GovCIO Media & Research Podcasts

← GovCIO Media & Research Podcasts8. Sept. · 6 Min.

Streamlining the ATO Process Makes Software Deployments More Efficient, Secure | CyberCast

Streamlining the ATO Process Makes Software Deployments More Efficient, Secure | CyberCast8. Sept.6 Min.

Federal agencies can make the authorization to operate (ATO) process more efficient by treating security as an ongoing part of software development rather than a checklist to complete before deployment, according to Victoria Yan Pillitteri, cybersecurity lead at the National Institute of Standards and Technology.

Speaking with GovCIO Media & Research at the Carahsoft DevSecOps Conference, Pillitteri outlined common misconceptions that can slow the ATO process, including treating authorization as a one-time compliance exercise or simply a hurdle to clear for approval. Pillitteri explained how NIST guidance gives agencies flexibility to tailor the ATO process to their specific missions, systems and risk tolerances rather than taking a one-size-fits-all approach.

She also discusses how clearly defining roles and responsibilities, strengthening risk management practices and building security into software development from the beginning can help agencies streamline authorization while deploying software more efficiently and securely.