
Sign up to save your podcasts
Or


Authority to Operate (ATO) is a process that certifies a system to operate for a certain period of time by evaluating the risk of the system's security controls. ATO is based on the National Institute of Standards and Technology's Risk Management Framework (NIST 800-37). In this podcast, Shane Ficorilli and Hasan Yasar, both with the Carnegie Mellon University Software Engineering Institute, discuss continuous ATO, including challenges, the role of DevSecOps, and cultural issues that organizations must address.
By Members of Technical Staff at the Software Engineering Institute4.5
1818 ratings
Authority to Operate (ATO) is a process that certifies a system to operate for a certain period of time by evaluating the risk of the system's security controls. ATO is based on the National Institute of Standards and Technology's Risk Management Framework (NIST 800-37). In this podcast, Shane Ficorilli and Hasan Yasar, both with the Carnegie Mellon University Software Engineering Institute, discuss continuous ATO, including challenges, the role of DevSecOps, and cultural issues that organizations must address.

32,246 Listeners

273 Listeners

26,380 Listeners

1,105 Listeners

626 Listeners

371 Listeners

651 Listeners

44 Listeners

317 Listeners

8,077 Listeners

73 Listeners

0 Listeners

0 Listeners

6,097 Listeners

1,348 Listeners

139 Listeners

16,525 Listeners