<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>RMF on WellScript</title><link>https://wellscript.io/tags/rmf/</link><description>Recent content in RMF on WellScript</description><image><title>WellScript</title><url>https://wellscript.io/images/wellscript-cover.png</url><link>https://wellscript.io/images/wellscript-cover.png</link></image><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 25 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://wellscript.io/tags/rmf/index.xml" rel="self" type="application/rss+xml"/><item><title>How Technical Findings Map to Security Controls</title><link>https://wellscript.io/rmf/how-technical-findings-map-to-security-controls/</link><pubDate>Sat, 25 Jul 2026 00:00:00 +0000</pubDate><guid>https://wellscript.io/rmf/how-technical-findings-map-to-security-controls/</guid><description>How ACAS scans and STIG checks connect to NIST 800-53 controls in eMASS, and what CCI and AP actually do behind the scenes.</description></item><item><title>Scheduled Searches and Alerts That Satisfy Continuous Monitoring</title><link>https://wellscript.io/splunk/scheduled-searches-continuous-monitoring/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://wellscript.io/splunk/scheduled-searches-continuous-monitoring/</guid><description>How scheduled searches and alerts in Splunk turn continuous monitoring from a policy requirement into evidence an assessor will accept.</description></item><item><title>How ACAS Findings Become Remediation Evidence</title><link>https://wellscript.io/rmf/how-acas-findings-become-remediation-evidence/</link><pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate><guid>https://wellscript.io/rmf/how-acas-findings-become-remediation-evidence/</guid><description>ACAS findings do not become remediation evidence on their own. Here is how scan data moves from Tenable.sc into the documentation your AO actually reviews.</description></item><item><title>What Is a POA&amp;M and How Does It Support Your ATO?</title><link>https://wellscript.io/poam/what-is-a-poam/</link><pubDate>Sun, 14 Jun 2026 00:00:00 +0000</pubDate><guid>https://wellscript.io/poam/what-is-a-poam/</guid><description>A POA&amp;amp;M is more than a list of open findings. It is a formal commitment that shapes your ATO, drives remediation timelines, and tells your AO whether risk is being managed.</description></item><item><title>What Is eMASS and How Does It Support RMF?</title><link>https://wellscript.io/emass/what-is-emass/</link><pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate><guid>https://wellscript.io/emass/what-is-emass/</guid><description>eMASS is the DoD&amp;#39;s system of record for RMF packages — here&amp;#39;s what it actually does, how it fits the authorization workflow, and what working in it looks like.</description></item><item><title>What Is RMF? A Practical Introduction for SysAdmins</title><link>https://wellscript.io/rmf/what-is-rmf/</link><pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate><guid>https://wellscript.io/rmf/what-is-rmf/</guid><description>RMF isn&amp;#39;t a bureaucratic detour from technical work. It&amp;#39;s where your technical work gets evaluated, justified, and either trusted or questioned.</description></item></channel></rss>