Cyber Weapon System and Infrastructure Tool Accreditation
How can the Air Force accredit IT systems in a more efficient, trackable, and consistent manner?
IT systems are logged in Enterprise Mission Assurance Support Service (eMASS) after receiving an Authority to Operate (ATO) following a review using the Risk Management Framework (RMF) documented in AFI17-101 Risk Management Framework (RMF) for Air Force Information Technology (IT). Each base enclave is expected to maintain an ATO for each network on their base however enterprise and weapon system infrastructure resides at the base leading to conflicts. The Enterprise and each cyber weapon system does not have an eMASS package and instead requires an eMASS package per tool as it is on-boarded onto the network.