ATO as a Service™ Included in ATARC Cloud Security Working Group Report
About the ATARC Cloud Security Working Group Agile ATO Project
In September 2019, ATARC launched the Cloud Security Working Group with representatives from private and public sector. The Group proposed a proof of concept or Agile ATO pilot that aimed to demonstrate trending technologies and concepts applied to cloud environments:
(1) Zero-Trust Architectures (ZTA) and principles,
(2) DevSecOps’ integrated processes of development and operations,
(3) agile Authorizations to Operate (ATO) through automation of the assessment and authorization (A&A) process with NIST’s OSCAL and
(4) Trusted Internet Connection (TIC) 3.0 – network requirements.
The pilot was named Orion and in 2021 it became Orion JK21. The ORION JK21 team felt strongly that being able to provide a proof of concept for each of these emerging trends would move forward cloud security and compliance automation.
ATO as a Service’s Role in ATARC Agile ATO Project
ATO as a Service™ was used to auto-generate System Security Plans (SSPs) as part of the Agile ATO project. ATO as a Service™ utilizes the Open Security Controls Assessment Language (OSCAL) to auto-generate SSPs in a machine readable format.
For more information about OSCAL, click here.
Click here to download the report.
Jasson Walker Jr
cFocus Software Incorporated
+1 3014554030
email us here
Legal Disclaimer:
EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.
