C&A DocWriter® is the document authorship and management tool for
Certification and Accreditation (C&A)
Download our C&A Whitepaper -- Improving
Efficiency of C&A
C&A DocWriter is a client-server application for the creation,
editing, and management of large compound documents that must be maintained
by a group of people under the highest practical security conditions
while tracking requirements and testing for compliance.
Use for Government Certification & Accreditation, and Private
Sector IT Governance, Privacy, and Security Auditing
New: C&A
DocWriter Web Module provides all of the functionality needed for
C&A through the convenience of a browser-based web application.
New: Compliance
Dashboard application integrates with C&A DocWriter to provide a
complete 360 degree view of your organization's C&A process.
New: New templates and
control packs are available to support the Payment Card
Industry (PCI) Report on Compliance.
C&A DocWriter is designed for creating and managing all documents related to
Certification and Accreditation (C&A) including:
Federal Government IT Governance
DITSCAP 8510.1-M
DIACAP
NIACAP/NIST 800-18 General Support
System (GSS)
NIACAP/NIST 800-18 Major Application
(MA)
JAFAN
NISPOM
C4ISP and ISP
DCID 6/3
FIPS 201 Personal
Identity Verification
Private Sector IT Governance
Continuity of
Operations Plans (COOP)
COBIT, HIPAA, S-OX, and
Auditing for IT Privacy and Security
Payment Card Industry (PCI)
Report on Compliance
More templates and control
packs coming soon!
Use C&A DocWriter to:
- Create SSAA's and other security plans
- Manage Requirements Traceability Matrices (RTMs)
- Manage Plans of Actions and Milestones (POA&Ms)
- Manage and Document Security Test and Evaluation documents (ST&E).
- Manage and implement security controls.
And do it all within the highest practical security conditions.
Version 4.1 Now Available!
Features Include:
Knowledge Base -- Create a knowledge base of commonly used content
for security plans, security tests, risk assessments, vulnerabilities, and
other data objects. Save time by reusing content on multiple security
plans.
Plan of Actions & Milestones -- Easily create POA&Ms for
controls and export to Microsoft Word or Microsoft Excel.
Variables in the Security Plan -- Use variables as placeholders in
the security plan to simplify managing changes to content. Variables
work like mail merge to track and update values that may changes such as
persons names, offices, and contact information. Variables act as a
mail-merge in security plan creation.
Additional Features Include:
Requirements Traceability Matrix (RTM) support -- import and
manage RTMs in DocWriter. Generate RTMs in Word or Excel. Ask
about our free RTM packs of controls.
ST&E Support -- Fill out and generate ST&Es for each RTM
entry using your own custom template.
T&E Support -- Fill out and generate T&Es for each
ST&E entry using your own custom template.
Residual Risk Assessment -- Fill out and generate RRAs for each
T&E using your own custom template.
Issue Tracking -- Track issues and actions that need to be
addressed to complete your C&A documents and assure compliance with
action items. It's like bug-tracking for the C&A process.
Advanced Search -- Powerful search capability helps you find
documents and information.
Unique to C&A DocWriter is the powerful
hierarchical plan template. This approach allows all users who participate
in the C&A process to share information. It assures that security plans
are not created in isolation and are easily accessible by everyone who needs
to see them.
The
hierarchical plan brings together different users whether they are managers,
security officers or testers under one umbrella that produces greater
efficiencies and therefore lowers costs for building and managing security
plans. Immediate operational and cost containment benefits include:
- Dramatically shorter time to build a security plan and therefore
certify the system
- Skilled testers can spend less time on plan development and more on
high-value testing tasks
- Managing the plan electronically significantly reduces costs
associated with handling, plan updates and storing paper documents
- Plans are stored in an enterprise database for powerful search
capabilities allowing organizations to easily update plans as new
security threats emerge or new assets are added.
C&A DocWriter Security
C&A DocWriter allows you to develop security plans and management document under
the highest practical security conditions. C&A DocWriter is suitable for the
Department of Defense highest levels of security. Security features
include:
- Customizable password rules enforce minimum length and special
character requirements for password.
- Roles-based document access restricts documents to particular
users.
- Document version control ensures that only one user at a time
can modify a document.
- Documents are never overwritten with changes. The entire
change history of documents can be access (with the proper permission of
course!)
- User-based permissions control who gets to see or modify what.
- Every login attempt is logged.
- Every access to a document is logged.
Already have C&A underway? C&A DocWriter is the C&A Tool that
integrates your current C&A Documents
You can get started with C&A DocWriter even if you are not starting C&A from
scratch. Integrate all of your current documents into C&A DocWriter
to provide
a secure repository with web-based access. As your C&A effort
progress, you can integrate C&A DocWriter features at the pace you desire.
System Specifications:
- Desktop application supports Windows 2000, XP (including SP2) and Later
- C&A DocWriter includes highly customizable security/permissions levels
- Open database can be integrated with other enterprise systems
C&A DocWriter Database
C&A DocWriter supports the following
databases:
- Microsoft Access
- Microsoft SQL Server
- Oracle
Use C&A DocWriter as a stand-alone desktop application,
or client-server database, or both. For each database you use, you
will add users who can log in to the database, and you will set permission
settings for what each user can view or edit.
Free Trial Version on CD
Contact Starpoint Software for pricing
information and a free trial version of C&A DocWriter on CD with C&A templates
for DITSCAP, NIACAP, NIST, C4ISP JAFAN, and DCID 6/3.
C&A Training Available
Starpoint Software now offers C&A Training at your location for
DITSCAP, DIACAP, NIACAP and other C&A specifications. Contact Starpoint Software for
pricing information.