From 6052e2389622caaa9d057cf846bc99b2696d01d0 Mon Sep 17 00:00:00 2001 From: Chris Compton Date: Tue, 31 Oct 2023 11:16:49 -0500 Subject: [PATCH] Adjust legend and layout. --- docs/ato/ATO.legend.drawio.svg | 10 +- docs/ato/README.md | 75 ++++- docs/ato/support/Actors.drawio.svg | 438 +++++++++++++++++++++++++++++ 3 files changed, 508 insertions(+), 15 deletions(-) create mode 100644 docs/ato/support/Actors.drawio.svg diff --git a/docs/ato/ATO.legend.drawio.svg b/docs/ato/ATO.legend.drawio.svg index 1d9d7ff..394037c 100644 --- a/docs/ato/ATO.legend.drawio.svg +++ b/docs/ato/ATO.legend.drawio.svg @@ -1,4 +1,4 @@ - + @@ -399,16 +399,16 @@ -
+
- ORGANIZATION SYSTEM OWNER + ORGANIZATION SYSTEM OWNER OR DELEGATES
- - ORGANIZATION SYSTEM OWNER + + ORGANIZATION SYSTEM OWNER OR DELEGATES diff --git a/docs/ato/README.md b/docs/ato/README.md index e01d14b..2fbcf07 100644 --- a/docs/ato/README.md +++ b/docs/ato/README.md @@ -3,17 +3,20 @@ ## Diagram Legend -![Legend](ATO.legend.drawio.svg) ->*Fig 1. Legend for the diagrams that follow.* - +
+ +
Fig 1. Legend for the diagrams that follow.
+
--- ## Initiation Phase -![Initiation](ATO.initiation.drawio.svg) ->*Fig 2. Outline of the steps necessary to complete initiation phase.* +
+ +
Fig 2. Outline of the steps necessary to complete initiation phase.
+
### Process Description @@ -29,8 +32,10 @@ ## Implementation Phase -![Implementation](ATO.implementation.drawio.svg) ->*Fig 3. Outline of the steps necessary to complete initiation phase.* +
+ +
Fig 3. Outline of the steps necessary to complete initiation phase.
+
### Process Description @@ -49,8 +54,10 @@ ## Authorization Phase -![Authorization](ATO.authorization.drawio.svg) ->*Fig 4. Outline of the steps necessary to complete initiation phase.* +
+ +
Fig 4. Outline of the steps necessary to complete initiation phase.
+
### Process Description @@ -66,4 +73,52 @@ 21. **Monitor for changes on an ongoing basis** 22. **Record system changes.** 23. Reassess. Go to #5 (or #4 if the plan requires adjustment.) -24. Reauthorize the members. \ No newline at end of file +24. Reauthorize the members. + +## System Actors + +For the purposes of the project, the roles have been collapsed into a subset of: + +- **System Administrator** (Organization) - Representing the Operations side of the sphere. +- **Authorizing Official** (Organization) - Representing the Authorization side of the sphere. +- **Federation**: General term used to describe all participating Authorizing Officials. + +A more detailed set of roles exist *(Fig. 5)*, and my be required for a fully implemented system. + +--- + +
+ +
Fig 5. An outline of roles that may be involved in a system like BloSS@M.
+
+ + + + + + + \ No newline at end of file diff --git a/docs/ato/support/Actors.drawio.svg b/docs/ato/support/Actors.drawio.svg new file mode 100644 index 0000000..66d0dfa --- /dev/null +++ b/docs/ato/support/Actors.drawio.svg @@ -0,0 +1,438 @@ + + + + + + + +
+
+
+ + Prepare + +
+
+
+
+ + Prepare + +
+
+ + + + +
+
+
+ + Categorize + +
+
+
+
+ + Categorize + +
+
+ + + + +
+
+
+ + Select + +
+
+
+
+ + Select + +
+
+ + + + + + +
+
+
+ + Implement + +
+
+
+
+ + Implement + +
+
+ + + + + + +
+
+
+ + Assess + +
+
+
+
+ + Assess + +
+
+ + + + + + +
+
+
+ + Authorize + +
+
+
+
+ + Authorize + +
+
+ + + + + + +
+
+
+ + Monitor + +
+
+
+
+ + Monitor + +
+
+ + + + + + +
+
+
+ + System Change + +
+
+
+
+ + System Change + +
+
+ + + + +
+
+
+ ATO +
+
+
+
+ + ATO + +
+
+ + + + + +
+
+
+ System Owner +
+
+
+
+ + System... + +
+
+ + + + +
+
+
+ Acquisition Specialist +
+ (Users) +
+
+
+
+ + Acquisi... + +
+
+ + + + +
+
+
+ User +
+
+
+
+ + User + +
+
+ + + + +
+
+
+ Operations +
+
+
+
+ + Operations + +
+
+ + + + +
+
+
+ System Administrator +
+
+
+
+ + System... + +
+
+ + + +
+
+
+ Authorization +
+
+
+
+ + Authorization + +
+
+ + + + + +
+
+
+ Assets +
+
+
+
+ + Assets + +
+
+ + + + + +
+
+
+ Authorization +
+
+
+
+ + Authorization + +
+
+ + + + +
+
+
+ Authorizing Official +
+
+
+
+ + Author... + +
+
+ + + + +
+
+
+ Assessor or EA +
+
+
+
+ + Assess... + +
+
+ + + + +
+
+
+ ISSO +
+
+
+
+ + ISSO + +
+
+ + + + +
+
+
+ Privacy Officer +
+
+
+
+ + Privac... + +
+
+ + + + + + +
+
+
+ Developers/ +
+ Architects +
+
+
+
+ + Develo... + +
+
+ + + + +
+
+
+ CISO/CIPO +
+
+
+
+ + CISO/C... + +
+
+
+ + + + + Text is not SVG - cannot display + + + +
\ No newline at end of file