Starpoint Software Inc.
C&A DocWriter Software
Collaborative Document Development for C&A

C&A DocWriter® is the document authorship and management tool for Certification and Accreditation (C&A)

Download our C&A Whitepaper -- Improving Efficiency of C&A

C&A DocWriter is a client-server application for the creation, editing, and management of large compound documents that must be maintained by a group of people under the highest practical security conditions while tracking requirements and testing for compliance.

Use for Government Certification & Accreditation, and Private Sector IT Governance, Privacy, and Security Auditing

New:  C&A DocWriter Web Module provides all of the functionality needed for C&A through the convenience of a browser-based web application.

New:  Compliance Dashboard application integrates with C&A DocWriter to provide a complete 360 degree view of your organization's C&A process.

New:  New templates and control packs are available to support the Payment Card Industry (PCI) Report on Compliance

C&A DocWriter is designed for creating and managing all documents related to Certification and Accreditation (C&A) including:

Federal Government IT Governance
DITSCAP 8510.1-M
DIACAP
NIACAP/NIST 800-18 General Support System (GSS)
NIACAP/NIST 800-18 Major Application (MA)
JAFAN
NISPOM
C4ISP and ISP
DCID 6/3
FIPS 201 Personal Identity Verification

Private Sector IT Governance
Continuity of Operations Plans (COOP)
COBIT, HIPAA, S-OX, and Auditing for IT Privacy and Security
Payment Card Industry (PCI) Report on Compliance


More templates and control packs coming soon!

Use C&A DocWriter to:

  • Create SSAA's and other security plans
  • Manage Requirements Traceability Matrices (RTMs)
  • Manage Plans of Actions and Milestones (POA&Ms)
  • Manage and Document Security Test and Evaluation documents (ST&E).
  • Manage and implement security controls.

And do it all within the highest practical security conditions.

Version 4.1 Now Available!

Features Include:

Knowledge Base -- Create a knowledge base of commonly used content for security plans, security tests, risk assessments, vulnerabilities, and other data objects.  Save time by reusing content on multiple security plans. 

Plan of Actions & Milestones -- Easily create POA&Ms for controls and export to Microsoft Word or Microsoft Excel.

Variables in the Security Plan -- Use variables as placeholders in the security plan to simplify managing changes to content.  Variables work like mail merge to track and update values that may changes such as persons names, offices, and contact information.  Variables act as a mail-merge in security plan creation.

Additional Features Include:

Requirements Traceability Matrix (RTM) support -- import and manage RTMs in DocWriter.  Generate RTMs in Word or Excel.  Ask about our free RTM packs of controls.

ST&E Support -- Fill out and generate ST&Es for each RTM entry using your own custom template.

T&E Support -- Fill out and generate T&Es for each ST&E entry using your own custom template.

Residual Risk Assessment -- Fill out and generate RRAs for each T&E using your own custom template.

Issue Tracking -- Track issues and actions that need to be addressed to complete your C&A documents and assure compliance with action items.  It's like bug-tracking for the C&A process.

Advanced Search -- Powerful search capability helps you find documents and information. 

Unique to C&A DocWriter is the powerful hierarchical plan template. This approach allows all users who participate in the C&A process to share information. It assures that security plans are not created in isolation and are easily accessible by everyone who needs to see them.

The hierarchical plan brings together different users whether they are managers, security officers or testers under one umbrella that produces greater efficiencies and therefore lowers costs for building and managing security plans. Immediate operational and cost containment benefits include:

  • Dramatically shorter time to build a security plan and therefore certify the system
  • Skilled testers can spend less time on plan development and more on high-value testing tasks
  • Managing the plan electronically significantly reduces costs associated with handling, plan updates and storing paper documents
  • Plans are stored in an enterprise database for powerful search capabilities allowing organizations to easily update plans as new security threats emerge or new assets are added.

C&A DocWriter Security

C&A DocWriter allows you to develop security plans and management document under the highest practical security conditions.  C&A DocWriter is suitable for the Department of Defense highest levels of security.  Security features include:

  • Customizable password rules enforce minimum length and special character requirements for password.
  • Roles-based document access restricts documents to particular users.
  • Document version control ensures that only one user at a time can modify a document.
  • Documents are never overwritten with changes.  The entire change history of documents can be access (with the proper permission of course!)
  • User-based permissions control who gets to see or modify what.
  • Every login attempt is logged.
  • Every access to a document is logged.

Already have C&A underway?  C&A DocWriter is the C&A Tool that integrates your current C&A Documents

You can get started with C&A DocWriter even if you are not starting C&A from scratch.  Integrate all of your current documents into C&A DocWriter to provide a secure repository with web-based access.  As your C&A effort progress, you can integrate C&A DocWriter features at the pace you desire.

System Specifications:

  • Desktop application supports Windows 2000, XP (including SP2) and Later
  • C&A DocWriter includes highly customizable security/permissions levels
  • Open database can be integrated with other enterprise systems

C&A DocWriter Database

C&A DocWriter supports the following databases:

  • Microsoft Access
  • Microsoft SQL Server
  • Oracle

Use C&A DocWriter as a stand-alone desktop application, or client-server database, or both.  For each database you use, you will add users who can log in to the database, and you will set permission settings for what each user can view or edit.

Free Trial Version on CD

Contact Starpoint Software for pricing information and a free trial version of C&A DocWriter on CD with C&A templates for DITSCAP, NIACAP, NIST, C4ISP JAFAN, and DCID 6/3.

C&A Training Available

Starpoint Software now offers C&A Training at your location for DITSCAP, DIACAP, NIACAP and other C&A specifications.  Contact Starpoint Software for pricing information.