, risk, and authorization authority.

  1. Prepare

    Set roles, priorities, context, sources, and the authorization approach.

    Authority · Framework
  2. Categorize

    Establish the system boundary, information types, impact, dependencies, and data flows.

    Boundary
  3. Select

    Choose and tailor the control baseline, overlays, inheritance, and responsibilities.

    Requirements
  4. Implement

    Put selected controls and supporting operating work into effect and document how they work.

    Implementation
  5. Assess

    Collect evidence, test implementation, record findings, and preserve assessor independence.

    Evidence · Assessment
  6. Authorize

    Give the designated authorizing official the evidence, conditions, and residual risk record for a decision.

    Risk decision
  7. Monitor

    Maintain evidence, configuration, vulnerabilities, changes, incidents, remediation, and authorization impact.

    Continuity

01 · Authority

Who sets risk tolerance and who may decide?

DoD RMF · DoD mission authorization

Formal authorization pathway. NIST RMF implemented through DoD policy. Cloud and cyber services contribute evidence; the mission AO retains the system authorization decision.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Authorizing Official (AO)
  • System owner
  • CIO
  • ISSM / ISSO
  • Security Control Assessor (SCA)

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Risk tolerance
  • RMF role assignment
  • Mission and business context

Technology

No separate item at this stage.

Artifacts

Cloud Foundations contributes to this area.

  • Authorization strategy Cloud Foundations work product
  • Role and authority record Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • AO names the decision boundary
  • System owner funds remediation
Federal RMF · Federal civilian system authorization

Formal authorization pathway. The same NIST RMF spine, applied through FISMA, OMB direction, and each agency’s authorization policy.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Agency AO
  • CIO
  • CISO
  • System owner
  • Common-control provider

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Organization and system risk management

Technology

No separate item at this stage.

Artifacts

Cloud Foundations contributes to this area.

  • Agency authorization strategy Cloud Foundations work product
  • Risk-management roles Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Agency policy defines delegations and review gates
FedRAMP High · FedRAMP High cloud reuse

Cloud-service evidence plus agency authorization. FedRAMP High provides a reusable cloud-service security package. The agency still authorizes the federal information system and its specific use of the service.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Cloud Service Provider (CSP)
  • Third Party Assessment Organization (3PAO)
  • FedRAMP
  • Agency AO
  • Agency system owner

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Choose authorization path
  • Establish agency partnership and reuse strategy

Technology

No separate item at this stage.

Artifacts

Cloud Foundations contributes to this area.

  • Authorization plan Cloud Foundations work product
  • Partnership record Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Agency identifies the cloud service as an external service
FedRAMP provider · Commercial cloud and service provider certification

Commercial-provider lens across the FedRAMP lifecycle. For a commercial software, SaaS, or managed-service provider pursuing FedRAMP Marketplace certification or validation. Historical Moderate aligns to Class C Advanced; historical High aligns to Class D High Assurance. The provider owns the offering and evidence, a recognized assessor supplies independent assessment where required, FedRAMP grants the Marketplace designation, and each agency AO decides agency-system use.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Provider executive sponsor
  • Product owner
  • CISO / security owner
  • Federal business owner
  • Advisory and integration partner
  • Prospective agency sponsor / AO

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Federal-market decision
  • Certification-path and investment decision
  • Executive risk tolerance
  • Role, authority, and independence assignment

Technology

No separate item at this stage.

Artifacts

Cloud Foundations contributes to this area.

  • Certification strategy Cloud Foundations work product
  • Role and authority matrix Cloud Foundations work product
  • Federal-market assumptions
  • Advisor and assessor independence record

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • A SaaS provider retains WWT, a specialist advisor such as stackArmor, or both
  • The provider appoints accountable product and security owners before package work begins
State / local · State, local, tribal, and education pathways

Jurisdiction-selected authorization or assurance. A jurisdiction may use NIST RMF, GovRAMP cloud assurance, its own policy, or a combination. The named government authority decides what constitutes acceptance.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • State or local CIO / CISO
  • Agency risk authority
  • System owner
  • Procurement and privacy officials

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Identify jurisdiction and decision authority

Technology

No separate item at this stage.

Artifacts

Cloud Foundations contributes to this area.

  • Authority and acceptance criteria Cloud Foundations work product
  • Acquisition security requirements Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • State policy names who accepts system risk
CSF 2.0 · NIST CSF 2.0 improvement pathway

Outcome-oriented cybersecurity risk management. CSF 2.0 organizes outcomes through Govern, Identify, Protect, Detect, Respond, and Recover. It can stand alone for improvement or support formal authorization; it does not itself issue an ATO.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Executive leadership
  • Cybersecurity leader
  • Business and risk owners
  • Legal and privacy leaders

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Governance
  • Risk appetite and accountability

Technology

No separate item at this stage.

Artifacts

Cloud Foundations contributes to this area.

  • Cybersecurity risk strategy Cloud Foundations work product
  • Roles and policies Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Leadership sets target outcomes and investment priorities
Cloud Waypoint contribution, outputs and closeout

Foundations and Application Dependency Mapping prepare evidence and decision inputs. Output availability, prerequisites and limitations below come from the Studio export registry.

Existing capability

  • Cloud Foundations: Governance, ownership, decision rights and workforce evidence positions.
  • Cloud Foundations: Decision and stakeholder registers identify accountable people and open calls.

Outputs and remaining work

Decision and authority register

Export available · CSV / HTML · Cloud Foundations

Named authorities, open decisions, owners, evidence basis, and next decision.

Stakeholder and responsibility starter

Export available · CSV / HTML · Cloud Foundations

A reviewable role and RACI starting point for the client record.

Target operating intent

Not currently exported · No current export · Cloud Foundations

Not produced by the Studio today: the record holds no governed target-posture structure (alternatives, limits, attestation) to assemble it from.

Measured closeout

AR-001 · AR-002 · AR-003 · AR-005 · AR-038 · AR-040 · AR-049 · AR-050

A charter, named decision owners, accepted responsibilities, and dated client decisions can support movement; a consultant-authored role chart alone cannot.

Studio stages: Entry · Foundations.

02 · Framework

Which law, policy, baseline, or outcomes govern?

DoD RMF · DoD mission authorization

Formal authorization pathway. NIST RMF implemented through DoD policy. Cloud and cyber services contribute evidence; the mission AO retains the system authorization decision.

People

  • DoD Component cybersecurity office

Process

Cloud Foundations contributes to this area.

  • DoD RMF
  • NSS tailoring where applicable

Technology

No separate item at this stage.

Artifacts

Cloud Foundations contributes to this area.

  • DoDI 8510.01
  • NIST SP 800-37
  • CNSSI 1253
  • NIST SP 800-53

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Component overlays
  • Impact-level conditions
Federal RMF · Federal civilian system authorization

Formal authorization pathway. The same NIST RMF spine, applied through FISMA, OMB direction, and each agency’s authorization policy.

People

  • Agency security and privacy offices

Process

Cloud Foundations contributes to this area.

  • NIST RMF
  • Agency tailoring and privacy integration

Technology

No separate item at this stage.

Artifacts

Cloud Foundations contributes to this area.

  • FISMA
  • NIST SP 800-37
  • NIST SP 800-53 / 53A
  • FIPS 199 / 200

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Agency overlay or control parameters
FedRAMP High · FedRAMP High cloud reuse

Cloud-service evidence plus agency authorization. FedRAMP High provides a reusable cloud-service security package. The agency still authorizes the federal information system and its specific use of the service.

People

  • FedRAMP and agency security teams

Process

Cloud Foundations contributes to this area.

  • FedRAMP Rev. 5 authorization
  • Agency RMF

Technology

No separate item at this stage.

Artifacts

Cloud Foundations contributes to this area.

  • FedRAMP High baseline
  • NIST SP 800-53 Rev. 5
  • Agency-specific requirements

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • High baseline with FedRAMP parameters
FedRAMP provider · Commercial cloud and service provider certification

Commercial-provider lens across the FedRAMP lifecycle. For a commercial software, SaaS, or managed-service provider pursuing FedRAMP Marketplace certification or validation. Historical Moderate aligns to Class C Advanced; historical High aligns to Class D High Assurance. The provider owns the offering and evidence, a recognized assessor supplies independent assessment where required, FedRAMP grants the Marketplace designation, and each agency AO decides agency-system use.

People

  • FedRAMP
  • Provider control owners
  • Advisory and integration partner
  • Recognized assessor / 3PAO where required

Process

Cloud Foundations contributes to this area.

  • Choose the applicable Certified (Rev. 5) or Validated (20x) path
  • Map historical Moderate to Class C Advanced
  • Map historical High to Class D High Assurance
  • Confirm current class, path, and assessor rules at engagement start

Technology

No separate item at this stage.

Artifacts

Cloud Foundations contributes to this area.

  • FedRAMP Consolidated Rules
  • Applicable Rev. 5 or 20x requirements
  • NIST SP 800-53
  • FIPS 199 and FIPS 200 where applicable

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • 20x Classes A through C are finalized; Class D remains in development
  • Class D is limited to agency-sponsored certification paths
State / local · State, local, tribal, and education pathways

Jurisdiction-selected authorization or assurance. A jurisdiction may use NIST RMF, GovRAMP cloud assurance, its own policy, or a combination. The named government authority decides what constitutes acceptance.

People

  • Jurisdiction security office
  • GovRAMP community

Process

Cloud Foundations contributes to this area.

  • Jurisdiction RMF or security review
  • GovRAMP cloud assurance
  • NIST CSF Profile

Technology

No separate item at this stage.

Artifacts

Cloud Foundations contributes to this area.

  • NIST RMF or CSF 2.0
  • GovRAMP baseline
  • State statutes and policy

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • State adopts a baseline and adds jurisdiction requirements
CSF 2.0 · NIST CSF 2.0 improvement pathway

Outcome-oriented cybersecurity risk management. CSF 2.0 organizes outcomes through Govern, Identify, Protect, Detect, Respond, and Recover. It can stand alone for improvement or support formal authorization; it does not itself issue an ATO.

People

  • Cybersecurity program team

Process

Cloud Foundations contributes to this area.

  • Choose scope and use of CSF Core, Profiles, and Tiers

Technology

No separate item at this stage.

Artifacts

Cloud Foundations contributes to this area.

  • NIST CSF 2.0
  • Implementation examples
  • Informative references

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • CSF Profile used for an enterprise or service
Cloud Waypoint contribution, outputs and closeout

Foundations and Application Dependency Mapping prepare evidence and decision inputs. Output availability, prerequisites and limitations below come from the Studio export registry.

Existing capability

  • Cloud Foundations: Standards-linked policy, authorization-package, inheritance, data, acquisition, and Zero Trust evidence positions.
  • Cloud Foundations: Source-traced rationale and a governed distinction between requirements, reference patterns, and client decisions.

Outputs and remaining work

Standards crosswalk

Partial output · CSV / HTML · Cloud Foundations

Each assessed position against its standard and the reference sources the Studio carries, with unresolved tailoring visible. The client's own policies are not in the record, so no policy is mapped.

Tailoring and applicability worksheet

Export available · CSV / HTML · Cloud Foundations

Written once control selection is complete. Owners are the recorded providers, a control with none reads not recorded, and open decisions are named rather than resolved.

Written only once the control selection is complete (categorization holds a level for C, I and A).

Client policy action queue

Not currently exported · No current export · Cloud Foundations

Not produced by the Studio today: the record holds no accepted policy gaps to queue.

Measured closeout

AR-004 · AR-016 · AR-018 · AR-022 · AR-027 · AR-029 · AR-033 · AR-041 · AR-043

Approved policy, applicability, or tailoring decisions may move the reading. A crosswalk that has not been adopted improves readiness and traceability only.

Studio stages: Entry · Foundations.

03 · Boundary

What system, service, information, and dependencies are in scope?

DoD RMF · DoD mission authorization

Formal authorization pathway. NIST RMF implemented through DoD policy. Cloud and cyber services contribute evidence; the mission AO retains the system authorization decision.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Enterprise architect
  • Mission owner
  • GSS owner
  • Cloud / network operator

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • System registration
  • Boundary and interconnection analysis
  • Information-flow mapping

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Mission application
  • General Support System (GSS)
  • Landing zone
  • External and inherited services

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • System description Cloud Foundations work product
  • Boundary diagram Cloud Foundations work product
  • Data-flow diagram Application Dependency Mapping work product
  • Interconnection inventory Application Dependency Mapping work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Mission tenant inherits shared GSS controls
  • Separately authorized cloud service remains external
Federal RMF · Federal civilian system authorization

Formal authorization pathway. The same NIST RMF spine, applied through FISMA, OMB direction, and each agency’s authorization policy.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • System owner
  • Enterprise architect
  • Privacy officer

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • System and information inventory
  • Boundary analysis
  • Privacy scoping

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Federal information system
  • Enterprise common controls
  • External and cloud services

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • System description Cloud Foundations work product
  • Boundary and data-flow diagrams Application Dependency Mapping work product
  • Information inventory Application Dependency Mapping work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Agency system uses an external cloud service offering
FedRAMP High · FedRAMP High cloud reuse

Cloud-service evidence plus agency authorization. FedRAMP High provides a reusable cloud-service security package. The agency still authorizes the federal information system and its specific use of the service.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • CSP system owner
  • Agency architect
  • 3PAO

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Cloud offering boundary definition
  • Agency use-case scoping

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Cloud Service Offering (CSO)
  • External dependencies
  • Agency system and integrations

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Authorization boundary diagram Cloud Foundations work product
  • Data-flow diagram Application Dependency Mapping work product
  • Service inventory Application Dependency Mapping work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Certified CSO is one external service inside a larger agency system
FedRAMP provider · Commercial cloud and service provider certification

Commercial-provider lens across the FedRAMP lifecycle. For a commercial software, SaaS, or managed-service provider pursuing FedRAMP Marketplace certification or validation. Historical Moderate aligns to Class C Advanced; historical High aligns to Class D High Assurance. The provider owns the offering and evidence, a recognized assessor supplies independent assessment where required, FedRAMP grants the Marketplace designation, and each agency AO decides agency-system use.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Product architect
  • Cloud platform owner
  • Security architect
  • Application and service owners
  • Third-party service owners

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Define the cloud service offering
  • Map product and administrative boundaries
  • Trace data flows, integrations, and external dependencies
  • Separate provider, customer, and third-party responsibilities

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Commercial software or SaaS product
  • Cloud accounts, subscriptions, and landing zones
  • Identity, network, data, logging, and delivery services
  • External and embedded services

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Cloud service offering description Cloud Foundations work product
  • Certification boundary diagram Cloud Foundations work product
  • Data-flow diagram Application Dependency Mapping work product
  • Service and dependency inventory Application Dependency Mapping work product
  • Third-party resource inventory Application Dependency Mapping work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • The listed offering excludes the provider corporate environment unless it directly supports the service
  • Direct and indirect Marketplace use cases are identified before listing
State / local · State, local, tribal, and education pathways

Jurisdiction-selected authorization or assurance. A jurisdiction may use NIST RMF, GovRAMP cloud assurance, its own policy, or a combination. The named government authority decides what constitutes acceptance.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Agency owner
  • Architect
  • Provider

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Service and data scoping
  • Dependency and residency review

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Government system
  • Cloud service
  • Shared state services
  • Local integrations

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Boundary diagram Cloud Foundations work product
  • Data inventory Application Dependency Mapping work product
  • Service and integration map Application Dependency Mapping work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • SaaS boundary is separated from agency workflows and records
CSF 2.0 · NIST CSF 2.0 improvement pathway

Outcome-oriented cybersecurity risk management. CSF 2.0 organizes outcomes through Govern, Identify, Protect, Detect, Respond, and Recover. It can stand alone for improvement or support formal authorization; it does not itself issue an ATO.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Business owner
  • Technology owner
  • Supply-chain owners

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Scope assets, services, suppliers and dependencies

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • IT
  • OT
  • IoT
  • Cloud
  • Mobile
  • AI systems

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Scope statement Cloud Foundations work product
  • Asset and dependency inventory Application Dependency Mapping work product
  • Business environment Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • One target profile covers a critical business service
Cloud Waypoint contribution, outputs and closeout

Foundations and Application Dependency Mapping prepare evidence and decision inputs. Output availability, prerequisites and limitations below come from the Studio export registry.

Existing capability

  • ADM: ADM reconciles declared and observed dependencies as matched, unmatched, conflict, or never declared.
  • Foundations + ADM: The record already carries application ownership, boundary, interface, data-flow, integration, and infrastructure context.

Outputs and remaining work

Application and dependency register

Export available · CSV / HTML · ADM

Applications, owners, interfaces, observations, conflicts, and unresolved crossings.

Requires Application Dependency Mapping, with applications and dependencies recorded.

CMDB starter seed

Not currently exported · No current export · ADM

Not produced by the Studio today: the Studio imports inventory but writes no candidate configuration items or relationships.

Boundary and data-flow pack

Partial output · CSV / HTML · Foundations + ADM

Boundary components, flows, interconnections and limitations as CSV and HTML; diagrams appear within Package readiness. A separate SVG file and a single bundled pack are not supplied.

ServiceNow / JSM candidate topology

Not currently exported · No current export · ADM

Not produced by the Studio today: no CMDB classes, identifiers or reconciliation rules are generated.

Measured closeout

AR-006 · AR-007 · AR-008 · AR-009 · AR-021 · AR-022 · AR-023 · AR-026 · AR-028 · AR-029 · AR-030

Owner-confirmed inventory and reconciled dependencies can support movement. Observation is evidence of communication, not proof that the path is approved or complete.

Studio stages: Foundations · GSS design.

04 · Requirements

Which outcomes, controls, overlays, and responsibilities apply?

DoD RMF · DoD mission authorization

Formal authorization pathway. NIST RMF implemented through DoD policy. Cloud and cyber services contribute evidence; the mission AO retains the system authorization decision.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Control owners
  • Common-control provider
  • Mission application owner

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Categorize
  • Select and tailor controls
  • Allocate inheritance and shared responsibility

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • SCCA functions
  • Cloud service offering
  • Identity, network, logging and endpoint services

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Security categorization
  • Control baseline
  • Overlay and tailoring record Cloud Foundations work product
  • Control inheritance matrix Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • VDSS and VDMS functions map to selected controls
  • CSSP responsibilities are named by activity
Federal RMF · Federal civilian system authorization

Formal authorization pathway. The same NIST RMF spine, applied through FISMA, OMB direction, and each agency’s authorization policy.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Control owners
  • Privacy officials
  • Common-control provider

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Categorize
  • Select
  • Tailor
  • Allocate controls

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Agency enterprise services
  • Cloud and SaaS dependencies

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Impact categorization
  • Selected control baseline
  • Privacy requirements
  • Customer-responsibility matrix Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Moderate-impact system inherits enterprise identity controls
FedRAMP High · FedRAMP High cloud reuse

Cloud-service evidence plus agency authorization. FedRAMP High provides a reusable cloud-service security package. The agency still authorizes the federal information system and its specific use of the service.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • CSP control owners
  • Agency control owners

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Allocate provider, customer, shared and inherited controls

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • CSP platform
  • Agency tenant configuration
  • Enterprise services

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • High baseline
  • Control responsibility matrix Cloud Foundations work product
  • Agency delta requirements Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Customer-configured controls remain with the agency
FedRAMP provider · Commercial cloud and service provider certification

Commercial-provider lens across the FedRAMP lifecycle. For a commercial software, SaaS, or managed-service provider pursuing FedRAMP Marketplace certification or validation. Historical Moderate aligns to Class C Advanced; historical High aligns to Class D High Assurance. The provider owns the offering and evidence, a recognized assessor supplies independent assessment where required, FedRAMP grants the Marketplace designation, and each agency AO decides agency-system use.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Control owners
  • Product and platform engineering
  • Privacy and legal leads
  • Customer-success owner
  • Advisory and integration partner

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Select class and path requirements
  • Allocate controls and shared responsibility
  • Define secure configuration and customer responsibilities
  • Identify inherited, provider, customer, and third-party evidence

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Configuration baselines
  • Encryption and key management
  • Identity and privileged access
  • Telemetry, vulnerability, and incident services

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Control responsibility matrix Cloud Foundations work product
  • Customer responsibility matrix Cloud Foundations work product
  • Requirements traceability matrix
  • Secure configuration requirements
  • Privacy and data-handling requirements

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • A provider-owned control is distinguished from a customer configuration obligation
  • Agency deltas are tracked separately from reusable certification evidence
State / local · State, local, tribal, and education pathways

Jurisdiction-selected authorization or assurance. A jurisdiction may use NIST RMF, GovRAMP cloud assurance, its own policy, or a combination. The named government authority decides what constitutes acceptance.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Government control owners
  • Provider control owners

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Select baseline
  • Allocate shared responsibilities
  • Add statutory requirements

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Cloud and enterprise services

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Control matrix Cloud Foundations work product
  • Privacy and records requirements Cloud Foundations work product
  • Contract security schedule Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Criminal justice, health, tax, or education data adds obligations
CSF 2.0 · NIST CSF 2.0 improvement pathway

Outcome-oriented cybersecurity risk management. CSF 2.0 organizes outcomes through Govern, Identify, Protect, Detect, Respond, and Recover. It can stand alone for improvement or support formal authorization; it does not itself issue an ATO.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Outcome owners
  • Stakeholders and customers

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Create Current and Target Profiles
  • Prioritize gaps
  • Choose Tier where useful

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

No separate item at this stage.

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Current Profile Cloud Foundations work product
  • Target Profile Cloud Foundations work product
  • Gap and priority register Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Target outcomes reflect legal, contractual and mission needs
Cloud Waypoint contribution, outputs and closeout

Foundations and Application Dependency Mapping prepare evidence and decision inputs. Output availability, prerequisites and limitations below come from the Studio export registry.

Existing capability

  • Cloud Foundations: Control inheritance, shared responsibility and technical control positions.
  • Foundations + ADM: Evidence records connect assessed positions, selected controls, current facts, gaps and actions. Each output below states its actual scope.

Outputs and remaining work

Responsibility and inheritance matrix

Partial output · CSV / HTML · Cloud Foundations

SSP draft, a responsibility and ownership register with unresolved ownership visible, and an inheritance CSV when control selection is complete. Separate provider, enterprise, platform, GSS and workload tiers are not recorded.

Written only once the control selection is complete (categorization holds a level for C, I and A).

Control and position traceability register

Export available · CSV / HTML · Foundations + ADM

Traces each assessed position and each selected control to its sources or evidence, workstreams, findings or open weaknesses, owner and open decisions. Controls and positions, not requirements; the record holds no position-to-control mapping, so none is drawn.

Decision and gap worksheet

Partial output · CSV / HTML · Cloud Foundations

Open decisions and unmet acceptance tests held for disposition, with their reasons. The record holds no agency, component, jurisdiction or workload deltas, so none are listed.

Measured closeout

AR-004 · AR-008 · AR-010 · AR-016 · AR-017 · AR-018 · AR-019 · AR-020 · AR-022 · AR-027 · AR-029 · AR-030 · AR-043 · AR-044 · AR-045 · AR-046 · AR-047 · AR-048

A confirmed allocation and accepted responsibility model can support movement. Cloud Waypoint does not select the final baseline or accept inherited risk.

Studio stages: GSS design · Package.

05 · Implementation

How do people, process, and technology satisfy them?

DoD RMF · DoD mission authorization

Formal authorization pathway. NIST RMF implemented through DoD policy. Cloud and cyber services contribute evidence; the mission AO retains the system authorization decision.

People

Cloud Foundations contributes to this area.

  • GSS operator
  • CSSP
  • Application team
  • Cloud platform team
  • Network provider

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Configure
  • Document
  • Integrate
  • Exercise
  • Remediate

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • VDSS
  • VDMS
  • BCAP / CAP
  • TCCM
  • SIEM / telemetry
  • Vulnerability and configuration tooling

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • System Security Plan (SSP) Cloud Foundations work product
  • CONOPS Cloud Foundations work product
  • Configuration baseline
  • Procedures Cloud Foundations work product
  • Responsibility matrix Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Telemetry reaches the designated CSSP
  • A landing-zone service implements a common control
Federal RMF · Federal civilian system authorization

Formal authorization pathway. The same NIST RMF spine, applied through FISMA, OMB direction, and each agency’s authorization policy.

People

Cloud Foundations contributes to this area.

  • Product and engineering teams
  • Security and privacy teams
  • Service providers

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Design
  • Configure
  • Document
  • Operate

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Identity
  • Endpoint
  • Network
  • Cloud
  • Logging
  • Resilience services

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • SSP Cloud Foundations work product
  • Policies and procedures Cloud Foundations work product
  • Configuration baseline
  • Contingency and incident plans Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Agency configuration completes provider responsibilities
FedRAMP High · FedRAMP High cloud reuse

Cloud-service evidence plus agency authorization. FedRAMP High provides a reusable cloud-service security package. The agency still authorizes the federal information system and its specific use of the service.

People

Cloud Foundations contributes to this area.

  • CSP operations
  • Agency cloud team
  • Agency security operations

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Configure service
  • Integrate tenant
  • Document shared responsibility

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Authorized CSO
  • Identity federation
  • Logging integration
  • Encryption and key services

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • CSP SSP
  • Agency SSP references Cloud Foundations work product
  • Configuration and integration records Application Dependency Mapping work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Agency configures its tenant and sends logs to its monitoring service
FedRAMP provider · Commercial cloud and service provider certification

Commercial-provider lens across the FedRAMP lifecycle. For a commercial software, SaaS, or managed-service provider pursuing FedRAMP Marketplace certification or validation. Historical Moderate aligns to Class C Advanced; historical High aligns to Class D High Assurance. The provider owns the offering and evidence, a recognized assessor supplies independent assessment where required, FedRAMP grants the Marketplace designation, and each agency AO decides agency-system use.

People

Cloud Foundations contributes to this area.

  • Product engineering
  • Cloud platform engineering
  • Security operations
  • Compliance and evidence owners
  • Advisory and integration partner

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Implement and document requirements
  • Remediate readiness gaps
  • Operationalize configuration, vulnerability, incident, and change practices
  • Prepare reusable certification data

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Product and platform controls
  • Policy-as-code and configuration automation
  • Scanning and evidence automation
  • Ticketing, logging, and incident tooling

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • System Security Plan or security decision record
  • Policies and procedures Cloud Foundations work product
  • Configuration and integration records Application Dependency Mapping work product
  • Incident, contingency, and change plans
  • Certification readiness backlog Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Foundations supplies the operating model and package head start
  • ADM supplies observed integrations, dependencies, crossings, and candidate topology
  • A multi-cloud FinOps platform prepares for High / Class D so agencies can evaluate it for JWCC and its successor, UCM
State / local · State, local, tribal, and education pathways

Jurisdiction-selected authorization or assurance. A jurisdiction may use NIST RMF, GovRAMP cloud assurance, its own policy, or a combination. The named government authority decides what constitutes acceptance.

People

Cloud Foundations contributes to this area.

  • Provider
  • Government IT and security
  • Managed-service partners

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Configure
  • Integrate
  • Document
  • Exercise

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Cloud service
  • Identity
  • Logging
  • Endpoint and network controls

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • System plan Cloud Foundations work product
  • Configuration record
  • Procedures Cloud Foundations work product
  • Responsibility matrix Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Government identity and logging complete the service integration
CSF 2.0 · NIST CSF 2.0 improvement pathway

Outcome-oriented cybersecurity risk management. CSF 2.0 organizes outcomes through Govern, Identify, Protect, Detect, Respond, and Recover. It can stand alone for improvement or support formal authorization; it does not itself issue an ATO.

People

Cloud Foundations contributes to this area.

  • Process owners
  • Engineering and operations
  • Security teams
  • Suppliers

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Govern
  • Identify
  • Protect
  • Detect
  • Respond
  • Recover

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Asset management
  • Identity
  • Data protection
  • Monitoring
  • Response and recovery capabilities

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Roadmap Cloud Foundations work product Application Dependency Mapping work product
  • Policies Cloud Foundations work product
  • Procedures Cloud Foundations work product
  • Architecture and configuration records Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Protective and detective outcomes become owned work
Cloud Waypoint contribution, outputs and closeout

Foundations and Application Dependency Mapping prepare evidence and decision inputs. Output availability, prerequisites and limitations below come from the Studio export registry.

Existing capability

  • Foundations + ADM: Transformation planning connects workstreams, dependencies, gates and horizons.
  • Foundations + ADM: Planning and Jira-shaped CSVs support client work management; tool-specific import mapping requires validation.

Outputs and remaining work

Jira work board

Export available · CSV · Foundations + ADM

Jira-shaped CSV for client review and mapping. ServiceNow import compatibility is not established.

Carries the workstreams placed on the storyboard; with none placed the file holds only its header.

Transformation project plan

Partial output · CSV · Foundations + ADM

Planning CSV available. A Microsoft Project XML file is also generated and checked against Microsoft's published schema; opening it in Microsoft Project has not yet been confirmed.

Carries the workstreams placed on the storyboard; with none placed the file holds only its header.

MoSCoW decision-ready backlog

Not currently exported · No current export · Foundations + ADM

Not produced by the Studio today: the Studio does not model Must, Should, Could or Won't priorities.

Process Asset Library starter

Partial output · HTML / JSON · Cloud Foundations

HTML reference and a generated JSON process library. Most content is the practice's fixed library, labelled as such; roles per process, measures and tests are not recorded.

Measured closeout

AR-006 · AR-007 · AR-008 · AR-009 · AR-010 · AR-011 · AR-012 · AR-013 · AR-014 · AR-015 · AR-019 · AR-020 · AR-024 · AR-028 · AR-030 · AR-031 · AR-032 · AR-033 · AR-034 · AR-035 · AR-041 · AR-042 · AR-044 · AR-045 · AR-046 · AR-047 · AR-048 · AR-049 · AR-050

A plan or backlog is not implementation evidence. Movement above Defined requires adopted workflow and current operating proof from the client environment.

Studio stages: GSS design · Operate.

06 · Evidence

What proves the intended result and who produced it?

DoD RMF · DoD mission authorization

Formal authorization pathway. NIST RMF implemented through DoD policy. Cloud and cyber services contribute evidence; the mission AO retains the system authorization decision.

People

Cloud Foundations contributes to this area.

  • Control implementers
  • Evidence custodians
  • Common-control provider

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Collect attributable evidence
  • Verify provenance and currency
  • Track weaknesses

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Configuration exports
  • Logs and alerts
  • Ticketing and change records
  • Scanning results

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Implementation statements Cloud Foundations work product
  • Evidence index Cloud Foundations work product Application Dependency Mapping work product
  • Test results
  • POA&M Cloud Foundations work product
  • Inheritance evidence

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Observed log delivery
  • Approved baseline plus drift record
Federal RMF · Federal civilian system authorization

Formal authorization pathway. The same NIST RMF spine, applied through FISMA, OMB direction, and each agency’s authorization policy.

People

Cloud Foundations contributes to this area.

  • Implementers
  • Evidence owners
  • Service providers

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Evidence collection and provenance
  • Weakness tracking

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Logs
  • Configuration records
  • Scans
  • Exercises

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Control evidence
  • POA&M Cloud Foundations work product
  • Test records
  • Provider authorization material

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Reusable provider evidence plus agency-specific proof
FedRAMP High · FedRAMP High cloud reuse

Cloud-service evidence plus agency authorization. FedRAMP High provides a reusable cloud-service security package. The agency still authorizes the federal information system and its specific use of the service.

People

Cloud Foundations contributes to this area.

  • CSP
  • 3PAO
  • Agency evidence owners

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Package production
  • Secure package reuse
  • Agency-specific supplementation

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Provider and agency evidence repositories

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • SSP
  • SAP
  • SAR
  • POA&M
  • Readiness Assessment Report when used
  • Agency implementation evidence Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Agency reuses provider assessment instead of reassessing the platform
FedRAMP provider · Commercial cloud and service provider certification

Commercial-provider lens across the FedRAMP lifecycle. For a commercial software, SaaS, or managed-service provider pursuing FedRAMP Marketplace certification or validation. Historical Moderate aligns to Class C Advanced; historical High aligns to Class D High Assurance. The provider owns the offering and evidence, a recognized assessor supplies independent assessment where required, FedRAMP grants the Marketplace designation, and each agency AO decides agency-system use.

People

Cloud Foundations contributes to this area.

  • Control implementers
  • Evidence custodians
  • Product and security operations
  • Advisory and integration partner

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Collect attributable and current evidence
  • Maintain human-readable and machine-readable certification data
  • Track weaknesses, exceptions, and remediation
  • Preserve evidence provenance

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Automated evidence collection
  • Configuration and vulnerability exports
  • Logs, alerts, tickets, and change records
  • Software and service inventories

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Certification evidence index Cloud Foundations work product Application Dependency Mapping work product
  • Implementation evidence
  • Automated evidence outputs
  • POA&M Cloud Foundations work product
  • Evidence provenance record

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • The provider maintains reusable evidence about its responsibilities
  • An agency reuses provider evidence and adds evidence for its own system and use
State / local · State, local, tribal, and education pathways

Jurisdiction-selected authorization or assurance. A jurisdiction may use NIST RMF, GovRAMP cloud assurance, its own policy, or a combination. The named government authority decides what constitutes acceptance.

People

Cloud Foundations contributes to this area.

  • Provider evidence owners
  • Government system owner
  • Independent assessor

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Collect reusable and jurisdiction-specific evidence

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Assessment repository
  • Monitoring and ticket records

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • GovRAMP or provider package
  • Assessment report
  • POA&M Cloud Foundations work product
  • Agency evidence Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Reusable cloud assessment is supplemented for local use
CSF 2.0 · NIST CSF 2.0 improvement pathway

Outcome-oriented cybersecurity risk management. CSF 2.0 organizes outcomes through Govern, Identify, Protect, Detect, Respond, and Recover. It can stand alone for improvement or support formal authorization; it does not itself issue an ATO.

People

Cloud Foundations contributes to this area.

  • Outcome owners
  • Internal audit
  • Operations teams

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Measure outcomes
  • Retain proof
  • Track performance

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Metrics dashboards
  • Logs
  • Exercises
  • Tickets

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Profile evidence Cloud Foundations work product Application Dependency Mapping work product
  • Metrics Cloud Foundations work product
  • Exercise results
  • Risk register Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Evidence shows whether a target outcome is achieved
Cloud Waypoint contribution, outputs and closeout

Foundations and Application Dependency Mapping prepare evidence and decision inputs. Output availability, prerequisites and limitations below come from the Studio export registry.

Existing capability

  • Cloud Foundations: Evidence positions retain rationale, gaps, quality, confidence, confirmation and source pointers.
  • Foundations + ADM: Observation, interview confirmation, provenance and package integrity remain distinguishable.

Outputs and remaining work

Evidence and traceability index

Export available · CSV / HTML · Foundations + ADM

Evidence pointer, source, position, confirmation, limitation, and related action.

POA&M and remediation seed

Export available · CSV · Cloud Foundations

Findings, owners, milestones, evidence needs, dependencies, and status for client import.

Integrity and provenance manifest

Export available · JSON · Cloud Foundations

Included within the closeout or client pack; not a standalone download.

Operational evidence return contract

Partial output · CSV / HTML · Foundations + ADM

What the client's systems return for closeout verification: source, location, retention, owner and cadence, from the record. Export formats and field layouts for each client system are not specified.

Measured closeout

AR-010 · AR-012 · AR-015 · AR-016 · AR-017 · AR-018 · AR-019 · AR-020 · AR-023 · AR-025 · AR-026 · AR-027 · AR-028 · AR-029 · AR-030 · AR-037 · AR-038 · AR-039 · AR-043 · AR-044 · AR-045 · AR-046 · AR-047 · AR-048 · AR-051

Only attributable, current evidence changes the closeout reading. A generated index makes evidence usable but does not make an unsupported control effective.

Studio stages: Assessment · Package.

07 · Assessment

Who independently examines design, operation, and evidence?

DoD RMF · DoD mission authorization

Formal authorization pathway. NIST RMF implemented through DoD policy. Cloud and cyber services contribute evidence; the mission AO retains the system authorization decision.

People

Cloud Foundations contributes to this area.

  • SCA
  • Assessment team
  • Technical test specialists

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Examine
  • Interview
  • Test
  • Record findings

Technology

  • Assessment tooling
  • Validation scripts
  • Independent scans

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Security Assessment Plan (SAP)
  • Security Assessment Report (SAR)
  • Risk assessment
  • Findings register Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Assessor validates control effectiveness
  • Unmet conditions enter remediation
Federal RMF · Federal civilian system authorization

Formal authorization pathway. The same NIST RMF spine, applied through FISMA, OMB direction, and each agency’s authorization policy.

People

Cloud Foundations contributes to this area.

  • Independent assessor
  • Agency assessment team
  • Privacy reviewers

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Examine
  • Interview
  • Test
  • Risk analysis

Technology

  • Assessment and validation tools

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • SAP
  • SAR
  • Risk assessment
  • Privacy assessment where applicable

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Agency verifies inherited and system-specific controls
FedRAMP High · FedRAMP High cloud reuse

Cloud-service evidence plus agency authorization. FedRAMP High provides a reusable cloud-service security package. The agency still authorizes the federal information system and its specific use of the service.

People

Cloud Foundations contributes to this area.

  • 3PAO
  • Agency assessors

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Independent CSO assessment
  • Agency assessment of its use and remaining controls

Technology

  • Assessment tools and scans

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • 3PAO assessment results
  • Agency SAR or risk review

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Provider findings and agency configuration are evaluated separately
FedRAMP provider · Commercial cloud and service provider certification

Commercial-provider lens across the FedRAMP lifecycle. For a commercial software, SaaS, or managed-service provider pursuing FedRAMP Marketplace certification or validation. Historical Moderate aligns to Class C Advanced; historical High aligns to Class D High Assurance. The provider owns the offering and evidence, a recognized assessor supplies independent assessment where required, FedRAMP grants the Marketplace designation, and each agency AO decides agency-system use.

People

Cloud Foundations contributes to this area.

  • Recognized assessor / 3PAO where required
  • Provider control owners
  • Technical test specialists
  • FedRAMP review team

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Plan the independent assessment
  • Examine, interview, and test
  • Resolve readiness and assessment findings
  • Protect assessor independence

Technology

  • Assessment tooling
  • Penetration-testing environment
  • Evidence review workspace

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Assessment plan
  • Assessment report
  • Findings register Cloud Foundations work product
  • Remediation evidence
  • Assessor independence record

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • The advisor prepares the provider; the recognized assessor makes independent findings
  • A provider does not present advisory readiness work as independent assessment
State / local · State, local, tribal, and education pathways

Jurisdiction-selected authorization or assurance. A jurisdiction may use NIST RMF, GovRAMP cloud assurance, its own policy, or a combination. The named government authority decides what constitutes acceptance.

People

Cloud Foundations contributes to this area.

  • 3PAO or independent assessor
  • Government review team

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Provider assessment
  • Jurisdiction-specific risk and compliance review

Technology

  • Assessment and validation tools

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Assessment report
  • Gap register Cloud Foundations work product Application Dependency Mapping work product
  • Risk recommendation Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • State evaluates provider evidence and its own configuration
CSF 2.0 · NIST CSF 2.0 improvement pathway

Outcome-oriented cybersecurity risk management. CSF 2.0 organizes outcomes through Govern, Identify, Protect, Detect, Respond, and Recover. It can stand alone for improvement or support formal authorization; it does not itself issue an ATO.

People

Cloud Foundations contributes to this area.

  • Program assessors
  • Internal audit
  • Independent reviewers

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Profile assessment
  • Capability review
  • Gap validation

Technology

  • Assessment and reporting tools

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Updated Current Profile Cloud Foundations work product
  • Gap assessment Cloud Foundations work product Application Dependency Mapping work product
  • Risk analysis Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Assessment compares current outcomes to the target
Cloud Waypoint contribution, outputs and closeout

Foundations and Application Dependency Mapping prepare evidence and decision inputs. Output availability, prerequisites and limitations below come from the Studio export registry.

Existing capability

  • Foundations + ADM: The protected 0–4 reading retains rationale, confidence, evidence quality and confirmation gates.
  • Cloud Foundations: Findings remain separate from authorization and from document completeness.

Outputs and remaining work

Assessment posture export

Export available · CSV / HTML · Cloud Foundations

Each applicable position, score, label, rationale, gap, evidence, quality, confidence, and confirmation.

Requires a Foundations engagement with populated assessment evidence.

Findings and gap register

Export available · CSV / HTML · Foundations + ADM

Reviewable findings tied to evidence positions and transformation actions.

Requires a Foundations engagement with populated assessment evidence.

Assessor handover index

Export available · CSV / HTML · Cloud Foundations

Evidence locations, test needs, open questions, package sections, and named custodians; not an SAP or SAR.

Measured closeout

AR-016 · AR-017 · AR-018 · AR-019 · AR-020 · AR-025 · AR-037 · AR-043 · AR-044 · AR-045 · AR-046 · AR-047 · AR-048

Cloud Waypoint may reassess evidence posture with the client. Independent assessors retain assessment conclusions and the governing authority retains acceptance.

Studio stages: Assessment.

08 · Risk decision

Who accepts, conditions, treats, transfers, or rejects risk?

DoD RMF · DoD mission authorization

Formal authorization pathway. NIST RMF implemented through DoD policy. Cloud and cyber services contribute evidence; the mission AO retains the system authorization decision.

People

Cloud Foundations contributes to this area.

  • AO
  • AO designated representatives
  • Risk executives

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Review residual risk
  • Set authorization conditions
  • Issue or deny decision

Technology

No separate item at this stage.

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Authorization decision document
  • ATO / conditional decision
  • Terms and conditions
  • Accepted POA&M

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • AO accepts defined residual risk
  • Inherited authorization is considered, not mistaken for mission approval
Federal RMF · Federal civilian system authorization

Formal authorization pathway. The same NIST RMF spine, applied through FISMA, OMB direction, and each agency’s authorization policy.

People

Cloud Foundations contributes to this area.

  • Agency AO

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Risk review
  • Authorization decision

Technology

No separate item at this stage.

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • ATO or other agency decision
  • Authorization conditions
  • Accepted remediation plan

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • AO authorizes the federal information system’s defined use
FedRAMP High · FedRAMP High cloud reuse

Cloud-service evidence plus agency authorization. FedRAMP High provides a reusable cloud-service security package. The agency still authorizes the federal information system and its specific use of the service.

People

Cloud Foundations contributes to this area.

  • FedRAMP authorization authority
  • Agency AO

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Cloud-service authorization
  • Separate agency system risk decision

Technology

No separate item at this stage.

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • FedRAMP authorization package
  • Agency ATO for the system using the CSO

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • FedRAMP status enables reuse; it does not issue the mission system ATO
FedRAMP provider · Commercial cloud and service provider certification

Commercial-provider lens across the FedRAMP lifecycle. For a commercial software, SaaS, or managed-service provider pursuing FedRAMP Marketplace certification or validation. Historical Moderate aligns to Class C Advanced; historical High aligns to Class D High Assurance. The provider owns the offering and evidence, a recognized assessor supplies independent assessment where required, FedRAMP grants the Marketplace designation, and each agency AO decides agency-system use.

People

Cloud Foundations contributes to this area.

  • FedRAMP authorization and review officials
  • Provider accountable executive
  • Agency Authorizing Official
  • Agency system owner

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • FedRAMP grants, conditions, or denies the offering designation
  • Provider accepts certification conditions and remediation duties
  • Agency evaluates reuse, integration, and agency-system risk
  • Agency AO accepts risk for the agency system and its use

Technology

No separate item at this stage.

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • FedRAMP Marketplace designation
  • Certification decision record
  • Agency authorization decision
  • Conditions and remediation commitments

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • FedRAMP Certified or FedRAMP Validated applies to the cloud service offering
  • FedRAMP certification is not an agency ATO and does not transfer the agency AO’s authority
State / local · State, local, tribal, and education pathways

Jurisdiction-selected authorization or assurance. A jurisdiction may use NIST RMF, GovRAMP cloud assurance, its own policy, or a combination. The named government authority decides what constitutes acceptance.

People

Cloud Foundations contributes to this area.

  • Named jurisdiction authority
  • Contracting and program officials

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Authorization, approval, procurement acceptance, or risk treatment as policy requires

Technology

No separate item at this stage.

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Jurisdiction decision record
  • Authorization or acceptance conditions
  • Contract remedies

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • GovRAMP status supports reuse; local authority determines use
CSF 2.0 · NIST CSF 2.0 improvement pathway

Outcome-oriented cybersecurity risk management. CSF 2.0 organizes outcomes through Govern, Identify, Protect, Detect, Respond, and Recover. It can stand alone for improvement or support formal authorization; it does not itself issue an ATO.

People

Cloud Foundations contributes to this area.

  • Executive and risk owners

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Prioritize
  • Treat
  • Accept
  • Transfer
  • Avoid

Technology

No separate item at this stage.

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Funded roadmap
  • Risk-treatment decisions
  • Accepted exceptions

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Leadership funds highest-impact outcome gaps
  • No ATO is created by CSF alone
Cloud Waypoint contribution, outputs and closeout

Foundations and Application Dependency Mapping prepare evidence and decision inputs. Output availability, prerequisites and limitations below come from the Studio export registry.

Existing capability

  • Cloud Foundations: Executive brief and decision register surface conditions and unresolved actions.
  • Cloud Foundations: Consultant recommendations remain separate from assessment and authority decisions.

Outputs and remaining work

Executive decision brief

Partial output · HTML · Cloud Foundations

HTML brief available; PDF uses the browser print function rather than a generated PDF export.

Decision and gate register

Export available · CSV / HTML · Cloud Foundations

Decision, authority, evidence basis, dependencies, due point, and unresolved conditions.

Risk-response action queue

Export available · CSV · Cloud Foundations

Jira-shaped CSV of actions for client review. Import mapping and action approval remain with the client.

Measured closeout

AR-001 · AR-002 · AR-003 · AR-004 · AR-005 · AR-016 · AR-017 · AR-018 · AR-031 · AR-034 · AR-035 · AR-036 · AR-037 · AR-038 · AR-039 · AR-040 · AR-041

A dated client decision can close an open decision and change evidence posture. Only the designated authority accepts, conditions, transfers, treats, or rejects risk.

Studio stages: Package · Closeout.

09 · Continuity

How are change, performance, incidents, and residual risk monitored?

DoD RMF · DoD mission authorization

Formal authorization pathway. NIST RMF implemented through DoD policy. Cloud and cyber services contribute evidence; the mission AO retains the system authorization decision.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • System owner
  • ISSM / ISSO
  • CSSP
  • GSS operator
  • AO

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Continuous monitoring
  • Incident response
  • Change impact analysis
  • Periodic reporting and reassessment

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Telemetry pipeline
  • Vulnerability management
  • Configuration monitoring
  • Incident systems

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Continuous-monitoring strategy Cloud Foundations work product
  • Status reports Cloud Foundations work product
  • Change records
  • Updated POA&M Cloud Foundations work product
  • Incident evidence

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Material change returns work to the appropriate RMF step
  • CSSP operations contribute monitoring evidence
Federal RMF · Federal civilian system authorization

Formal authorization pathway. The same NIST RMF spine, applied through FISMA, OMB direction, and each agency’s authorization policy.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • System owner
  • Operations team
  • Security operations
  • AO

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Continuous monitoring
  • Ongoing authorization where adopted
  • Incident and change review

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Monitoring
  • Vulnerability management
  • Asset and configuration management

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Monitoring reports Cloud Foundations work product
  • Updated package Cloud Foundations work product
  • POA&M Cloud Foundations work product
  • Change-impact decisions

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Evidence remains current between authorization decisions
FedRAMP High · FedRAMP High cloud reuse

Cloud-service evidence plus agency authorization. FedRAMP High provides a reusable cloud-service security package. The agency still authorizes the federal information system and its specific use of the service.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • CSP
  • 3PAO
  • FedRAMP
  • Agency system owner and AO

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Continuous monitoring
  • Significant-change review
  • Vulnerability remediation
  • Agency oversight

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Provider monitoring
  • Agency tenant monitoring

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Continuous-monitoring submissions
  • POA&M updates
  • Significant-change package
  • Agency monitoring evidence Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Provider and customer each sustain their part of the shared model
FedRAMP provider · Commercial cloud and service provider certification

Commercial-provider lens across the FedRAMP lifecycle. For a commercial software, SaaS, or managed-service provider pursuing FedRAMP Marketplace certification or validation. Historical Moderate aligns to Class C Advanced; historical High aligns to Class D High Assurance. The provider owns the offering and evidence, a recognized assessor supplies independent assessment where required, FedRAMP grants the Marketplace designation, and each agency AO decides agency-system use.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Provider continuous-monitoring team
  • Product and security operations
  • FedRAMP oversight
  • Agency customer and AO representatives

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Maintain certification data
  • Monitor vulnerabilities, configuration, incidents, and changes
  • Report significant changes and material events
  • Support agency evidence reuse and customer obligations

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Continuous monitoring and scanning
  • Configuration and change telemetry
  • Incident communications
  • Certification-data interfaces

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Continuous-monitoring strategy Cloud Foundations work product
  • Certification data updates
  • Updated POA&M Cloud Foundations work product
  • Significant-change package
  • Customer security communications

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Product changes trigger bounded certification and customer impact review
  • Agency customers receive current provider evidence for their own authorization and monitoring
State / local · State, local, tribal, and education pathways

Jurisdiction-selected authorization or assurance. A jurisdiction may use NIST RMF, GovRAMP cloud assurance, its own policy, or a combination. The named government authority decides what constitutes acceptance.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Provider
  • Government owner
  • Security operations
  • Risk authority

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Continuous monitoring
  • Contract oversight
  • Incident notification
  • Change review

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Provider and government monitoring

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Monitoring reports Cloud Foundations work product
  • Incident notices
  • POA&M updates Cloud Foundations work product
  • Renewal evidence

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Material provider change triggers government review
CSF 2.0 · NIST CSF 2.0 improvement pathway

Outcome-oriented cybersecurity risk management. CSF 2.0 organizes outcomes through Govern, Identify, Protect, Detect, Respond, and Recover. It can stand alone for improvement or support formal authorization; it does not itself issue an ATO.

People

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Cybersecurity program
  • Business owners
  • Operations and suppliers

Process

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Continuous improvement
  • Incident learning
  • Profile refresh
  • Supplier review

Technology

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Monitoring and measurement services

Artifacts

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Revised Profiles Cloud Foundations work product
  • Performance trends Cloud Foundations work product
  • Lessons learned Cloud Foundations work product
  • Updated roadmap Cloud Foundations work product

Examples

Cloud Foundations contributes to this area.

Application Dependency Mapping contributes to this area.

  • Respond and Recover lessons revise Govern, Identify and Protect priorities
Cloud Waypoint contribution, outputs and closeout

Foundations and Application Dependency Mapping prepare evidence and decision inputs. Output availability, prerequisites and limitations below come from the Studio export registry.

Existing capability

  • Cloud Foundations: Transformation and operating-model reports prepare the receiving team for continued work.
  • Foundations + ADM: Process references and handover outputs help receiving teams define continuing work; available files and limitations are identified below.

Outputs and remaining work

Transformation and continuation pack

Partial output · CSV / HTML · Cloud Foundations

Transformation reports and CSV available. A Microsoft Project XML file is also generated and checked against Microsoft's published schema; opening it in Microsoft Project has not yet been confirmed.

Carries the workstreams placed on the storyboard; with none placed the file holds only its header.

Maturity movement receipt

Export available · JSON / HTML · Cloud Foundations

Compares a sealed baseline and a sealed closeout of the same scope and method: evidence completeness and, separately, maturity over readings confirmed in both. A pair that is not comparable gets no movement, only the reasons; the records do not carry the Studio release that scored each reading.

Requires a comparable baseline and closeout record of the same engagement (same scope and method).

ITSM / CMDB integration starter

Not currently exported · No current export · Foundations + ADM

Not produced by the Studio today: the process library's event taxonomy is teaching content; nothing is generated from the record for ITSM or CMDB tools.

Adopted client operations

Client-owned · Client systems and records · Client

Client-owned: the client configures, owns and operates it. The Studio does not produce it.

Measured closeout

AR-010 · AR-011 · AR-012 · AR-013 · AR-014 · AR-015 · AR-016 · AR-017 · AR-018 · AR-019 · AR-020 · AR-021 · AR-022 · AR-023 · AR-024 · AR-025 · AR-026 · AR-027 · AR-028 · AR-032 · AR-033 · AR-035 · AR-036 · AR-037 · AR-038 · AR-039 · AR-040 · AR-042 · AR-043 · AR-044 · AR-045 · AR-046 · AR-047 · AR-048 · AR-049 · AR-050 · AR-051

The closeout delta is measured only after evidence review. Sustained Level 3 or Level 4 requires client operation beyond the handover date and may need later verification.

Studio stages: Operate · Closeout.

Measure movement only from comparable evidence

When immutable baseline and closeout records cover the same applicable 51 evidence positions, compare the confirmed readings and report the 0–4 average, the existing 30/40/30 People–Process–Technology composite, domain movement, changed positions, and confirmation coverage.

  • 0 → 1 when a supported intent, draft artifact, or occasional practice now exists.
  • 1 → 2 only when a named client owner confirms the practice is defined and operating.
  • 2 → 3 only when current telemetry, tooling, tickets, exports, or repeated operational evidence show consistent execution.
  • 3 → 4 only when reusable automation produces governed, monitored, exception-handled evidence.
  • A delivered template or export can improve completeness without changing maturity. Target Level 3 or Level 4 remains a separate, client-specific decision.

Compare only explicitly retained baseline and closeout records with the same scope and method. Output availability is stated in the handover list; document delivery alone does not establish maturity improvement.

Reading boundary

These pathways organize preparation and evidence. A framework, platform authorization, assessment or reusable package does not replace the decision authority governing the actual system and use.

Primary framework sources

Source model da5ff605c6d24d543a2a559c58019ccb0721ddac9a785ff144cd2d7076971525 · Export manifest 8c9a337e8b89a31f1d61c8ebd5defbc71eaca0446a06cee5b065accb29394420 · Engagement crosswalk 61fa6163cff97e3431c1e93847e4c168f9fc960958fc87900f5c60c95c933e29