Decision and authority register
Export available · CSV / HTML · Cloud Foundations
Named authorities, open decisions, owners, evidence basis, and next decision.
Detailed reference · framework navigator
Follow the RMF lifecycle and open a governing path at each stage to see the people, process, technology, artifacts and examples.
The nine-stage Cloud Waypoint spine adds delivery detail without creating another framework. These links show where each NIST RMF step is prepared; the governing organization retains tailoring, assessment, risk, and authorization authority.
Set roles, priorities, context, sources, and the authorization approach.
Authority · FrameworkEstablish the system boundary, information types, impact, dependencies, and data flows.
BoundaryChoose and tailor the control baseline, overlays, inheritance, and responsibilities.
RequirementsPut selected controls and supporting operating work into effect and document how they work.
ImplementationCollect evidence, test implementation, record findings, and preserve assessor independence.
Evidence · AssessmentGive the designated authorizing official the evidence, conditions, and residual risk record for a decision.
Risk decisionMaintain evidence, configuration, vulnerabilities, changes, incidents, remediation, and authorization impact.
ContinuityWhich law, policy, baseline, or outcomes govern?
Formal authorization pathway. NIST RMF implemented through DoD policy. Cloud and cyber services contribute evidence; the mission AO retains the system authorization decision.
Cloud Foundations contributes to this area.
No separate item at this stage.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Formal authorization pathway. The same NIST RMF spine, applied through FISMA, OMB direction, and each agency’s authorization policy.
Cloud Foundations contributes to this area.
No separate item at this stage.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud-service evidence plus agency authorization. FedRAMP High provides a reusable cloud-service security package. The agency still authorizes the federal information system and its specific use of the service.
Cloud Foundations contributes to this area.
No separate item at this stage.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Commercial-provider lens across the FedRAMP lifecycle. For a commercial software, SaaS, or managed-service provider pursuing FedRAMP Marketplace certification or validation. Historical Moderate aligns to Class C Advanced; historical High aligns to Class D High Assurance. The provider owns the offering and evidence, a recognized assessor supplies independent assessment where required, FedRAMP grants the Marketplace designation, and each agency AO decides agency-system use.
Cloud Foundations contributes to this area.
No separate item at this stage.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Jurisdiction-selected authorization or assurance. A jurisdiction may use NIST RMF, GovRAMP cloud assurance, its own policy, or a combination. The named government authority decides what constitutes acceptance.
Cloud Foundations contributes to this area.
No separate item at this stage.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Outcome-oriented cybersecurity risk management. CSF 2.0 organizes outcomes through Govern, Identify, Protect, Detect, Respond, and Recover. It can stand alone for improvement or support formal authorization; it does not itself issue an ATO.
Cloud Foundations contributes to this area.
No separate item at this stage.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Foundations and Application Dependency Mapping prepare evidence and decision inputs. Output availability, prerequisites and limitations below come from the Studio export registry.
Partial output · CSV / HTML · Cloud Foundations
Each assessed position against its standard and the reference sources the Studio carries, with unresolved tailoring visible. The client's own policies are not in the record, so no policy is mapped.
Export available · CSV / HTML · Cloud Foundations
Written once control selection is complete. Owners are the recorded providers, a control with none reads not recorded, and open decisions are named rather than resolved.
Written only once the control selection is complete (categorization holds a level for C, I and A).
Not currently exported · No current export · Cloud Foundations
Not produced by the Studio today: the record holds no accepted policy gaps to queue.
AR-004 · AR-016 · AR-018 · AR-022 · AR-027 · AR-029 · AR-033 · AR-041 · AR-043
Approved policy, applicability, or tailoring decisions may move the reading. A crosswalk that has not been adopted improves readiness and traceability only.
Studio stages: Entry · Foundations.
What system, service, information, and dependencies are in scope?
Formal authorization pathway. NIST RMF implemented through DoD policy. Cloud and cyber services contribute evidence; the mission AO retains the system authorization decision.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Formal authorization pathway. The same NIST RMF spine, applied through FISMA, OMB direction, and each agency’s authorization policy.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud-service evidence plus agency authorization. FedRAMP High provides a reusable cloud-service security package. The agency still authorizes the federal information system and its specific use of the service.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Commercial-provider lens across the FedRAMP lifecycle. For a commercial software, SaaS, or managed-service provider pursuing FedRAMP Marketplace certification or validation. Historical Moderate aligns to Class C Advanced; historical High aligns to Class D High Assurance. The provider owns the offering and evidence, a recognized assessor supplies independent assessment where required, FedRAMP grants the Marketplace designation, and each agency AO decides agency-system use.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Jurisdiction-selected authorization or assurance. A jurisdiction may use NIST RMF, GovRAMP cloud assurance, its own policy, or a combination. The named government authority decides what constitutes acceptance.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Outcome-oriented cybersecurity risk management. CSF 2.0 organizes outcomes through Govern, Identify, Protect, Detect, Respond, and Recover. It can stand alone for improvement or support formal authorization; it does not itself issue an ATO.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Foundations and Application Dependency Mapping prepare evidence and decision inputs. Output availability, prerequisites and limitations below come from the Studio export registry.
Export available · CSV / HTML · ADM
Applications, owners, interfaces, observations, conflicts, and unresolved crossings.
Requires Application Dependency Mapping, with applications and dependencies recorded.
Not currently exported · No current export · ADM
Not produced by the Studio today: the Studio imports inventory but writes no candidate configuration items or relationships.
Partial output · CSV / HTML · Foundations + ADM
Boundary components, flows, interconnections and limitations as CSV and HTML; diagrams appear within Package readiness. A separate SVG file and a single bundled pack are not supplied.
Not currently exported · No current export · ADM
Not produced by the Studio today: no CMDB classes, identifiers or reconciliation rules are generated.
AR-006 · AR-007 · AR-008 · AR-009 · AR-021 · AR-022 · AR-023 · AR-026 · AR-028 · AR-029 · AR-030
Owner-confirmed inventory and reconciled dependencies can support movement. Observation is evidence of communication, not proof that the path is approved or complete.
Studio stages: Foundations · GSS design.
Which outcomes, controls, overlays, and responsibilities apply?
Formal authorization pathway. NIST RMF implemented through DoD policy. Cloud and cyber services contribute evidence; the mission AO retains the system authorization decision.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Formal authorization pathway. The same NIST RMF spine, applied through FISMA, OMB direction, and each agency’s authorization policy.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud-service evidence plus agency authorization. FedRAMP High provides a reusable cloud-service security package. The agency still authorizes the federal information system and its specific use of the service.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Commercial-provider lens across the FedRAMP lifecycle. For a commercial software, SaaS, or managed-service provider pursuing FedRAMP Marketplace certification or validation. Historical Moderate aligns to Class C Advanced; historical High aligns to Class D High Assurance. The provider owns the offering and evidence, a recognized assessor supplies independent assessment where required, FedRAMP grants the Marketplace designation, and each agency AO decides agency-system use.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Jurisdiction-selected authorization or assurance. A jurisdiction may use NIST RMF, GovRAMP cloud assurance, its own policy, or a combination. The named government authority decides what constitutes acceptance.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Outcome-oriented cybersecurity risk management. CSF 2.0 organizes outcomes through Govern, Identify, Protect, Detect, Respond, and Recover. It can stand alone for improvement or support formal authorization; it does not itself issue an ATO.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
No separate item at this stage.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Foundations and Application Dependency Mapping prepare evidence and decision inputs. Output availability, prerequisites and limitations below come from the Studio export registry.
Partial output · CSV / HTML · Cloud Foundations
SSP draft, a responsibility and ownership register with unresolved ownership visible, and an inheritance CSV when control selection is complete. Separate provider, enterprise, platform, GSS and workload tiers are not recorded.
Written only once the control selection is complete (categorization holds a level for C, I and A).
Export available · CSV / HTML · Foundations + ADM
Traces each assessed position and each selected control to its sources or evidence, workstreams, findings or open weaknesses, owner and open decisions. Controls and positions, not requirements; the record holds no position-to-control mapping, so none is drawn.
Partial output · CSV / HTML · Cloud Foundations
Open decisions and unmet acceptance tests held for disposition, with their reasons. The record holds no agency, component, jurisdiction or workload deltas, so none are listed.
AR-004 · AR-008 · AR-010 · AR-016 · AR-017 · AR-018 · AR-019 · AR-020 · AR-022 · AR-027 · AR-029 · AR-030 · AR-043 · AR-044 · AR-045 · AR-046 · AR-047 · AR-048
A confirmed allocation and accepted responsibility model can support movement. Cloud Waypoint does not select the final baseline or accept inherited risk.
Studio stages: GSS design · Package.
How do people, process, and technology satisfy them?
Formal authorization pathway. NIST RMF implemented through DoD policy. Cloud and cyber services contribute evidence; the mission AO retains the system authorization decision.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Formal authorization pathway. The same NIST RMF spine, applied through FISMA, OMB direction, and each agency’s authorization policy.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud-service evidence plus agency authorization. FedRAMP High provides a reusable cloud-service security package. The agency still authorizes the federal information system and its specific use of the service.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Commercial-provider lens across the FedRAMP lifecycle. For a commercial software, SaaS, or managed-service provider pursuing FedRAMP Marketplace certification or validation. Historical Moderate aligns to Class C Advanced; historical High aligns to Class D High Assurance. The provider owns the offering and evidence, a recognized assessor supplies independent assessment where required, FedRAMP grants the Marketplace designation, and each agency AO decides agency-system use.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Jurisdiction-selected authorization or assurance. A jurisdiction may use NIST RMF, GovRAMP cloud assurance, its own policy, or a combination. The named government authority decides what constitutes acceptance.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Outcome-oriented cybersecurity risk management. CSF 2.0 organizes outcomes through Govern, Identify, Protect, Detect, Respond, and Recover. It can stand alone for improvement or support formal authorization; it does not itself issue an ATO.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Foundations and Application Dependency Mapping prepare evidence and decision inputs. Output availability, prerequisites and limitations below come from the Studio export registry.
Export available · CSV · Foundations + ADM
Jira-shaped CSV for client review and mapping. ServiceNow import compatibility is not established.
Carries the workstreams placed on the storyboard; with none placed the file holds only its header.
Partial output · CSV · Foundations + ADM
Planning CSV available. A Microsoft Project XML file is also generated and checked against Microsoft's published schema; opening it in Microsoft Project has not yet been confirmed.
Carries the workstreams placed on the storyboard; with none placed the file holds only its header.
Not currently exported · No current export · Foundations + ADM
Not produced by the Studio today: the Studio does not model Must, Should, Could or Won't priorities.
Partial output · HTML / JSON · Cloud Foundations
HTML reference and a generated JSON process library. Most content is the practice's fixed library, labelled as such; roles per process, measures and tests are not recorded.
AR-006 · AR-007 · AR-008 · AR-009 · AR-010 · AR-011 · AR-012 · AR-013 · AR-014 · AR-015 · AR-019 · AR-020 · AR-024 · AR-028 · AR-030 · AR-031 · AR-032 · AR-033 · AR-034 · AR-035 · AR-041 · AR-042 · AR-044 · AR-045 · AR-046 · AR-047 · AR-048 · AR-049 · AR-050
A plan or backlog is not implementation evidence. Movement above Defined requires adopted workflow and current operating proof from the client environment.
Studio stages: GSS design · Operate.
What proves the intended result and who produced it?
Formal authorization pathway. NIST RMF implemented through DoD policy. Cloud and cyber services contribute evidence; the mission AO retains the system authorization decision.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Formal authorization pathway. The same NIST RMF spine, applied through FISMA, OMB direction, and each agency’s authorization policy.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud-service evidence plus agency authorization. FedRAMP High provides a reusable cloud-service security package. The agency still authorizes the federal information system and its specific use of the service.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Commercial-provider lens across the FedRAMP lifecycle. For a commercial software, SaaS, or managed-service provider pursuing FedRAMP Marketplace certification or validation. Historical Moderate aligns to Class C Advanced; historical High aligns to Class D High Assurance. The provider owns the offering and evidence, a recognized assessor supplies independent assessment where required, FedRAMP grants the Marketplace designation, and each agency AO decides agency-system use.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Jurisdiction-selected authorization or assurance. A jurisdiction may use NIST RMF, GovRAMP cloud assurance, its own policy, or a combination. The named government authority decides what constitutes acceptance.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Outcome-oriented cybersecurity risk management. CSF 2.0 organizes outcomes through Govern, Identify, Protect, Detect, Respond, and Recover. It can stand alone for improvement or support formal authorization; it does not itself issue an ATO.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Foundations and Application Dependency Mapping prepare evidence and decision inputs. Output availability, prerequisites and limitations below come from the Studio export registry.
Export available · CSV / HTML · Foundations + ADM
Evidence pointer, source, position, confirmation, limitation, and related action.
Export available · CSV · Cloud Foundations
Findings, owners, milestones, evidence needs, dependencies, and status for client import.
Export available · JSON · Cloud Foundations
Included within the closeout or client pack; not a standalone download.
Partial output · CSV / HTML · Foundations + ADM
What the client's systems return for closeout verification: source, location, retention, owner and cadence, from the record. Export formats and field layouts for each client system are not specified.
AR-010 · AR-012 · AR-015 · AR-016 · AR-017 · AR-018 · AR-019 · AR-020 · AR-023 · AR-025 · AR-026 · AR-027 · AR-028 · AR-029 · AR-030 · AR-037 · AR-038 · AR-039 · AR-043 · AR-044 · AR-045 · AR-046 · AR-047 · AR-048 · AR-051
Only attributable, current evidence changes the closeout reading. A generated index makes evidence usable but does not make an unsupported control effective.
Studio stages: Assessment · Package.
Who independently examines design, operation, and evidence?
Formal authorization pathway. NIST RMF implemented through DoD policy. Cloud and cyber services contribute evidence; the mission AO retains the system authorization decision.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Formal authorization pathway. The same NIST RMF spine, applied through FISMA, OMB direction, and each agency’s authorization policy.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud-service evidence plus agency authorization. FedRAMP High provides a reusable cloud-service security package. The agency still authorizes the federal information system and its specific use of the service.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Commercial-provider lens across the FedRAMP lifecycle. For a commercial software, SaaS, or managed-service provider pursuing FedRAMP Marketplace certification or validation. Historical Moderate aligns to Class C Advanced; historical High aligns to Class D High Assurance. The provider owns the offering and evidence, a recognized assessor supplies independent assessment where required, FedRAMP grants the Marketplace designation, and each agency AO decides agency-system use.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Jurisdiction-selected authorization or assurance. A jurisdiction may use NIST RMF, GovRAMP cloud assurance, its own policy, or a combination. The named government authority decides what constitutes acceptance.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Outcome-oriented cybersecurity risk management. CSF 2.0 organizes outcomes through Govern, Identify, Protect, Detect, Respond, and Recover. It can stand alone for improvement or support formal authorization; it does not itself issue an ATO.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Foundations and Application Dependency Mapping prepare evidence and decision inputs. Output availability, prerequisites and limitations below come from the Studio export registry.
Export available · CSV / HTML · Cloud Foundations
Each applicable position, score, label, rationale, gap, evidence, quality, confidence, and confirmation.
Requires a Foundations engagement with populated assessment evidence.
Export available · CSV / HTML · Foundations + ADM
Reviewable findings tied to evidence positions and transformation actions.
Requires a Foundations engagement with populated assessment evidence.
Export available · CSV / HTML · Cloud Foundations
Evidence locations, test needs, open questions, package sections, and named custodians; not an SAP or SAR.
AR-016 · AR-017 · AR-018 · AR-019 · AR-020 · AR-025 · AR-037 · AR-043 · AR-044 · AR-045 · AR-046 · AR-047 · AR-048
Cloud Waypoint may reassess evidence posture with the client. Independent assessors retain assessment conclusions and the governing authority retains acceptance.
Studio stages: Assessment.
Who accepts, conditions, treats, transfers, or rejects risk?
Formal authorization pathway. NIST RMF implemented through DoD policy. Cloud and cyber services contribute evidence; the mission AO retains the system authorization decision.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
No separate item at this stage.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Formal authorization pathway. The same NIST RMF spine, applied through FISMA, OMB direction, and each agency’s authorization policy.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
No separate item at this stage.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud-service evidence plus agency authorization. FedRAMP High provides a reusable cloud-service security package. The agency still authorizes the federal information system and its specific use of the service.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
No separate item at this stage.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Commercial-provider lens across the FedRAMP lifecycle. For a commercial software, SaaS, or managed-service provider pursuing FedRAMP Marketplace certification or validation. Historical Moderate aligns to Class C Advanced; historical High aligns to Class D High Assurance. The provider owns the offering and evidence, a recognized assessor supplies independent assessment where required, FedRAMP grants the Marketplace designation, and each agency AO decides agency-system use.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
No separate item at this stage.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Jurisdiction-selected authorization or assurance. A jurisdiction may use NIST RMF, GovRAMP cloud assurance, its own policy, or a combination. The named government authority decides what constitutes acceptance.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
No separate item at this stage.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Outcome-oriented cybersecurity risk management. CSF 2.0 organizes outcomes through Govern, Identify, Protect, Detect, Respond, and Recover. It can stand alone for improvement or support formal authorization; it does not itself issue an ATO.
Cloud Foundations contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
No separate item at this stage.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Foundations and Application Dependency Mapping prepare evidence and decision inputs. Output availability, prerequisites and limitations below come from the Studio export registry.
Partial output · HTML · Cloud Foundations
HTML brief available; PDF uses the browser print function rather than a generated PDF export.
Export available · CSV / HTML · Cloud Foundations
Decision, authority, evidence basis, dependencies, due point, and unresolved conditions.
Export available · CSV · Cloud Foundations
Jira-shaped CSV of actions for client review. Import mapping and action approval remain with the client.
AR-001 · AR-002 · AR-003 · AR-004 · AR-005 · AR-016 · AR-017 · AR-018 · AR-031 · AR-034 · AR-035 · AR-036 · AR-037 · AR-038 · AR-039 · AR-040 · AR-041
A dated client decision can close an open decision and change evidence posture. Only the designated authority accepts, conditions, transfers, treats, or rejects risk.
Studio stages: Package · Closeout.
How are change, performance, incidents, and residual risk monitored?
Formal authorization pathway. NIST RMF implemented through DoD policy. Cloud and cyber services contribute evidence; the mission AO retains the system authorization decision.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Formal authorization pathway. The same NIST RMF spine, applied through FISMA, OMB direction, and each agency’s authorization policy.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud-service evidence plus agency authorization. FedRAMP High provides a reusable cloud-service security package. The agency still authorizes the federal information system and its specific use of the service.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Commercial-provider lens across the FedRAMP lifecycle. For a commercial software, SaaS, or managed-service provider pursuing FedRAMP Marketplace certification or validation. Historical Moderate aligns to Class C Advanced; historical High aligns to Class D High Assurance. The provider owns the offering and evidence, a recognized assessor supplies independent assessment where required, FedRAMP grants the Marketplace designation, and each agency AO decides agency-system use.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Jurisdiction-selected authorization or assurance. A jurisdiction may use NIST RMF, GovRAMP cloud assurance, its own policy, or a combination. The named government authority decides what constitutes acceptance.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Outcome-oriented cybersecurity risk management. CSF 2.0 organizes outcomes through Govern, Identify, Protect, Detect, Respond, and Recover. It can stand alone for improvement or support formal authorization; it does not itself issue an ATO.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Cloud Foundations contributes to this area.
Application Dependency Mapping contributes to this area.
Foundations and Application Dependency Mapping prepare evidence and decision inputs. Output availability, prerequisites and limitations below come from the Studio export registry.
Partial output · CSV / HTML · Cloud Foundations
Transformation reports and CSV available. A Microsoft Project XML file is also generated and checked against Microsoft's published schema; opening it in Microsoft Project has not yet been confirmed.
Carries the workstreams placed on the storyboard; with none placed the file holds only its header.
Export available · JSON / HTML · Cloud Foundations
Compares a sealed baseline and a sealed closeout of the same scope and method: evidence completeness and, separately, maturity over readings confirmed in both. A pair that is not comparable gets no movement, only the reasons; the records do not carry the Studio release that scored each reading.
Requires a comparable baseline and closeout record of the same engagement (same scope and method).
Not currently exported · No current export · Foundations + ADM
Not produced by the Studio today: the process library's event taxonomy is teaching content; nothing is generated from the record for ITSM or CMDB tools.
Client-owned · Client systems and records · Client
Client-owned: the client configures, owns and operates it. The Studio does not produce it.
AR-010 · AR-011 · AR-012 · AR-013 · AR-014 · AR-015 · AR-016 · AR-017 · AR-018 · AR-019 · AR-020 · AR-021 · AR-022 · AR-023 · AR-024 · AR-025 · AR-026 · AR-027 · AR-028 · AR-032 · AR-033 · AR-035 · AR-036 · AR-037 · AR-038 · AR-039 · AR-040 · AR-042 · AR-043 · AR-044 · AR-045 · AR-046 · AR-047 · AR-048 · AR-049 · AR-050 · AR-051
The closeout delta is measured only after evidence review. Sustained Level 3 or Level 4 requires client operation beyond the handover date and may need later verification.
Studio stages: Operate · Closeout.
When immutable baseline and closeout records cover the same applicable 51 evidence positions, compare the confirmed readings and report the 0–4 average, the existing 30/40/30 People–Process–Technology composite, domain movement, changed positions, and confirmation coverage.
Compare only explicitly retained baseline and closeout records with the same scope and method. Output availability is stated in the handover list; document delivery alone does not establish maturity improvement.
These pathways organize preparation and evidence. A framework, platform authorization, assessment or reusable package does not replace the decision authority governing the actual system and use.
Source model da5ff605c6d24d543a2a559c58019ccb0721ddac9a785ff144cd2d7076971525 · Export manifest 8c9a337e8b89a31f1d61c8ebd5defbc71eaca0446a06cee5b065accb29394420 · Engagement crosswalk 61fa6163cff97e3431c1e93847e4c168f9fc960958fc87900f5c60c95c933e29