Blogs & Articles

Below are blogs, articles, white papers, and the like showing various ways Soteria Software and specifically OpenRMF® Professional can help you automate around RMF and FedRAMP information and processes.

Tracking Vulnerability Burndown in Container Images for RMF

Tracking Vulnerability Burndown in Container Images for RMF

To track the vulnerability burndown of images using scans, you note the open vulnerabilities based on the image tag. And track this over time. Images are not patched “in place” like workstations, servers, or virtual machines. You recreate them.


In OpenRMF Professional v2.12 coming out May 2025, you can automatically track your image vulnerability burndown over time. Just like you do with your patch vulnerabilities, software vulnerabilities, and checklist compliance vulnerabilities.

Can I Perform SCAP Scans on Container Images? Yes You Can!

Can I Perform SCAP Scans on Container Images? Yes You Can!

With software images and containerized applications on the rise, the question of scanning and compliance comes into view. These images are a little bit OS and application combined. We have vulnerability scanning. We have software bill of material (SBOM) generation. SWFT is working to use these two items to quickly get a preliminary ATO for software faster.


What about compliance checks in images? Can we scan images like we do workstations and servers? And get compliance results to generate checklists with the status and severity?


Come to find out, yes you can. Enter RapidFort.

Use your Residual Risk Numbers as your Scoring Method

Use your Residual Risk Numbers as your Scoring Method

Using our OpenRMF Professional solution, you track your open vulnerabilities on checklists and compliance scans, patch vulnerability scans, as well as other technology scans. You can quickly see your scores by status.


There is another way to score your accreditation packages: Residual Risk. Score your accreditations and network by actual RISK not just raw severity a scanner gave them.

Achieving an ATO is a Team Sport

Achieving an ATO is a Team Sport

Going through an accreditation and achieving an ATO is a team process and team goal. It takes a team of people all doing their part of the process to get the final product and achieve the required end results.


At Soteria Software, we enable organizations to use their team efficiently with proper collaboration and automation. To get past individuals doing their specific piece manually, without knowing what comes before, after, happens at the end, or anything in between.

Tools and Solutions for STIGs and Risk Management Framework (RMF) Part 1 of 4

Tools and Solutions for STIGs and Risk Management Framework (RMF) Part 1 of 4

This article show how to use DISA SCC SCAP scanner to perform a SCAP scan.


Navigating the world of information technology and cybersecurity can be overwhelming, especially for newcomers. Understanding the tools available to streamline your duties and gain insights into your area’s cyber compliance status is crucial.

Tools and Solutions for STIGs and Risk Management Framework (RMF)Part 2 of 4 DISA STIG Viewer 2.18

Tools and Solutions for STIGs and Risk Management Framework (RMF) Part 2 of 4 - DISA STIG Viewer 2.18

DISA STIG Viewer is a GUI java based application provided to open content and create checklists for managing the security setting on your system or network. Many use it to manage and edit their checklists. It is free and useful for managing your technical compliance or just securing your computer.


This article explains the tool, how to incorporate SCAP scans and what to do with checklists manually.

Tools and Solutions for STIGs and Risk Management Framework (RMF) Part 2 of 4 DISA STIG Viewer 3.5

Tools and Solutions for STIGs and Risk Management Framework (RMF) Part 2 of 4 - DISA STIG Viewer 3.5

DISA STIG Viewer is a new GUI provided to open content and create checklists for managing the security setting on your system or network. Many use it to manage and edit their checklists. It is free and useful for managing your technical compliance or just securing your computer.


This article explains the tool, how to incorporate SCAP scans and what to do with checklists manually.

How to Perform a Credentialed Patch Scan Using Tenable Nessus Professional

How to Perform a Credentialed Patch Scan Using Tenable Nessus Professional

Vulnerability management is a critical component of cybersecurity, and Nessus Professional is one of the most widely used tools for identifying security weaknesses. Among its many features, Nessus can perform patch scans to detect missing security updates across an organization’s systems. Understanding this is just a portion of your security and compliance posture. This article contains guidance on how to run a credentialed patch scan.

Where OpenRMF Professional Fits in the Larger US Federal Government Cyber Compliance Ecosystem

Where OpenRMF Professional Fits in the Larger US Federal Gov’t Cyber Compliance Ecosystem

There are applications and tools (mostly gov’t created, some home grown) right now that do pieces of the RMF, FedRAMP and cyber compliance processes. The challenge with these — they are individual, separate, mostly manual, and disjointed. You do one, then you load into another. Then you bring up 1 of 17 .xlsx files to update and send out to the team.


And when one thing changes, you do it all over again. NO MORE!!

Using System Preferences to Customize your ATO Data and Editing

Using System Preferences to Customize your ATO Data and Editing

In the latest version of OpenRMF Professional, we added some preferences to control data to use, edit, and organize. These are features customers have asked for we had in our roadmap. But we moved the timeline to the left to get them into their hands faster.


Uncredentialed scans. Disable severity override. And tigher control on adding Team Subpackage items.

Using Elasticsearch for Full Text Checklist Searching

Using Elasticsearch for Full Text Checklist Searching

We have added ELK Stack into the mix for not just logging. We are now using it to full text all checklist information for quick search and access. On our way to full text indexing your whole accreditation package. Do this using our internal ELK stack or your own Elastic Stack or Elastic Cloud.

Compliance Assessments Made Easier

Compliance Assessments Made Easy

When you have a larger Authority to Operate (ATO) with multiple tenants running under you, you have to manage a lot more than just your infrastructure. You have to manage all theirs as well!


Using OpenRMF Professional and its unique Team Subpackages feature, you can have those groups track and update just their own compliance scans, patch scans, and POAM items. While you track the impact to your entire ATO. All from the same solution.

Track Multiple Tenants in your ATO Through an Organized View of your Data

Track Multiple Tenants in your ATO Easily

When you have a larger Authority to Operate (ATO) with multiple tenants running under you, you have to manage a lot more than just your infrastructure. You have to manage all theirs as well!


Using OpenRMF Professional and its unique Team Subpackages feature, you can have those groups track and update just their own compliance scans, patch scans, and POAM items. While you track the impact to your entire ATO. All from the same solution.

What You Need to Get Moving with OpenRMF Professional

What You Need to Get Moving with OpenRMF Professional

This quick article explains what files, scans, and information you need to quickly get OpenRMF Professional working for you and your team. Use these and in a few minutes you can see where you are, where you need to go, and how to get there.


With minimal training / help files. And without paying someone hundreds of dollars an hour to “configure” and “customize” your automated cyber compliance solution.

How to NOT burn out your Cyber staff when going through Accreditation

DON'T burn out your Cyber staff during Accreditation

Please do not make your smart Cyber people do Excel wizardry, documentation galore, and be paper pushers!


Automate tasks so they can use their skills and brain more. Easy to say, hard to do — or is it?


We show the problems and offer some solutions in this article. And ask you to prove us wrong!

New Features in OpenRMF Professional v2.10

New Features in OpenRMF Professional v2.10

We finally released our long-awaited v2.10 of Soteria Software’s flagship product, OpenRMF® Professional. Here are highlights of 3 new features people have requested and are falling in love with already.


  • Missing Checklist Wizard - search the OS and software list for checklists you missed
  • Checklist Applicability Wizard - enter a hostname, pick types of checklists required, add them, create with a single click
  • Device Profiles - track the ports/protocols/services allowed for your device by attaching a profile and running reports
A Cyber Compliance Automation Journey

A Cyber Compliance Automation Journey

Here is a simple foundational model to go from manual cyber compliance scans and review, to automation of review, to automation of scans, to integration, to full up automation and more.


You build your solid foundation of automation from the ground up, automating tasks, freeing up resources and reducing your stress and blood pressure!


Use OpenRMF® Professional in your Cyber Security Mesh Architecture (CSMA) to create a best-of-breed suite of automation around your cyber needs.

Get Historical Context Around your RMF and Cyber Compliance Packages

Get Historical Context Around your RMF and Cyber Compliance Packages

One of the hardest things around tracking your different RMF, FedRAMP and other cyber compliance packages is the amount of data it generates. And aggregate it. Turn it into actionable information. Executing a plan against it.


Track configuration management and newer vulnerabilities. In an easily-to-digest way that does not involve opening 400 separate files.


The solution to handle that large amount of data, tracking changes and trends, as well as performing proper configuration management across your entire team is why we at Soteria Software created OpenRMF® Professional.

Platform IT, RMF, and Automation

Platform IT, RMF, and Automation with OpenRMF® Professional

OpenRMF® Professional has a lot of automation built-in for tracking cyber compliance. This is especially true for device, network and device scans for compliance and patch vulnerabilities.


But what about Platform IT, that special purpose hardware and software? Can OpenRMF® Professional help with Risk Management Framework (RMF) for that? In a word: YES!

Track Foreign Military Sales (FMS) Partners' Cyber Compliance Remotely with OpenRMF Professional

Track Foreign Military Sales (FMS) Partners' Cyber Compliance Remotely with OpenRMF® Professional

Foreign Military Sales (FMS) with friendly country customers must also maintain cyber compliance. And trying to explain RMF and complex controls is difficult a best! So use OpenRMF® Professional to quickly and easily accomplish that for all your FMS customers:

  1. Track compliance, patches, POAM items, and milestones remotely in multiple ways
  2. Train FMS customers on RMF easily by simplifying, structuring data, and showing how to do scans
  3. Create SOPs around use of OpenRMF® Professional with FMS and RMF
  4. Get repeatable results across your entire portfolio of FMS
Bulk Upgrade Checklists in OpenRMF Professional v2.9

Bulk Upgrade Checklists in OpenRMF® Professional v2.9

OpenRMF® Professional v2.9 contains a new highly requested feature -- Bulk Upgrade of Checklists:

  • Select multiple STIG, DISA, CIS or Custom checklists requiring upgrades
  • Click the Upgrade button
  • Bulk Upgrade of those Checklists happens in the background
  • Notifications sent on upgrade and completion of all selected
  • Keep working on other items while the upgrade happens
Track Evidence and File Attachments for Cyber Compliance with OpenRMF Professional

Track Evidence and File Attachments for Cyber Compliance

Tracking your cyber compliance for RMF, FedRAMP, StateRAMP, and the like requires more than scanning! To show all angles of cyber compliance it also requires evidence in the form of PDF, DOCX, PNG/JPG snapshots, write-ups and other documents that are not checklists or vulnerability scans.

OpenRMF® Professional v2.9 allows for that now with Evidence Management. For your whole ATO / accreditation package. POAM items. Checklist Vulnerabilities. Or even Compliance Statements.

OpenRMF Professional v2.9 released

OpenRMF® Professional v2.9 released

OpenRMF® Professional v2.9 is finally here! Some of the new features include:

  • New dashboard look and feel
  • Evidence Management
  • Bulk Upgrade Checklists
  • Bulk Edit POAM
  • New Team Subpackage Functionality
  • StateRAMP and Custom Compliance Frameworks
  • Additional reports and charts
  • Additional API calls
What Makes OpenRMF Professional different?

What Makes OpenRMF® Professional different?

There are several good GRC tools out there. What sets OpenRMF® Professional apart? A few things stand out immediately.

  1. Automating cyber compliance around the scans you are already doing!
  2. Hyper Automation around your compliance data to make it work for you
  3. Team Collaboration around all your cyber compliance data and processes
  4. Install, setup, and use on Day 1 with a little work, quick setup, and very little configuration
RMF Continuous Authorization and Monitoring with OpenRMF Professional

Enable RMF Continuous Authorization and Monitoring

Use OpenRMF® Professional to continually automate your Risk Management Framework (RMF) steps and the tasks involved. Reduce risk while reducing costs and manual tasks through automation of scans, trends, compliance, reporting, and live POAM tracking.

Implement Continuous Monitoring with OpenRMF Professional

Ways to Implement Continuous Monitoring

You can use OpenRMF® Professional to help implement 6 of the 11 security domains concerning Continuous Monitoring outlined in NIST 800–137 Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations.

What's New in OpenRMF Professional v2.8.6

OpenRMF® Professional v2.8.6 new and updated features

We have added several great features for the latest release.

Automated Cyber Readiness (CCRI). Loading lists for easier bulk add/edit. A universal patch vulnerability format for patch scans. And more! Check out in this latest article.

OpenRMF Professional is RMF. Simplified.

OpenRMF® Professional is RMF. Simplified.

Nothing works more powerfully than simplicity.


In simple terms: Stop using the 1995 Rand McNally Road Atlas (manual RMF) and start using your cell phone with GPS and Waze (automated RMF with OpenRMF® Professional) to navigate where you need to be.

OpenRMF Professional helps you comply with NIST Controls as well

OpenRMF® Professional helps you comply with NIST Controls as well automate your ATO Process

Did you know…you can actually use OpenRMF® Professional to comply with NIST controls in the CA, CM, PL, PM, RA, SA, and SC families?!?! Well you can. Not only does our OpenRMF® Professional solution speed your ATO process, save massive time and money, and move you toward a Continuous ATO process. It also helps you comply with your required RMF and FedRAMP controls at the same time.

Inherited Controls, Cloud, and OpenRMF

OpenRMF® Professional v2.8.3 Feature Release

With our new feature release out July 8th, Soteria Software has added compliance statements and detailed compliance reporting for you, your ISSO/ISSM/ISSE and Cyber team. We also included NIST 800–53 Revision 5 controls and corresponding CCIs to use. Finally, we also added support for using Rapid7 Nexpose SCAP and Full Audit scan data.

13 Ways to a Faster ATO with OpenRMF Professional

13 Ways to a Faster ATO with OpenRMF® Professional

Automation is key to attaining an ATO for your RMF or FedRAMP systems and applications faster. With OpenRMF® Professional and its latest features, you can use our compliance engine, vulnerability tracking, and reporting mechanisms to quickly see where you are, what you need to do, get compliant and then generate the documentation to prove it.

Organize Your ATO Process with Team Subpackages

Organize Your ATO Process with Team Subpackages

Your cyber personnel and program manager see and manage all your ATO information and status! Your system admins only see their checklists and devices. Your developers only see their checklists and devices. And your network admins only see their data. However, the automated compliance, POAM, vulnerability tracking and reporting is still working for you across your entire ATO system package all the time.


This is the Team Subpackages concept.

Bulk Edit, Lock and Checklist Templates for faster ATO Processes

Use Bulk Edits, Locks, and Checklist Templates a Faster ATO

Did you know you can use the checklist template engine in OpenRMF® Professional to have checklists already pre-filled with your manual checks and known good automated check results? And you can use the Bulk Edit feature for your checklist vulnerabilities to have consistent standard answers across your checklist vulnerability entries? Even use the Bulk Lock feature to cut down on false positives across your checklist updates. Do the work and automate the paperwork with OpenRMF® Professional!

Use OpenRMF Professional for Commercial Customers as well

Use OpenRMF® Professional for Commercial Customers As Well

Tracking your cyber compliance is NOT just for US Federal government or DoD in particular. Proper cyber hygiene and applying the right cyber frameworks is important regardless of you being a government agency, large business, or even a smaller business. With our latest version 2.8, you can use OpenRMF® Professional to track your CIS benchmark scans as well as DISA benchmarks against the same NIST controls for Risk Management Framework or even a tailored list of controls just as easily.

Use CIS Benchmarks to Track Cyber Compliance in OpenRMF Professional

Use CIS Benchmarks to Track Cyber Compliance in OpenRMF® Professional

With version 2.8, you can now use CIS based benchmarks to scan your applications, software, and devices for tracking compliance and vulnerabilities. Automatically make a CIS checklist template from your .audit file. Scan your devices. Upload the results. Track over time using OpenRMF® Professional’s automation engine. Combine these with SCAP scans, DISA checklists and Custom checklists designed in the Custom Checklist designer to get a full picture of your system package cyber compliance.

Inherited Controls, Cloud, and OpenRMF

Track RMF and FedRAMP system packages with inherited common controls from cloud providers

To track RMF and FedRAMP system packages as you move them to your cloud, you first can use the new OpenRMF® Professional v2.7 with Custom Checklists to create your base level infrastructure system package for your platform or cloud infrastructure. Then, use the new Inheritance feature (common controls) when generating and tracking compliance for applications, services, and platforms for your users that inherits these controls and your main infrastructure system package compliance.

OpenRMF Professional and DevSecOps

DevSecOps, RMF, and OpenRMF® Professional

OpenRMF® can fit into your DevSecOps process in several unique ways to help you with Risk Management Framework (RMF) and your ATO (Authority to Operate) process. It helps you manage security, compliance, reporting, scans and data calls in a much more automated fashion. This article takes the view of Risk Management Framework (RMF), looking at DevSecOps, through the lens of OpenRMF® Professional.

Cost of Manual RMF and FedRAMP

Cost of Manual vs. Automated Compliance

Have you ever calculated the cost of manually tracking your RMF or FedRAMP system packages? You know, the way most do it — manually editing and viewing checklists and spreadsheets, scan PDFs and reports. Have you ever tracked the same cost of manually doing the upfront work on compliance, that leads toward better cybersecurity, versus automating it?

OpenRMF Professional v2.7

We Just Released OpenRMF® Professional v2.7!

It’s the same great RMF and FedRAMP cyber compliance and collaboration application. Now it includes Tracking Inheritance and Common Controls. More powerful bulk editing and locking. Massively expanded API. Tracking Cyber Compliance History. Bulk tagging. More charts and reports. And smoother setup and installation/upgrade. Major highlights are below!