Step 1

Start with the contract-security foundation.

Classified processing begins with the facility, contract, classification guidance, approved location, responsible security roles, and DCSA direction. Confirm the DD Form 254, Security Classification Guide, authorization boundary, classification level, connectivity, users, and intended processing before designing or modifying the system.

ContractDD Form 254, classification guidance, sponsor, and performance requirements
FacilityFacility clearance, approved areas, physical protections, and access controls
RolesFSO, ISSM, ISSO, system owner, users, and government stakeholders
SystemBoundary, classification, architecture, media, connectivity, and mission use

Step 2

Prepare the people, accounts, inventories, and evidence process.

Establish the responsible security roles and access to NISP eMASS early. Build a controlled inventory of hardware, software, firmware, interfaces, media, users, privileged accounts, and locations. Define how configuration evidence, test results, risk decisions, and ongoing records will be created and protected.

Handling caution: NISP eMASS is used to manage authorization information, but DCSA states that it is not approved for storing classified information. Keep classified content out of the system and follow current DCSA guidance for package details.

Step 3

Use RMF as a lifecycle, not a one-time submission.

01

Prepare

Define stakeholders, mission, boundary, resources, and risk context.

02

Categorize

Document the system and information impact based on authoritative guidance.

03

Select

Tailor the control baseline and document overlays, inheritance, and parameters.

04

Implement

Configure the system and document how each requirement is satisfied.

05

Assess

Test implementation, document results, and address deficiencies.

06

Authorize

Present the risk posture and package for an authorization decision.

07

Monitor

Track change, vulnerabilities, evidence, incidents, and authorization conditions.

Step 4

Build an authorization package that is internally consistent.

The system description, architecture, inventories, control implementation, assessment results, risk documentation, and continuous-monitoring approach need to describe the same environment. Any mismatch creates avoidable questions during government review or onsite validation.

Package areaKey consistency check
System descriptionMission, users, classification, location, and boundary match actual use
ArchitectureComponents, interfaces, data flows, and protections match inventories and controls
Control implementationNarratives identify responsible roles, technology, evidence, and operating process
Assessment and riskFindings, mitigations, residual risk, and decisions are traceable
Continuous monitoringRecurring reviews align with system risk and authorization conditions

Step 5

Protect the authorization by controlling change.

Track hardware, software, firmware, users, privileges, connections, media, vulnerabilities, and configuration changes. Evaluate whether changes affect the authorization boundary, control implementation, risk posture, or government approval conditions before implementation.

DCSA RMF planning checklist