Agent skill

Executing Nist Rmf Authorization To Operate

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Drive a federal system through the NIST Risk Management Framework (SP 800-37 Rev 2) to an Authorization to Operate (ATO): Prepare, Categorize (FIPS 199), Select a control baseline (FIPS 200 / SP…

Apache-2.0Auto-check passedBackend & APIs

Install Executing Nist Rmf Authorization To Operate

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill executing-nist-rmf-authorization-to-operate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills executing-nist-rmf-authorization-to-operate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/executing-nist-rmf-authorization-to-operate .claude/skills/executing-nist-rmf-authorization-to-operate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
executing-nist-rmf-authorization-to-operate
GitHub stars
34k
Token cost
~2.2k tokens
SKILL.md length
948 words
Files
5 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Drive a federal system through the NIST Risk Management Framework (SP 800-37 Rev 2) to an Authorization to Operate (ATO): Prepare, Categorize (FIPS 199), Select a control baseline (FIPS 200 / SP…

  • Works in 6 steps: Categorize (FIPS 199 + SP 800-60) → Select (FIPS 200 + SP 800-53 Rev 5 + SP… → Implement → …
  • A system needs an ATO
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Executing Nist Rmf Authorization To Operate is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Drive a federal system through the NIST Risk Management Framework (SP 800-37 Rev 2) to an Authorization to Operate (ATO): Prepare, Categorize (FIPS 199), Select a control baseline (FIPS 200 / SP 800-53 Rev 5), Implement, Assess (SP 800-53A), Authorize, and Monitor continuously. Use when a system needs an ATO or a renewal, when working a FISMA/FedRAMP authorization package, when building or reviewing an SSP, SAR, or POA&M, when categorizing a system as Low/Moderate/High impact, when selecting or tailoring a…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `scripts/process.py`).

It sits in Backend & APIs, covering Authorization and RBAC. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • A system needs an ATO
  • Working a FISMA/FedRAMP authorization package
  • Reviewing an SSP
  • Categorizing a system as Low/Moderate/High impact

Example prompts

  • “/executing-nist-rmf-authorization-to-operate”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Categorize (FIPS 199 + SP 800-60)
  2. Select (FIPS 200 + SP 800-53 Rev 5 + SP 800-53B)
  3. Implement
  4. Assess (SP 800-53A Rev 5)
  5. Authorize
  6. Monitor (continuous monitoring)

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Executing Nist Rmf Authorization To Operate loads about 2.2k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 244 tokens; SKILL.md has 948 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~244
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 948 words, ~2,199 tokens.

Download SKILL.mdSave it as .claude/skills/executing-nist-rmf-authorization-to-operate/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
executing-nist-rmf-authorization-to-operate
description
Drive a federal system through the NIST Risk Management Framework (SP 800-37 Rev 2) to an Authorization to Operate (ATO): Prepare, Categorize (FIPS 199), Select a control baseline (FIPS 200 / SP 800-53 Rev 5), Implement, Assess (SP 800-53A), Authorize, and Monitor continuously. Use when a system needs an ATO or a renewal, when working a FISMA/FedRAMP authorization package, when building or reviewing an SSP, SAR, or POA&M, when categorizing a system as Low/Moderate/High impact, when selecting or tailoring a control baseline, or when standing up continuous monitoring (ConMon) after authorization. Covers ATO, conditional ATO (cATO), and the artifacts assessors expect. Keywords: NIST RMF, 800-37, ATO, authorization to operate, FISMA, FedRAMP, SSP, SAR, POA&M, FIPS 199, FIPS 200, 800-53, 800-53A, control baseline, security categorization, continuous monitoring, authorizing official, system boundary, ongoing authorization.
domain
cybersecurity
subdomain
compliance-governance
tags
nist-rmf, nist-800-37, ato, fisma, fedramp, nist-800-53, fips-199, ssp, poam, continuous-monitoring, governance
version
1.0
author
andrewibrah
license
Apache-2.0
nist_csf
GV.OC-03, GV.RM-01, ID.AM-08, ID.RA-05, PR.IR-01
mitre_attack
T1078, T1190, T1068, T1210, T1486

Executing the NIST RMF to an Authorization to Operate (ATO)

When to Use

  • When a federal or federally-aligned system (or a FedRAMP cloud service) needs an Authorization to Operate, a re-authorization, or has fallen out of authorization.
  • When you must produce or review the core authorization artifacts: System Security Plan (SSP), Security Assessment Report (SAR), and Plan of Action & Milestones (POA&M).
  • When categorizing a system's impact level (Low / Moderate / High) under FIPS 199.
  • When selecting, tailoring, or implementing a NIST SP 800-53 Rev 5 control baseline.
  • When standing up continuous monitoring (ConMon) or pursuing ongoing authorization / cATO after an initial ATO.

Prerequisites

  • A defined system and authorization boundary (what's in, what's inherited, what's a leveraged service).
  • An identified Authorizing Official (AO), System Owner, and ISSO.
  • The information types the system handles (use SP 800-60 to map them to impact levels).
  • For cloud: the provider's Customer Responsibility Matrix (CRM) and any inherited/leveraged ATO.
  • Access to assessment evidence sources (config, scans, policies) for the Assess step.

Workflow

NIST SP 800-37 Rev 2 defines seven steps. Prepare is the foundation; the rest run in order and then loop through Monitor.

0/1. Prepare (organization and system level)

Establish context: roles (AO, SO, ISSO, assessor), risk-management strategy and tolerance (ties to SP 800-39), a control baseline strategy, common controls available for inheritance, and the system's mission/business context. Define the authorization boundary precisely — scope creep here inflates the whole package.

2. Categorize (FIPS 199 + SP 800-60)

Determine the impact level for confidentiality, integrity, and availability for each information type, then take the high-water mark across the three to set the overall system categorization: Low, Moderate, or High. Document in the SSP. This single decision drives the entire control baseline.

3. Select (FIPS 200 + SP 800-53 Rev 5 + SP 800-53B)

Start from the SP 800-53B baseline matching the categorization (Low/Moderate/High). Then tailor: apply scoping guidance, select compensating controls where needed, and assign values to organization-defined parameters. Add overlays (e.g., privacy, FedRAMP). Record the tailored set and the rationale in the SSP. Identify which controls are common (inherited), system-specific, or hybrid.

4. Implement

Deploy the selected controls and document how each is implemented in the SSP — the implementation statement, not just "yes." This is the artifact assessors read first; vague statements generate findings.

5. Assess (SP 800-53A Rev 5)

An independent assessor evaluates controls using the examine / interview / test methods against assessment objectives. Findings of "other than satisfied" become weaknesses. Output is the Security Assessment Report (SAR). Remediate what you can before authorization; the rest flows to the POA&M.

6. Authorize

Assemble the authorization package: SSP + SAR + POA&M (plus supporting artifacts). The AO reviews residual risk and renders a decision:

  • ATO — authorized, typically with a defined term and a ConMon expectation.
  • Conditional / cATO — authorized subject to conditions or operating under an approved ongoing-authorization model.
  • Denial / DATO — risk too high; system may not operate.

The decision and its rationale are captured in the authorization decision document.

7. Monitor (continuous monitoring)

Authorization is not a one-time gate. Maintain an ongoing posture: track control effectiveness, ingest scan/config drift, update the SSP on change, work the POA&M to closure, report per the ConMon plan, and feed significant changes back into reassessment. Mature programs move from periodic re-ATO to ongoing authorization.

Show full SKILL.md (410 more words)Show less

Key Concepts

ConceptDefinition
Authorization boundaryThe set of components, data flows, and inherited services covered by the authorization.
FIPS 199 categorizationLow/Moderate/High per C/I/A; overall = high-water mark across the three.
Control baselineThe SP 800-53B starting control set for the categorization, before tailoring.
TailoringAdjusting the baseline via scoping, compensating controls, and parameter values.
Common / inherited controlA control provided by another entity (e.g., the platform) and inherited by the system.
SSPSystem Security Plan — describes the system, boundary, and how each control is implemented.
SARSecurity Assessment Report — the assessor's findings on control effectiveness.
POA&MPlan of Action & Milestones — tracked weaknesses with owners and remediation dates.
ATO / cATO / DATOAuthorize / conditional (ongoing) / denial of authorization to operate.
Authorizing Official (AO)The senior official who accepts residual risk and signs the authorization.
ConMonContinuous monitoring — ongoing control-effectiveness and risk tracking post-ATO.

Tools & Systems

  • NIST SP 800-37 Rev 2 — the RMF process (7 steps).
  • FIPS 199 / FIPS 200 / SP 800-60 — categorization and minimum requirements.
  • NIST SP 800-53 Rev 5 / 800-53B — control catalog and baselines.
  • NIST SP 800-53A Rev 5 — assessment procedures (examine/interview/test).
  • OSCAL — machine-readable SSP/SAR/POA&M (NIST's authorization-document format).
  • eMASS (DoD) / FedRAMP templates — package management and submission.
  • GRC platforms — Xacta, ServiceNow, RegScale, etc., to manage the package and ConMon.
  • NIST CSF 2.0 — cross-walks to communicate RMF posture in framework terms.

Common Scenarios

  • New system pre-launch. Run Categorize → Authorize before go-live; ATO is the gate to production.
  • Cloud service (FedRAMP). Inherit the platform's controls, document the CRM split, and authorize the customer-responsible delta.
  • Re-authorization. Triggered by term expiry or significant change; refresh SSP/SAR/POA&M and re-decide.
  • cATO / ongoing authorization. Replace periodic re-ATO with continuous evidence and an approved ConMon model.
  • POA&M review. Triage open weaknesses by risk, assign owners and dates, and report closure trend to the AO.

Output Format

Produce an Authorization Package summary using assets/template.md, containing:

  1. System & boundary — description, components, data flows, inherited services.
  2. Categorization — FIPS 199 C/I/A and overall impact, with information-type rationale.
  3. Control baseline & tailoring — baseline selected, tailoring decisions, common vs system-specific.
  4. Implementation status — per-family implementation summary (from the SSP).
  5. Assessment results (SAR) — findings by severity; what's satisfied vs other-than-satisfied.
  6. POA&M — open weaknesses, risk, owner, milestone dates.
  7. Authorization decision — ATO/cATO/DATO, term, conditions, residual-risk statement, AO.
  8. ConMon plan — what's monitored, how often, reporting cadence, reassessment triggers.

Use scripts/process.py to select the right SP 800-53B baseline from a FIPS 199 categorization, summarize control-implementation status, and generate a POA&M table from a findings JSON.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/executing-nist-rmf-authorization-to-operate of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/standards.md
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Executing Nist Rmf Authorization To Operate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Executing Nist Rmf Authorization To Operate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Executing Nist Rmf Authorization To Operate this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0
Audit Reconccashwell/evm-cortex131—~1.5kAutomated safety check: PassMIT
Sec Checkwaynesutton/markdown-site628—~753Automated safety check: PassMIT
Security Threat Modelmajiayu000/spellbook287—~561Automated safety check: PassMIT
Cx Platform Admincoralogix/cx-cli121—~1.8kAutomated safety check: PassApache-2.0
Test AI Tool Authorizationcyberful/cyberful135—~549Automated safety check: PassAGPL-3.0

Similar skills

  • Audit Recon

    ccashwell/evm-cortex

    A skill your agent uses when performing initial audit reconnaissance.

    131 GitHub stars~1.5k tokensUpdated 9 days ago
    Backend & APIsAuto-check passed
  • Sec Check

    waynesutton/markdown-site

    Security review checklist for Convex functions, auth logic, public queries, admin routes, webhooks, uploads, and AI-generated code.

    628 GitHub stars~753 tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed
  • Security Threat Model

    majiayu000/spellbook

    Threat-model product features, APIs, data flows, secrets, permissions, supply-chain changes, auth boundaries, and risky code paths before or during implementation.

    287 GitHub stars~561 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Cx Platform Admin

    coralogix/cx-cli

    A skill your agent uses when the user asks "who has access", "audit permissions", "check user roles", "list API keys", "review access controls", "rotate API keys", "create API key", "delete expired…

    121 GitHub stars~1.8k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Test deterministic authorization around AI tool discovery, selection, canonical arguments, credentials, tenants, destinations, approvals, delegation, retries, and effects.

    135 GitHub stars~549 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Ideogram Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Harden an Ideogram integration across credentials, untrusted media, content safety, copyright controls, storage, and tenant authorization.

    2.8k GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Executing Nist Rmf Authorization To Operate

What does Executing Nist Rmf Authorization To Operate do?

Drive a federal system through the NIST Risk Management Framework (SP 800-37 Rev 2) to an Authorization to Operate (ATO): Prepare, Categorize (FIPS 199), Select a control baseline (FIPS 200 / SP…. Executing Nist Rmf Authorization To Operate is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Drive a federal system through the NIST Risk Management Framework (SP 800-37 Rev 2) to an Authorization to Operate (ATO): Prepare, Categorize (FIPS 199), Select a control baseline (FIPS 200 / SP 800-53 Rev 5), Implement, Assess (SP 800-53A), Authorize, and Monitor continuously.

When should I use Executing Nist Rmf Authorization To Operate?

Executing Nist Rmf Authorization To Operate fits situations like: A system needs an ATO; working a FISMA/FedRAMP authorization package; reviewing an SSP; categorizing a system as Low/Moderate/High impact.

How do I install Executing Nist Rmf Authorization To Operate in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill executing-nist-rmf-authorization-to-operate -a claude-code`. Or copy the skill folder (skills/executing-nist-rmf-authorization-to-operate in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/executing-nist-rmf-authorization-to-operate in your project. Claude Code loads it when a task matches its description.

How do I install Executing Nist Rmf Authorization To Operate in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill executing-nist-rmf-authorization-to-operate -a codex`. Or copy the skill folder (skills/executing-nist-rmf-authorization-to-operate in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/executing-nist-rmf-authorization-to-operate in your project. Codex loads it when a task matches its description.

Can I use Executing Nist Rmf Authorization To Operate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill executing-nist-rmf-authorization-to-operate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/executing-nist-rmf-authorization-to-operate, .gemini/skills/executing-nist-rmf-authorization-to-operate, .github/skills/executing-nist-rmf-authorization-to-operate and .opencode/skills/executing-nist-rmf-authorization-to-operate in your project.

What does Executing Nist Rmf Authorization To Operate need to run?

Going by SKILL.md and its folder, Executing Nist Rmf Authorization To Operate needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Executing Nist Rmf Authorization To Operate access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Executing Nist Rmf Authorization To Operate safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Executing Nist Rmf Authorization To Operate use?

Executing Nist Rmf Authorization To Operate is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Executing Nist Rmf Authorization To Operate use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to Executing Nist Rmf Authorization To Operate?

Skills that share tags, products or a category with Executing Nist Rmf Authorization To Operate: Audit Recon (ccashwell/evm-cortex, 131 stars), Sec Check (waynesutton/markdown-site, 628 stars), Security Threat Model (majiayu000/spellbook, 287 stars) and Cx Platform Admin (coralogix/cx-cli, 121 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Executing Nist Rmf Authorization To Operate?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,993 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.