For Federal agencies, Continuous Authorization to Operate (cATO) is a challenging, but necessary, approach to reduce cyber risk and accelerate innovation. To achieve cATO, agencies must produce real-time security data through continuous monitoring of risk management framework (RMF) controls that are embedded in the DevSecOps process.
Participants from various federal agencies shared their experiences with the ATO process, the role of an Authorizing Official (AO), as well as the challenges of transitioning to a continuous ATO model.
Format: |
|
Topics: | |
Website: | Visit Publisher Website |
Publisher: | ATARC |
Published: | March 29, 2023 |
License: | Copyrighted |
Copyright: | © ATARC |