Skip to Main Content Subscribe

Agencies Push to Rethink ATOs as Continuous Risk Management

Share

Ensuring security features like continuous monitoring and risk assessment is central to streamlining the authority to operate process.

Written by:
Speakers at the Carahsoft DevSecOps Conference 2026 in Reston VA
NIST Cybersecurity Lead Victoria Yan Pillitteri, discusses streamlining the authority to operate process at the Carahsoft DevSecOps Conference on July 28, 2026, in Reston, Virginia. Photo Credit: Invision Events

Federal agencies need to focus on baking security into their authorization to operate (ATO) processes to make them more efficient, government and industry experts said last week at the Carahsoft DevSecOps conference in Reston, Virginia.

At its broadest definition, an ATO is when a federal official approves that software or an IT system meets all safety and acceptable risk requirements. However, there is much more to the process.

“It’s basically looking at your problem, identifying what you have, what you need to protect, and building security and privacy around that. Protecting security and privacy is just good risk management,” said Victoria Yan Pillitteri, cybersecurity lead at the National Institute of Standards and Technology.

The key to an ATO is risk management, said Dave Raley, chief digital business officer of Operation StormBreaker at the Marine Corps.

“What is the thing? What does it do? And what does it have in it? How should you secure it from that perspective?” Raley said. He added that once the process is underway, officials should get a third-party opinion, then authorizing officer approval, followed by delivering what was promised.

An ATO is not an end product, but a process to manage risk, explained Pillitteri.

While there so no way to mitigate all risk, it is up to agencies to determine what risk levels they can tolerate to achieve their mission goals. Once that is determined, they can design solutions within those constraints, said Pillitteri.

Common Misunderstandings of ATO

A common misconception about the ATO process is that it is a checklist-based process, Pillitteri said. Risk assessment is a continuous process that requires attention to detail and constant observation. An ATO acts as snapshot status for this process.

Organizations that approach ATOs as a paperwork or compliance activity are doing it wrong, she added.

“Ultimately, none of that is managing risk. All you’ve done is comply, and there really is no such thing as compliance because you are supposed to tailor everything that NIST puts out. If you’re really so focused on the ATO prize, then you’ve missed the entire purpose of the process, which is understanding and managing risk throughout the life cycle,” Pillitteri said.

Many vendors and mission owners do not fully understand what an ATO is, said Raley. He noted that one mistake is to focus on the application layer, but this is just the tip of the iceberg. What is missed is the underlying system components, capabilities such as continuous monitoring, and the overlaying mission context.

Another stumbling block is organizations’ failure to own risk, said Gary Buchanan, CIO at the National Geospatial-Intelligence Agency. Beginning an ATO process without continuous risk monitoring in place is a common mistake, he said.

Continuous monitoring is what it’s all about. So that static one-day-in-time paperwork drill, that’s not it. Has anybody ever seen a stack of papers actually secure something?” Buchanan said.

Best Practices for ATO

An important step in streamlining the ATO process is determining what is in the system of record, what is in the software bill of materials, and what are the actual security risks and vulnerabilities, said Steven Stemmer, sales director for federal law enforcement at Chainguard.

Another factor for agencies is determining provenance — which components actually carry the risk and how to address this if a vulnerability occurs. If these factors are approached as best practices, Stemmer noted that efficiently managing the ATO process “becomes a much easier world to now live in.”

Automation is key to streamlining the ATO process. Using tools such as AI to help software engineers build in security features from the very beginning of a project instead of bolting it on afterwards also greatly accelerates the process and helps with internal security checks, Raley explained.

“How do we work with human nature instead of against it?” Pillitteri said. “Because the way that we look at ATOs right now is that [doing] after the fact compliance activity … you’ve already started off on the wrong foot. So let’s build that infrastructure. Let’s train the right people. Let’s get the right tools because we do have them now.”

Those right tools include cloud services through FedRAMP, commercially available tools and automated processes for managing governance, risk and compliance on networks, she added.

“Let’s make this easy. If we build it better, then we won’t have to be doing this paperwork exercise later,” Pillitteri said.

Related Content