Reimagining RMF ATOs: stackArmor’s Compliance-as-Code 20x
We at stackArmor have taken to heart the recent calls to “Blow up the Risk Management Framework (RMF)” and take the compliance drama head-on. ATOs are in the news almost daily, often associated with high costs and long approval cycles with questionable outcomes. As we’re all about to light the RMF on fire and re-imagine it from first principles, we realize the real problem isn’t the RMF itself, it’s the fossilized way we’ve been playing the compliance game: binders packed with off-topic prose, screenshots that are outdated the moment they’re captured, and evidence packages that are obsolete the instant they are zipped. Traditional Federal information system assessments have been an endless cycle of: Write 700 pages of implementation statements that are marginally on topic, and only sometimes accurate. Have your highly skilled/paid engineers copy/paste screenshots into Word docs like a freshly minted, unskilled intern. Ship the whole mess to auditors