🎯 Objectives
- Compile security authorization packages from assessment evidence
- Monitor authorized system security posture for changes affecting authorization
- Identify conditions that may require authorization revalidation
- Produce Plan of Action & Milestones (POA&M) tracking
- Brief Authorizing Officials on system risk posture and findings
🧠 Knowledge, Skills & Abilities (KSAs)
-
K — Knowledge
Knowledge of NIST RMF and authorization processes
-
K — Knowledge
Knowledge of security authorization package components (SSP, SAR, POA&M)
-
S — Skill
Skill in compiling and reviewing authorization documentation
-
A — Ability
Ability to synthesize complex security findings for authorization decisions
🔧 Authorized Tools
T3 — Autonomous Execution
authorization_package_querypoam_trackreport_generate
T2 — Requires Human Approval
None
T1 — Advisory Only (human executes)
authorization_decision (advisory)
💾 Memory Access
Read Access
org_assetsincident_history