RMF step 2 - Select controls for an authorization package
When the impact levels for the package have been approved, it is time to select baseline controls.
Before you begin
Role required: To write to the sn_im_cont_baseline_control_objective table: sn_irm_cont_auth.system_owner, sn_irm_cont_auth.info_system_sec_officer, sn_irm_cont_auth.admin
To access Mark as not Applicable: sn_irm_cont_auth.info_system_sec_officer, sn_irm_cont_auth.info_system_sec_manager, sn_irm_cont_auth.admin.
GRC Continuous Authorization and Monitoring
GRC: Continuous Authorization and Monitoring quick start tests require activating the Continuous Authorization and Monitoring plugin (com.sn_compliance) and loading the demo data.
| Test | Description | Release version |
|---|---|---|
| GRC: System Owner create and validate responsibilities and roles for an AB and AP | System Owner creates and validates
responsibilities and roles for an Authorization
Boundary and Authorization Package. Information Owners and System User are pre-populated when selecting the Authorization Boundary. |
Quebec (compatible with Paris and Orlando) |
| GRC: System Owner validate App Modules visibility | Verifies that the system owner persona is
able to view the Continuous Authorization &
Monitoring application menu and the following
modules under that menu:
|
Quebec (compatible with Paris and Orlando) |
| GRC: System Owner Request First approval & My approvals module | System Owner requests an approval. | Quebec (compatible with Paris and Orlando) |
| SO: Create and validate responsibilities and roles for an AB and AP | Verifies if a system owner can create an
Authorization Boundary by completing the fields on
the Authorization Boundary form. Also verify if the same SO can create an Authorization Package from the form view. |
Quebec (compatible with Paris and Orlando) |
To learn more about Continuous Authorization and Monitoring, see Continuous Authorization and Monitoring.