ATO package preparation
Authorization packages assembled with the control evidence
How a run goes
The steps this agent takes, in order, and what each one leaves behind.
Reads the system inventory, the control baseline and the evidence store
Assembles the authorization package for a system: the system security plan, the control implementation statements and the evidence for each control
Maps the evidence to the controls and finds the gaps
Flags the controls with no evidence or evidence older than the policy allows
Drafts the package and the plan of action
Drafts the plan of action for the open findings with owners and dates
Works in

ServiceNow, SharePoint, Jira
What it does
- Assembles the authorization package for a system: the system security plan, the control implementation statements and the evidence for each control
- Flags the controls with no evidence or evidence older than the policy allows
- Drafts the plan of action for the open findings with owners and dates
Connects to
ServiceNow
Open, correlate, and resolve incidents and requests.
SharePoint
Jira
Triage, create, and update issues with audit trails.
Skills included
- Control evidence mapping
- Plan of action drafting
Need it to work differently?
Every agent can be changed: the steps it takes, the systems it uses and who approves what.