Skip to main content

Published: 10/23/2024

CFACTS UI Changes: Current and new comparison

by CFACTS

We've prepared a list of changes for you to easily compare the old navigation to new.

This blog is part of a series of updates about the changes coming to the CFACTS application. The UI is being revised to better reflect the RMF (Risk Management Framework) process. We will be posting updates regularly to help you navigate this transition.

With the RMF UI changes, the tabs you are used to seeing in the authorization package are going to look different and some sections have been moved to other tabs to better reflect the RMF. These changes are detailed below. You can see the destination of the sections once the new RMF UI is released (we are anticipating rollout in early January). 

General tab

SectionNew TabNotes
Authorization Package TypeStep 0 - PrepareContains: Division Owner, Reporting Divisions
Information System DetailsStep 0 - PrepareNow found on sub tab: General Information
System Provider(s) for Service or CapabilitiesStep 0 - PrepareNow found on sub tab:  Hosting and Leveraged Services or Capabilities

This section has been renamed: Leveraging Other Services or Capabilities

Contains: CMS System Provider(s), FedRAMP Cloud Service(s), Non FedRAMP Cloud Service(s)

 
System Inheritor(s) for Services or CapabilitiesStep 0 - PrepareNow found on sub tab:  Hosting and Leveraged Services or Capabilities

 This section has been renamed: System(s) Leveraging Your Services or Capabilities 

Contains: System Inheritor(s), Inherited Controls and Elements: (Display Report)
Cloud ServicesStep 0 - PrepareNow found on sub tab:  Hosting and Leveraged Services or Capabilities

This section has been renamed: Leveraging Other Services or Capabilities

Contains: CMS System Provider(s), FedRAMP Cloud Service(s), Non FedRAMP Cloud Service(s)
StakeholdersStep 0 - PrepareNow found on sub tab: Stakeholder Identification
ISSO DocumentsStep 0 - PrepareNow found on sub tab: Stakeholder Identification

Contains: ISSO Documents
Related Pre-TPWAStep 1 - Categorize

 Now found on sub tab: PIA

Contains: Related Pre-TPWA

Appendix DocumentationStep 4 - AssessNow found on sub tab: Related Documents


Security Category tab

SectionNew TabNotes
Organizational UsersStep 1 -Categorize 
Information TypeStep 0 - PrepareNow found on sub tab: Information Types Inventory and Information Lifecycle   
Personally Identifiable Information (PII)Step 1 -Categorize 
Protected Health Information (PHI)Step 1 -Categorize 
Security CategoryStep 1 -CategorizeContains: Additional Security Category Documentation
Digital Identity DetailsStep 1 -Categorize 
Sub tab: SORNStep 1 -CategorizeContains: System of Records Notice (SORN) 
Sub tab: Contingency Plan Details Step 1 -CategorizeContains: Contingency Plan Documentation
Sub tab: incident Response Plan DetailsStep 1 -CategorizeContains: Incident Response Documentation 
Sub tab: PIAStep 1 -CategorizeContains: Privacy Impact Assessment (PIA), Privacy Impact Assessment(PIA) Details, Privacy Impact Assessment(PIA) Documentation
Sub tab: ISRAStep 0 - Prepare

Note: the ISRA is no longer on its own sub tab

Now found on sub tab: 

Information Types Inventory and Information Lifecycle 

Contains:  Prepare Information Security Risk Assessment (ISRA) Documentation, Generate ISRA button, Business and System Risks, Information and Security Risk Assessment(ISRA) Documentation

 

Sub tab: Computer Matching AgreementStep 1 -CategorizeContains: Computer matching Agreement Documentation
Sub tab: SIA documentationStep 1 -CategorizeContains: Security Impact Assessment Documentation
Sub tab: AuthenticationStep 1 -CategorizeContains: Authentication Selection, Related Authentication, Authentication Metrics Summary
Sub tab: E-CAPStep 1 -CategorizeThis tab is being retired and will not be in the new UI.
Sub tab:  High Value Assets (HAV)Step 1 -CategorizeContains: High Value Assets (HVA)High Value Documentation
Sub tab: M-21-31 LoggingStep 1 -CategorizeContains: M-21-31 Logging Questionnaire


Boundary tab

SectionNew TabNotes
CDM VisibilityStep 6 - Monitor 
Boundary DescriptionStep 0 - Prepare

Now found on sub tab: Authorization Boundary

 

 Contains: Authorization Boundary Description

Boundary DiagramsStep 0 – Prepare

Now found on sub tab: Authorization Boundary


Contains: Boundary Diagram Documentation

Interconnection(s)Step 0 – Prepare

Now found on sub tab: Authorization Boundary 

 

Contains: Interconnections

 

Memorandum of Understanding (MOU)Step 0 – Prepare

Now found on sub tab: Authorization Boundary 

Contains: Memorandum of Understanding(MOU) Documentation

System FQDN(s)Step 0 – Prepare

Now found on sub tab: Authorization Boundary 

Contains: System FQDNs

Hardware SummaryStep 0 – Prepare


Now found on sub tab: Authorization Boundary 

Contains: Hardware Cross Reference Report (Display Report)

Software SummaryStep 0 - Prepare


Now found on sub tab: Authorization Boundary 

Contains: Software

Controls tab

SectionNew TabNotes
Planned ARS Migration DateRemovedThis field has been removed as it is no longer needed.
Control ActionStep 2, 3 - Select and Implement 
Sub tab: ARS 5 SummaryStep 2, 3 - Select and ImplementContains: Count of Controls
Sub tab: Allocated Controls Elements Cross-ReferenceStep 2, 3 - Select and ImplementContains: Allocated Controls Elements Cross-Reference, Allocated Control Elements 
Sub tab: Allocated Controls Elements ReportStep 2, 3 - Select and ImplementContains: Allocated Controls Elements Report Instructions (Display Report)
Sub tab: Control Elements Missing Shared Implementation DetailsStep 2, 3 - Select and ImplementContains: Control Elements Missing Shared Implementation Details Report (Display Report)
Sub tab: Control Elements Missing Private Shared Implementation DetailsStep 2, 3 - Select and ImplementContains: Missing Private Implementation Details Report (Display Report)
Sub tab: Not Assessed and Other Than Satisfied Control ElementsStep 2, 3 - Select and ImplementContains: Not Assessed and Other Than Satisfied Control Elements (Display Report)

(This doesn’t appear unless there are controls in the package.)
Sub tab: CAAT TemplateStep 2, 3 - Select and ImplementContains: CAAT Template (Display Report)
Archive ControlsStep 2, 3 - Select and Implement 

Assessments tab

SectionNew TabNotes
Assessment HistoryStep 4 - AssessNow found on sub tab: Assessment
Assessment ArtifactsStep 4 - AssessNow found on sub tab: Assessment
Authorization Package DocumentationStep 4 - Assess

Name changed to:
Current Documentation (Display Report)

Now found on sub tab: Related Documents

 

POA&Ms tab

Section New Tab 
POA&Ms Summary Step 4 – AssessNow found on sub tab: POA&Ms
Sub tab: Open POA&MsStep 4 – Assess

 Now found on sub tab: POA&Ms

 Contains: Open POA&Ms Details (Display Report)

Sub tab: Delayed POA&MsStep 4 – Assess

 Now found on sub tab: POA&Ms

 Contains: Delayed POA&Ms Details (Display Report)

Sub tab: Pending Verification POA&MsStep 4 – Assess

 Now found on sub tab:POA&Ms

Contains: Pending Verification POA&Ms Details (Display Report)

Sub tab: Completed POA&MsStep 4 – Assess

Now found on sub tab: POA&Ms

Contains: Completed POA&Ms Details (Display Report)


 

Sub tab: Count of POA&Ms By Overall Status

Step 4 – Assess

Now found on sub tab: POA&Ms

Contains: Count of POA&Ms By Overall Status Details (Display Report)

 

 

Sub tab: Open POA&Ms Milestone Updates ReportsStep 4 - Assess

Now found on sub tab: POA&Ms

Contains: Open POA&Ms Milestone Updates Reports Details (Display Report)

Authorization tab

SectionNew TabNotes
Pre-assessment ReviewStep 4 - Assess

Now found on sub tab:

Assessment

System Security and Privacy Plan (SSPP)Step 5 - Authorize

Now found on sub tab: 

Authorization Decision and Details 

Contains: System Security and Privacy Plan (SSPP) Documentation, Generate SSPP Button

 

Security Assessment ReportStep 4 - Assess

Now found on sub tab: Assessment

 Contains: Security Assessment Report(SAR)

ATO RequestsStep 5 - Authorize

Now found on sub tab: ATO Requests 

Contains: ATO Requests

Override ATO Request InformationStep 5 – AuthorizeNow found on sub tab: ATO Requests
Authorization Decision Step 5 – Authorize

 Now found on sub tab: 

Authorization Decision and Details

Contains: Authorization Memo Documentation

 

Ongoing Authorization Details

Step 5 - Authorize

Now found on sub tab: 

Authorization Decision and Details

Certification Form (Legacy)Step 5 – Authorize

Now found on sub tab: Authorization Decision and Details 

Contains: Certificate Form

ATO DetailsStep 5 – AuthorizeNow found on sub tab: ATO Requests
ATO Maintenance = AttestationStep 5 - Authorize

Now found on sub tab: ATO Requests 

Contains Control Elements Assessment Since ATO Report (Display Report)

RetireStep 5 - Authorize

Now found on sub tab: Retirement

Contains: Retire Documentation, Retire Comments

 

Documentation tab

SectionNew TabNotes
Authorization Package DocumentationStep 4 - AssessNow found on sub tab: Related Documents Name changed to:
Current Documentation (Display Report)
Archived DocumentationStep 4 - AssessContains: Archived Documentation (Display Report)

Community Portal tab

The Community Portal has been phased out and will not be a part of the new RMF UI. You can aways reach out to the slack channel #cfacts_community if you need clarification or guidance.

Have questions?

Reach out to us on the CFACTS_Community slack channel or make an inquiry through the CFACTS Portal.

About the publisher:

The CMS FISMA Continuous Tracking System (CFACTS) is the database used to track system security and support the system authorization process. The CFACTS Team works on improvements to the platform and helps people use it effectively.