azurenoops / azurenoops/spin_agent
[WM-BW-7] Authorization export allowed without AO Risk Acceptance Statement
- Dominant language
- C#
- Stars
- 3
- Forks
- 1
- Avg merge
- 11h 20m
- Merged PRs (30d)
- 70
Description
## WM-BW-7 — No Identity-Bound AO Risk Acceptance Statement Required Before Export
**Category:** Broken ATO/RMF Workflow | **Priority:** High
**Regulation:** SP 800-37 Authorize Step
### Observation
Authorization export is allowed without a human-authored, named, identity-bound AO Risk Acceptance Statement. RMF gates are advisory-only. No AO attribution record model was observed.
### Evidence
- Issue #647 — RMF gates are advisory-only; no AO attribution record model observed
### Impact
Authorization packages can be exported without any documented AO decision. This renders the authorization artifact meaningless — there is no accountable decision-maker, no stated conditions, and no expiration date.
### Acceptance Criteria
- [ ] AO Risk Acceptance Statement record model created: AO identity, decision (authorize/deny), conditions, expiration date, timestamp
- [ ] Authorization export blocked unless a completed AO Risk Acceptance Statement exists
- [ ] Statement included in authorization package export
- [ ] RMF gate for Authorize step enforced (not advisory)
Contributor guide
Assessment
This issue has not been assessed yet.