Misunderstood ATOs Are Costing Agencies Time, Money
David Raley, Chief Digital Business Officer, Operation StormBreaker, Marine Corps
Misunderstandings about the Authority to Operate (ATO) process are slowing federal technology modernization efforts and driving up costs, according to David Raley, chief digital business officer for Operation StormBreaker in the Marine Corps.
Speaking at GovCIO Media & Research’s Federal IT Efficiency Summit, Raley argued that many delays stem from a fundamental misconception about what receives an authorization. Rather than granting ATOs to individual software applications, agencies authorize integrated systems operating within specific environments, taking into account mission context, infrastructure, users and data. Raley said this misunderstanding often leads to unnecessary delays for both government teams and industry partners.
To accelerate software delivery, Raley highlighted the Marine Corps’ Operation StormBreaker initiative, which leverages modern DevSecOps practices and continuous integration and continuous deployment (CI/CD) pipelines. By building applications on preauthorized platforms, teams can inherit the majority of required security controls, reducing compliance burdens and enabling faster, more efficient delivery of mission capabilities.
-
Dave Raley Chief Digital Business Officer, Operation StormBreaker Marine Corps
-
DOW CDAO: Agencies Enter 'Top of the Third Inning' on AI’s Value
Defense intelligence leaders say AI automation will become increasingly critical as the scale and speed of operations increase.
3m read -
VA Moves AI Beyond Pilots to Improve Veteran Care
Acting VA CAIO Kimberly McManus said the department is starting to see its AI efforts bear results as it looks to expand use.
2m read -
DOT Advisor: Federal Contracting Must Adapt to Keep Pace With AI
AI is advancing faster than federal procurement cycles, making modular contracts, AI disclosure and new pricing models increasingly critical.
11m watch -
NIST Explores AI’s Role in DevSecOps
Michael Ogata discusses NIST’s latest DevSecOps research, the growing role of AI agents and the need for new approaches to identity and authorization.
4m watch