Skip to content
Open access

OpenGRCRMF: A Vendor-Neutral Framework for Teaching and Modeling RMF Automation, Continuous Authorization, and Zero Trust Governance

Aug 2026 · Journal of Cybersecurity Education, Research & Practice · 0 citations

Abstract

Abstract—Federal and regulated organizations continue to rely on document-centric Authorization to Operate (ATO) processes even as the NIST Risk Management Framework (RMF), continuous monitoring guidance, Zero Trust Architecture (ZTA), and continuous authorization initiatives require more continuous, evidence-driven risk management [1]-[3], [13], [15]. Manual System Security Plan (SSP) updates, spreadsheet-based Plan of Action and Milestones (POA&M) tracking, and disconnected assessment evidence create governance latency: the delay between operational security events and authorization-ready governance response. This paper presents OpenGRCRMF, a proposed open, vendor-neutral reference framework that models RMF lifecycle activities as workflow states, treats authorization artifacts as structured governance objects, and maps DevSecOps and Zero Trust telemetry into authorization-relevant evidence. Using Design Science Research, the study develops the OpenGRCRMF architecture, formalizes its data and risk model, and evaluates expected governance effects through a synthetic simulation of 1,500 findings across 180 assets and 320 controls [9]. OpenGRCRMF is evaluated as a reference framework rather than a production platform using a self-contained simulation specification and sensitivity analysis. In the simulation, the OpenGRCRMF-enabled workflow reduced modeled governance processing time by 36.8 percent, increased modeled evidence completeness by 41.5 percent, and increased modeled control-to-evidence traceability by 52.7 percent compared with a document-centric baseline. These results are modeled outcomes under stated assumptions, not production deployment proof. The paper contributes a governance object model, governance latency construct, reproducibility-oriented simulation design, threat-to-validity analysis, and education-oriented framework for teaching how operational telemetry becomes authorization evidence.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.