Starpoint Software Inc.
C&A DocWriter Software
Collaborative Document Development for C&A

C&A DocWriter® -- Software Suite for Managing C&A and IT Security

C&A DocWriter is a client-server application database for the management of IT security controls and documents. Use for Government Certification & Accreditation, and Private Sector IT Governance, Privacy, and Security Auditing

New:  Download our new animated training movies showing program features and capabilities.

New:  New templates and control packs are available to support the Payment Card Industry (PCI) Report on Compliance

Download our C&A Whitepaper -- Improving Efficiency of C&A

Use C&A DocWriter for the following C&A and IT security applications:

Federal Government IT Governance
DITSCAP 8510.1-M
DIACAP
NIACAP/NIST 800-18 General Support System (GSS)
NIACAP/NIST 800-18 Major Application (MA)
JAFAN
NISPOM
C4ISP and ISP
DCID 6/3
FIPS 201 Personal Identity Verification
Army Regulation 25-2 August 3, 2007
NERC CIP Controls
More templates and control packs coming soon!
Private Sector IT Governance
Continuity of Operations Plans (COOP)
COBIT, HIPAA, S-OX, and Auditing for IT Privacy and Security
Payment Card Industry (PCI) Report on Compliance
Use C&A DocWriter to:
Create SSAA's and other security plans
Manage Requirements Traceability Matrices (RTMs)
Manage Plans of Actions and Milestones (POA&Ms)
Manage and Document Security Test and Evaluation documents (ST&E).
Manage and implement security controls.

New:  Version 5.0 Now Available!

Version 5.0 Features a New, More Efficient, Database Design Supporting:
Multiple Projects in a Single Database -- Manage all of your C&A data in a single database.
Multiple Systems per Project
Multiple Instances of an IA Control per System -- Track IA controls at any level of granularity.
Multiple Document Plan Templates per System -- Author and Track Multiple SSPs, SSAAs, COOPs, and other documents.
Share IA Controls Among Systems -- Improves management of system boundaries and provides more efficient documentation. 
Predefine Groups of IA Controls -- Build custom groups of controls for improved efficiency and reuse.
Version 5.0 Includes New Utility Programs
New Control Pack Builder utility to build your own packages of custom IA controls.  C&A DocWriter now supports importing IA controls from Microsoft Excel.
New Traveler Client allows entering data without a network connection. -- Enter data on the go and synchronize with the master database when your connection is reestablished.
Traveler Client is optimized for Pen-Based computing on the Tablet PC.  Use a Tablet PC like a clipboard and enter data using the built-in handwriting recognition in the Traveler Client.
New Plan Builder utility to allows you to build and share document plan templates for SSPs, COOPs, and other plans.
New Administration Console consolidates all of your administrative tasks in a separate client.
Version 5.0 New Knowledge Base Minimizes Repetitive Data Entry
C&A DocWriter uses an new IA Control Knowledge Base to minimize repetitive data entry of IA control results.  As users enter data for IA controls, they can quickly browse previous entries for the same or similar controls and with a single button click, duplicate those results.  This minimizes the tedium of documenting control results and enables consistent responses and documentation across systems.
Other Great Features Include:
Generate C&A Artifacts in Word or Excel
Requirements Traceability Matrix
Plan of Actions and Milestones (POA&M)
DIACAP Scorecard
Issue Tracking -- Track issues and actions that need to be addressed to complete your C&A documents and assure compliance with action items.  It's like bug-tracking for the C&A process.
Advanced Search -- Powerful search capability helps you find documents and information. 

Author Security Plans in a Secure, Collaborative Environment

Unique to C&A DocWriter is the powerful hierarchical plan template. This approach allows all users who participate in the C&A process to share information.

The hierarchical plan brings together different users whether they are managers, security officers or testers under one umbrella that produces greater efficiencies and therefore lowers costs for building and managing security plans. Immediate operational and cost containment benefits include:

  • Dramatically shorter time to build a security plan and therefore certify the system
  • Skilled testers can spend less time on plan development and more on high-value testing tasks
  • Managing the plan electronically significantly reduces costs associated with handling, plan updates and storing paper documents
  • Plans are stored in an enterprise database for powerful search capabilities allowing organizations to easily update plans as new security threats emerge or new assets are added.

C&A DocWriter Security

C&A DocWriter allows you to develop security plans and management document under the highest practical security conditions.  C&A DocWriter is suitable for the Department of Defense highest levels of security.  Security features include:

  • Customizable password rules enforce minimum length and special character requirements for password.
  • Roles-based document access restricts documents to particular users.
  • Document version control ensures that only one user at a time can modify a document.
  • Documents are never overwritten with changes.  The entire change history of documents can be access (with the proper permission of course!)
  • User-based permissions control who gets to see or modify what.
  • Every login attempt is logged.
  • Every access to a document is logged.

Already have C&A underway?  C&A DocWriter is the C&A Tool that integrates your current C&A Documents

You can get started with C&A DocWriter even if you are not starting C&A from scratch.  Integrate all of your current documents into C&A DocWriter to provide a secure repository with web-based access.  As your C&A effort progress, you can integrate C&A DocWriter features at the pace you desire.

System Specifications:

  • Desktop application supports Windows 2000, XP (including SP2) and Later
  • C&A DocWriter includes highly customizable security/permissions levels
  • Open database can be integrated with other enterprise systems

C&A DocWriter Database

C&A DocWriter supports the following databases:

  • Microsoft Access (2000 and Later)
  • Microsoft SQL Server (2000 and Later)
  • Oracle (9i and Later)

 

C&A DocWriter is backed by a proven history of commercial software development for science and engineering markets. Since 1994, Starpoint Software Inc. has been developing and marketing and critically acclaimed and commercially successful Windows software applications for the demanding customers in science and engineering. Out customer base ranges from small firms to Fortune 500 companies, from universities to government agencies in over thirty-five countries around the world.