Generate ATO artifacts for an authorization package
Generate ATO artifacts such as System Security Plan (SSP), Security Assessment Report (SAR), and Plan of Actions and Milestones (POA&Ms) from an authorization package in Microsoft Word format.
Before you begin
Role required: sn_irm_cont_auth.admin, sn_irm_cont_auth.authorization_official, sn_irm_cont_auth.info_system_sec_manager, sn_irm_cont_auth.info_system_sec_officer, sn_irm_cont_auth.system_owner
About this task
Authorization to Operate (ATO) artifacts are documents and evidence produced while authorizing a system that support the compliance of a package with the security standards.
SSP, SAR, and POA&Ms are reports that you can generate for an authorization package. Each report is a collection of documents attached to the authorization package that gives you a consolidated, detailed report about the
effectiveness of the system security.
- SSP
- A document that provides an overview of security requirements for an information system. It describes how a system adheres to the security requirements or how it plans to meet the requirements.
- SAR
- A structured document that provides the assessment results and recommended guidelines of an assessor in remediating the vulnerabilities found in the security controls.
- POA&Ms
- A document that gives details as to how to accomplish the elements of the plan, milestones to achieve the tasks, and time line to complete the milestones.
Note:
You can generate SSP, SAR, POA&Ms reports in Microsoft Word where you can update the content in CAM
Workspace. Whereas, in classic UI you can generate the SSP report in PDF format using the Generate Report(s) button in the Authorization package form.