How Technical Findings Map to Security Controls

Building on how findings become evidence? Start with How ACAS Findings Become Remediation Evidence. Most people who have worked an ACAS scan or a STIG checklist have watched a finding turn into a POA&M item without ever seeing the step that got it there. The finding shows up red in a report, and a few days later there is a line item in eMASS with a control number attached to it. Nobody walks through how that connection actually got made. ...

July 25, 2026 · 4 min · Carlos Henry

How ACAS Findings Become Remediation Evidence

New to RMF? Start with What Is RMF? A Practical Introduction for SysAdmins. Most people working in federal IT environments have pulled an ACAS report before they understood what that report was actually supposed to prove. The scan runs, Tenable.sc produces a list of findings sorted by severity, and somewhere in the process that output is supposed to turn into evidence that satisfies an AO. What nobody explains upfront is what happens between the scan finishing and a finding being considered remediated inside the RMF package. ...

June 26, 2026 · 7 min · Carlos Henry

What Is RMF? A Practical Introduction for SysAdmins

The Question Nobody Answers Directly At some point in your federal IT career, someone mentions RMF. Maybe it comes up in a meeting. Maybe you see it on a job posting. Maybe your ISSO asks for documentation you didn’t know you were supposed to keep. And if you’re a SysAdmin, something unexpected happens when you actually dig into it. The steps start making sense. The controls often map to things you already configure. The evidence they’re asking for looks a lot like documentation you probably should have been keeping anyway. You think: I actually get this. I kind of like digging into a system like this. ...

June 6, 2026 · 5 min · Carlos Henry