Authority to Operate (ATO) is a process that certifies a system to operate for a certain period of time by evaluating the risk of the system's security controls. ATO is based on the National Institute of Standards and Technology’s Risk Management Framework (NIST 800-37). In this podcast, Shane Ficorilli and Hasan Yasar, both with the Carnegie Mellon University Software Engineering Institute, discuss continuous ATO, including challenges, the role of DevSecOps, and cultural issues that organizations must address.
Supply Chain Risk Management: Managing Third Party and External Dependency Risk
Introduction to the Mission Thread Workshop
Applying Agile in the DoD: Eleventh Principle
A Workshop on Measuring What Matters
Applying Agile in the DoD: Tenth Principle
Predicting Software Assurance Using Quality and Reliability Measures
Applying Agile in the DoD: Ninth Principle
Cyber Insurance and Its Role in Mitigating Cybersecurity Risk
AADL and Dassault Aviation
Tactical Cloudlets
Agile Software Teams and How They Engage with Systems Engineering on DoD Acquisition Programs
Coding with AADL
The State of Agile
Applying Agile in the DoD: Eighth Principle
A Taxonomy of Operational Risks for Cyber Security
Agile Metrics
Four Principles for Engineering Scalable, Big Data Systems
An Appraisal of Systems Engineering: Defense v. Non-Defense
HTML5 for Mobile Apps at the Edge
Applying Agile in the DoD: Seventh Principle
Create your
podcast in
minutes
It is Free