Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

DOD CIO Office Issues Guidance on DevSecOps Continuous Authorization to Operate

by Jane Edwards
April 17, 2024
in Cybersecurity, News
Software code_272x270

Software code_272x270

The Department of Defense’s Office of the Chief Information Officer has released a document meant to serve as guidance for defense agencies seeking to achieve continuous authorization, or cATO, to operate for DevSecOps platforms and other applications produced by a software factory as part of efforts to counter cyberthreats.

Table of Contents

  • You might also like
  • GAO Offers Recommendations for Army’s Battlefield Network Modernization Effort
  • Sanjay Parthasarathy to Succeed Col. Alexander Rasmussen as Space Development Agency Chief Capability Officer
  • SSC, SpaceWERX Back 11 Firms With Latest Round of STRATFI Funding

You might also like

GAO Offers Recommendations for Army’s Battlefield Network Modernization Effort

Sanjay Parthasarathy to Succeed Col. Alexander Rasmussen as Space Development Agency Chief Capability Officer

SSC, SpaceWERX Back 11 Firms With Latest Round of STRATFI Funding

The DevSecOps Continuous Authorization Implementation Guide states that the authorizing official should demonstrate three competencies to reach cATO: continuous monitoring of risk management framework controls, active cyber defense and use of an approved DevSecOps reference design for a software factory with a secure software supply chain.

A cATO assessment ensures the software factory includes a holistic set of information to enable continuous risk analysis against agreed-to risk tolerances, feedback from cyber operations on unexpected changes in incident analysis, security configurations and other factors and continuous security posture and risk reporting, according to the document that was cleared for publication Thursday.

The guidance has classified key practices into three categories: DevSecOps platform, cATO process and DevSecOps team or people.

For instance, several cATO practices apply with regard to the DevSecOps platform, including the use of a cybersecurity service provider for monitoring the system single authorization boundary for malicious threat actor actions, development of a continuous monitoring strategy and use of security automation for tracking the application security posture within the production system.

In February 2022, the Pentagon issued a memorandum providing guidance on the necessary steps to do to allow systems to operate under a cATO state.

POC - 5th Annual CIO Summit

Register here to join the Potomac Officers Club’s 5th Annual CIO Summit on April 17 and learn more about the latest modernization strategies and how industry can help meet the priorities of federal CIOs.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

USCYBERCOM Turn to Flexible Buying Strategies to Speed Up Cyber Procurement; Courtney Maggiulli Quoted

Next Post

Rob Brown Selected as SVP of Alpha Omega’s National Security Sector

Recommended For You

Lt. Gen. David Thompson: Space Force Eyes Formation of Acquisitions Command

by Jane Edwards
October 2, 2020
Lt. Gen. David Thompson

Lt. Gen. David Thompson, vice commander of the U.S. Space Force, said the service plans to establish a new command focused on acquisition programs in 2021. The service announced...

Read moreDetails

Gen. John Hyten: DOD Considers Sensors for Missile Threat Detection No. 1 Capability

by Jane Edwards
August 12, 2021
Gen. John Hyten: DOD Considers Sensors for Missile Threat Detection No. 1 Capability

Gen. John Hyten, vice chairman of the Joint Chiefs of Staff and a two-time Wash100 Award winner, said the Department of Defense (DOD) needs sensors that can detect...

Read moreDetails

Katie Arrington: DoD’s Cyber Certification Framework Seeks to Better Understand Defense Supply Chain

by Jane Edwards
September 6, 2019
Katie Arrington: DoD’s Cyber Certification Framework Seeks to Better Understand Defense Supply Chain

Katie Arrington of the Department of Defense said DoD’s move to come up with a new cybersecurity certification model seeks to get a better oversight of the defense...

Read moreDetails

GAO: NARA Must Ensure Agencies’ Compliance With Federal Electronic Records Mgmt Policies

by Brenda Marie Rivers
December 6, 2022
GAO: NARA Must Ensure Agencies' Compliance With Federal Electronic Records Mgmt Policies

The Government Accountability Office has recommended that the National Archives and Records Administration establish a way of ensuring that small agencies have strategies in place for improving electronic...

Read moreDetails

Comptroller Kristyn Jones Appointed Acting Air Force Undersecretary; Frank Kendall Quoted

by Naomi Cooper
June 17, 2024
Comptroller Kristyn Jones Appointed Acting Air Force Undersecretary; Frank Kendall Quoted

Kristyn Jones, assistant secretary of the Air Force for financial management and comptroller, has been appointed to take on the role of undersecretary of the service branch on...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Australia
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • C5ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • Department of War
  • DHS
  • Digital Assets
  • Digital Modernization
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Intelligence Community
  • Legislation
  • M&A Activity
  • Middle East
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Technology
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!