EMASS


The Enterprise Mission Assurance Support Service is a service-oriented computer application that supports Information Assurance program management and automates the Risk Management Framework process.

Overview

eMASS is a service-oriented computer application that supports Information Assurance program management and automates the Risk Management Framework (RMF). The purpose of eMASS is to help the DoD to maintain IA situational awareness, manage risk, and comply with the Federal Information Security Management Act and the Federal Information Security Modernization Act. eMASS is owned by the U.S. Department of Defense. The program is sponsored by the Assistant Secretary of Defense for Networks and Information Integration and is managed by the Defense Information Systems Agency Program Executive Office for Mission Assurance and NetOps.
As the DoD's recommended tool for information system Assessment and Authorization, eMASS automates the A&A process, manages workflow among user roles, and generates a variety of reports based on user needs. The functional capabilities of eMASS have evolved in response to requirements from DoD leadership and operational user feedback.
eMASS is designed to work in concert with the, and empowers the DoD IA workforce in support of the DoD 8500-series Information Assurance policy framework and implementation guidance. eMASS establishes strict process control mechanisms for obtaining authorization to connect to the DoD's Global Information Grid networks, which helps to reduce the risk of cyber attacks and to accomplish the goals of RMF.

eMASS as a Cloud Service

eMASS also provides C&A capabilities in the DoD’s cloud computing environment, the Rapid Access Computing Environment. According to DISA government officials, offering eMASS as a cloud service will help to significantly reduce the time required to certify and accredit DoD information systems.