Planning for ATO at CMS (2024)

From Waterfall to Iterative Security Planning

Using the old waterfall process, getting and maintaining an Authority to Operate (ATO) can take 3-9 months and cost $90,000-$700,000. That is a significant amount of time and resources that could be used to build secure systems.

Planning for, embracing and internalizing security and compliance early and throughout the development cycle will help your project navigate the system and address requirements more efficiently. This is the goal of the Rapid ATO initiative.

By educating and preparing stakeholders, embracing iterative security planning and automating aspects of the ATO process, Rapid ATO will lower costs and shorten timelines required to achieve authorization. This will make CMS more secure and encourage more innovation at the agency.

How did we get here?

The Federal Information Security Management Act (FISMA) of 2002 requires each federal agency to develop, document, and implement an agency-wide program to provide information security for the information and systems that support the operations and assets of the agency. FISMA was amended in 2014 to modernize federal security practices.

Every information system operated by or on behalf of the U.S federal government is required to meet FISMA standards, which includes system authorization (ATO) signed by an Authorizing Official (AO).

What is a system?

A federal information system—"system"—is composed of components for collecting, storing, and processing data. This includes all hardware, software, humans and processes associated with developing, deploying, administrating, and maintaining the application. Systems provide information and knowledge in the form of digital products.

Why do you need an ATO?

Before a system can be deployed into production, the federal agency must issue an ATO. The process used to obtain ATO is the National Institute of Standard and Technology (NIST) Risk Management Framework.

This process ensures that CMS can track and manage the risk exposure of individual systems and the agency at large. It is essential to protect critical resources and sensitive information.

When to start working on an ATO?

Getting an ATO is a complex, multi-step process that impacts the design and implementation of your system. You should start thinking about how it applies to your system before you begin designing and implementing it. Starting the ATO process after you’ve already invested in development can result in costly delays and painful rework.

We don’t develop products using waterfall anymore. It’s time to end waterfall compliance.

How to use this site?

This site should be used early and often throughout your System Development Life Cycle, especially when you’re starting to consider a future project launch or feature release. This not only ensures the long-term protection of sensitive information but also prevents costly, duplicative effort after the project’s completion.

To better understand and prepare for key points in the ATO process and align your SDLC appropriately, it’s helpful to think about the ATO in phases:

  1. Initiate
  2. Develop and Assess
  3. Operate
  4. Retire
Planning for ATO at CMS (2024)
Top Articles
The U.S. Taxation of an American Princess – Meghan Markle - The Wolf Group
Netflix is discontinuing its cheapest ad-free subscription plan in these countries | - Times of India
Craigslist Livingston Montana
Woodward Avenue (M-1) - Automotive Heritage Trail - National Scenic Byway Foundation
Ups Dropoff Location Near Me
What Are the Best Cal State Schools? | BestColleges
The Realcaca Girl Leaked
World of White Sturgeon Caviar: Origins, Taste & Culinary Uses
Erin Kate Dolan Twitter
2135 Royalton Road Columbia Station Oh 44028
Signs Of a Troubled TIPM
Hijab Hookup Trendy
How To Cut Eelgrass Grounded
The Cure Average Setlist
Craigslist Free Stuff Santa Cruz
"Une héroïne" : les funérailles de Rebecca Cheptegei, athlète olympique immolée par son compagnon | TF1 INFO
Salem Oregon Costco Gas Prices
Robin D Bullock Family Photos
Gayla Glenn Harris County Texas Update
Talkstreamlive
Sunset Time November 5 2022
Yonkers Results For Tonight
27 Paul Rudd Memes to Get You Through the Week
Litter Robot 3 RED SOLID LIGHT
Bocca Richboro
Darrell Waltrip Off Road Center
Is Light Raid Hard
Phoenixdabarbie
Co10 Unr
Babydepot Registry
Street Fighter 6 Nexus
Xfinity Outage Map Lacey Wa
Verizon TV and Internet Packages
The Land Book 9 Release Date 2023
Mistress Elizabeth Nyc
Skyrim:Elder Knowledge - The Unofficial Elder Scrolls Pages (UESP)
Tiny Pains When Giving Blood Nyt Crossword
Merkantilismus – Staatslexikon
Felix Mallard Lpsg
Search All of Craigslist: A Comprehensive Guide - First Republic Craigslist
Shane Gillis’s Fall and Rise
Busted Newspaper Mcpherson Kansas
Free Crossword Puzzles | BestCrosswords.com
Silicone Spray Advance Auto
Large Pawn Shops Near Me
Noga Funeral Home Obituaries
552 Bus Schedule To Atlantic City
Enjoy Piggie Pie Crossword Clue
Who uses the Fandom Wiki anymore?
116 Cubic Inches To Cc
Craigslist Centre Alabama
Latest Posts
Article information

Author: Corie Satterfield

Last Updated:

Views: 6342

Rating: 4.1 / 5 (62 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Corie Satterfield

Birthday: 1992-08-19

Address: 850 Benjamin Bridge, Dickinsonchester, CO 68572-0542

Phone: +26813599986666

Job: Sales Manager

Hobby: Table tennis, Soapmaking, Flower arranging, amateur radio, Rock climbing, scrapbook, Horseback riding

Introduction: My name is Corie Satterfield, I am a fancy, perfect, spotless, quaint, fantastic, funny, lucky person who loves writing and wants to share my knowledge and understanding with you.