18Fâs agile-based authority-to-operate process aims to apply an iterative approach to IT security authorizations and place security work at the start of a project.
âWhat we try to do is at the very beginning of the project, the first few weeks, we get an ATO,â Michael Torres, director of product at 18F, told Nextgov.
âAnd then every piece after that, we increment that ATO so it covers more and more of the system,â he added.
Torres noted about 18Fâs efforts to further develop the iterative ATO process with security personnel at federal agencies.
âWhat weâre advocating is to help them and help the program team just focus on this small piece that weâre releasing so that we can make sure that thatâs secure and also put in processes and maybe some infrastructure to make sure the next time we release thereâs a process for an iterative ATO that doesnât take as much time and is not as daunting,â he added.