Reference Library

DoW & DISA Reference Materials.

Curated frameworks, publications, guidance, and standards relevant to DoWIN-aligned DevSecOps, RMF authorization, and DoW capability delivery. These are the authoritative sources that inform how ClearSpring and the Capability Factory are built and operated.

5Frameworks
4Publications
4Guidance Docs
3Standards
Zero Trust
DoW Zero Trust Strategy
Department of Defense

The DoW's overarching strategy for implementing zero trust architecture across all DoW information systems and networks. Defines the seven pillars and target-level activities.

View Resource
RMF
Risk Management Framework (RMF)
NIST / DISA

NIST SP 800-37 Rev. 2 — the foundational framework for managing security and privacy risk across federal information systems. Defines the six-step RMF lifecycle used across DoW.

View Resource
Architecture
DoW Cybersecurity Reference Architecture
DoW CIO

Defines the enterprise cybersecurity architecture for DoW information systems. Covers identity, access management, network segmentation, and endpoint security aligned to zero trust.

View Resource
Acquisition
Adaptive Acquisition Framework (AAF)
DAU / USD(A&S)

The DoW's flexible acquisition framework with six pathways. The Software Acquisition Pathway (SWP) is directly relevant to DevSecOps-enabled capability delivery inside environments like the DCF.

View Resource
JCIDS
JCIDS Manual
Joint Chiefs of Staff

The Joint Capabilities Integration and Development System manual. Defines the requirements process that drives capability development — the upstream input to the Capability Factory intake process.

View Resource
DevSecOps
DevSecOps Fundamentals Guidebook
DISA

DISA's authoritative guidance on DevSecOps implementation for DoW programs. Covers pipelines, container hardening, CI/CD security, and integration with the RMF authorization process.

View Resource
Reference Design
DoW Enterprise DevSecOps Reference Design
DoW CIO / DISA

Reference architecture for DoW DevSecOps implementations. Defines the hardened container platform, CI/CD pipeline, and security toolchain that ClearSpring is built to align with.

View Resource
Strategy
DoW Software Modernization Strategy
DoW CIO

The DoW's strategy for modernizing software development and delivery. Emphasizes continuous delivery, software factories, and the shift from program-centric to product-centric delivery models.

View Resource
cATO
Continuous ATO Playbook
DISA / DoW CIO

Guidance on implementing Continuous Authorization to Operate (cATO) for DoW programs. Defines the technical and process requirements for maintaining an ongoing authorization posture.

View Resource
STIG
DISA Security Technical Implementation Guides (STIGs)
DISA FSO

The authoritative source for DISA STIGs — configuration standards for DoW IT systems. ClearSpring's pre-validated controls are built against these baselines across every stack layer.

View Resource
eMASS
eMASS User Guide
DISA

Enterprise Mission Assurance Support Service — the DoW's system of record for RMF. Understanding eMASS workflows is essential for any program pursuing ATO inside the DoWIN.

View Resource
ACAS
ACAS (Assured Compliance Assessment Solution)
DISA

DISA's vulnerability scanning solution required across DoW networks. ClearSpring integrates ACAS natively — continuous scanning is a byproduct of the engineering process, not a separate step.

View Resource
Cloud SRG
DoW Cloud Computing Security Requirements Guide
DISA

Security requirements for cloud services used within DoW. Defines the impact levels (IL2–IL6) and authorization requirements relevant to capability deployment inside DoWIN-aligned environments.

View Resource
NIST 800-53
NIST SP 800-53 Rev. 5
NIST

Security and Privacy Controls for Information Systems and Organizations. The control catalog underlying RMF — ClearSpring's pre-validated controls map directly to these families.

View Resource
Containers
NIST SP 800-190: Container Security Guide
NIST

Application Container Security Guide. Defines security considerations for container images, registries, orchestration, and runtime — directly applicable to ClearSpring's Platform Layer.

View Resource
FISMA
FISMA Implementation Project
NIST

Federal Information Security Modernization Act implementation resources. Covers the full suite of FISMA-related NIST publications that define the compliance baseline for federal systems.

View Resource
How We Use These

Built to the Standard.
Not Adapted to It.

ClearSpring and the DISA Capability Factory are not commercial tools adapted for DoW. They were designed from the ground up against these frameworks — the STIGs, the RMF control catalog, the DevSecOps reference design, and the zero trust architecture. Every resource listed here has a direct implementation counterpart in how we build and operate.

STIG → ClearSpring Security Layer

DISA STIGs are pre-configured at every ClearSpring layer. Teams inherit compliant baselines — no manual STIG application required.

RMF / eMASS → Continuous ATO

ClearSpring generates RMF artifacts and eMASS-ready evidence as a byproduct of engineering operations. The ACCIDENT framework automates this continuously.

DevSecOps Ref. Design → Pipeline Layer

The DoW Enterprise DevSecOps Reference Design is the architectural blueprint for ClearSpring's Pipeline Layer — hardened CI/CD with integrated SAST, DAST, and container scanning.

Engage PD INC

See These Standards
Implemented in Practice.

Request a briefing to see how ClearSpring and the DISA Capability Factory implement these frameworks operationally — inside a live, authorized DoWIN environment.