Define what is entering the boundary
We document components, data flows, external services, model dependencies, trust relationships, and the changes they create for the existing authorization.
We bring AI and new system components into the program boundary, then handle integration, hardening, evidence, and authorization under the existing RMF process.
Discuss this scopeBring us in before a new AI capability or system component crosses the authorization boundary, or when an existing integration has created unanswered security and evidence questions.
We document components, data flows, external services, model dependencies, trust relationships, and the changes they create for the existing authorization.
We connect AI and integration risks to the system baseline, identify technical and procedural safeguards, and assign the evidence each safeguard must produce.
We work with engineering through implementation and testing, then update the SSP, diagrams, evidence, and assessment responses under the same RMF process.
We will review where the work stands, identify the first issue to resolve, and define the scope with the people responsible for delivery.
Talk with an RMF lead