Agencies Push to Rethink ATOs as Continuous Risk Management
Ensuring security features like continuous monitoring and risk assessment is central to streamlining the authority to operate process.
Federal agencies need to focus on baking security into their authorization to operate (ATO) processes to make them more efficient, government and industry experts said last week at the Carahsoft DevSecOps conference in Reston, Virginia.
At its broadest definition, an ATO is when a federal official approves that software or an IT system meets all safety and acceptable risk requirements. However, there is much more to the process.
“It’s basically looking at your problem, identifying what you have, what you need to protect, and building security and privacy around that. Protecting security and privacy is just good risk management,” said Victoria Yan Pillitteri, cybersecurity lead at the National Institute of Standards and Technology.
The key to an ATO is risk management, said Dave Raley, chief digital business officer of Operation StormBreaker at the Marine Corps.
“What is the thing? What does it do? And what does it have in it? How should you secure it from that perspective?” Raley said. He added that once the process is underway, officials should get a third-party opinion, then authorizing officer approval, followed by delivering what was promised.
An ATO is not an end product, but a process to manage risk, explained Pillitteri.
While there so no way to mitigate all risk, it is up to agencies to determine what risk levels they can tolerate to achieve their mission goals. Once that is determined, they can design solutions within those constraints, said Pillitteri.
Common Misunderstandings of ATO
A common misconception about the ATO process is that it is a checklist-based process, Pillitteri said. Risk assessment is a continuous process that requires attention to detail and constant observation. An ATO acts as snapshot status for this process.
Organizations that approach ATOs as a paperwork or compliance activity are doing it wrong, she added.
“Ultimately, none of that is managing risk. All you’ve done is comply, and there really is no such thing as compliance because you are supposed to tailor everything that NIST puts out. If you’re really so focused on the ATO prize, then you’ve missed the entire purpose of the process, which is understanding and managing risk throughout the life cycle,” Pillitteri said.
Many vendors and mission owners do not fully understand what an ATO is, said Raley. He noted that one mistake is to focus on the application layer, but this is just the tip of the iceberg. What is missed is the underlying system components, capabilities such as continuous monitoring, and the overlaying mission context.
Another stumbling block is organizations’ failure to own risk, said Gary Buchanan, CIO at the National Geospatial-Intelligence Agency. Beginning an ATO process without continuous risk monitoring in place is a common mistake, he said.
“Continuous monitoring is what it’s all about. So that static one-day-in-time paperwork drill, that’s not it. Has anybody ever seen a stack of papers actually secure something?” Buchanan said.
Best Practices for ATO
An important step in streamlining the ATO process is determining what is in the system of record, what is in the software bill of materials, and what are the actual security risks and vulnerabilities, said Steven Stemmer, sales director for federal law enforcement at Chainguard.
Another factor for agencies is determining provenance — which components actually carry the risk and how to address this if a vulnerability occurs. If these factors are approached as best practices, Stemmer noted that efficiently managing the ATO process “becomes a much easier world to now live in.”
Automation is key to streamlining the ATO process. Using tools such as AI to help software engineers build in security features from the very beginning of a project instead of bolting it on afterwards also greatly accelerates the process and helps with internal security checks, Raley explained.
“How do we work with human nature instead of against it?” Pillitteri said. “Because the way that we look at ATOs right now is that [doing] after the fact compliance activity … you’ve already started off on the wrong foot. So let’s build that infrastructure. Let’s train the right people. Let’s get the right tools because we do have them now.”
Those right tools include cloud services through FedRAMP, commercially available tools and automated processes for managing governance, risk and compliance on networks, she added.
“Let’s make this easy. If we build it better, then we won’t have to be doing this paperwork exercise later,” Pillitteri said.
This is a carousel with manually rotating slides. Use Next and Previous buttons to navigate or jump to a slide with the slide dots
-
Agencies Shift Security, Compliance Left to Deliver Software Faster
Officials are shifting compliance and AI governance earlier in the development to match commercial software speed and maintain security.
2m read -
Army Targets 2028-2029 for Digital Engineering Ecosystem
Army's Rosie Bauer said a fully connected digital ecosystem will link acquisition, requirements and logistics into a continuous thread.
2m read -
Federal Developers Treat AI Like a Junior Engineer
Federal technology leaders say AI coding assistants should be treated like junior engineers within DevSecOps pipelines.
4m read -
Federal Experts Urge Rigorous Testing Before Deploying AI Tools
The use of AI in government organizations requires security experts to revise how these tools are evaluated and tested before deployment.