---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# RMF step 0 - Prepare the authorization package

# RMF step 0 - Prepare the authorization package {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

In the Prepare step, you set up authorization boundaries, control overlays, and information types, as well as create the actual authorization package.

## Your actions in the Prepare step {#prepare-auth-pkg__section_r4s_jpw_hcc}

* **[Define the authorization boundary](https://www.servicenow.com/docs/tyrNrQPqYbCWDW63hoTQ9A)**   
  An authorization boundary defines the scope of a particular system that can be continuously managed and monitored using the CAM application.
* **[Create an authorization package](https://www.servicenow.com/docs/sGoT7kJaNRwiMTTCq3q5Lg)**   
  After you have defined the authorization boundaries for the assets or systems to send through the Authorization to Operate process, you must create an authorization package for that purpose. The package is processed through the seven steps mandated by the RMF.

