{"id":50173,"date":"2024-06-28T20:37:28","date_gmt":"2024-06-28T20:37:28","guid":{"rendered":"https:\/\/one.sightlinemg.com\/defensenews\/uncategorized\/2024\/06\/28\/how-achievable-is-the-continuous-authority-to-operate-model\/"},"modified":"2026-08-08T18:48:07","modified_gmt":"2026-08-08T18:48:07","slug":"how-achievable-is-the-continuous-authority-to-operate-model","status":"publish","type":"post","link":"https:\/\/one.sightlinemg.com\/defensenews\/opinion\/2024\/06\/28\/how-achievable-is-the-continuous-authority-to-operate-model\/","title":{"rendered":"How achievable is the continuous Authority to Operate model?"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Software is a critical component of military missions, but for too long, the Defense Department\u2019s security compliance procedures have blocked organizations from delivering relevant software capabilities to the warfighter.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Mission requirements and cyber threats change quickly. Staying current requires agile development practices that continuously integrate and deliver high-quality software with reduced risk. Security authorizations should be equally nimble, but repeatedly seeking an Authority to Operate, or ATO, is notoriously time-consuming. Waiting for an ATO and working through assessments is often the longest step in deploying software. These delays can have significant consequences, especially on the battlefield.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are better ways to manage the risk of information systems. DoD officials recently released the <a href=\"https:\/\/dodcio.defense.gov\/Portals\/0\/Documents\/Library\/DoDCIO-ContinuousAuthorizationImplementationGuide.pdf\">DevSecOps Continuous Authorization Implementation Guide<\/a>, which maps out the principles of the continuous Authority to Operate, or cATO, model. After a system achieves its initial authorization, properly implementing cATO a la ongoing authorization is a fundamental step in the department\u2019s vision to build a faster, more secure development environment and achieve software supremacy.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What is cATO?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Getting a traditional ATO requires a point-in-time check of security controls that can drag on for months. The exercise repeats when new features roll out or the authorization expires. Meanwhile, cyber adversaries continue to unveil novel threats.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">cATO is an ongoing authorization for continuous delivery after achieving the initial authorization. It allows an organization to build and release new system capabilities if it can continuously monitor them against the approved security controls. To achieve cATO, DoD identifies three criteria organizations must meet:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2014 Continuous monitoring of security controls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2014 Active cyber defense measures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2014 The adoption of DevSecOps practices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Shifting from periodic reviews to constant monitoring avoids drifting out of compliance and creates a more robust cybersecurity posture. This isn\u2019t just theory; it\u2019s a proven concept. As co-founder of the U.S. Air Force\u2019s Kessel Run, we originally designed cATO as a specified approach to ongoing authorization for continuous delivery, without cutting any corners.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We applied DecSecOps principles to meet the National Institute of Standards and Technology\u2019s<a href=\"https:\/\/csrc.nist.gov\/Projects\/risk-management\/about-rmf\"> Risk Management Framework<\/a>, or RMF, requirements. In April 2018, DoD officials approved cATO for Kessel Run\u2019s systems. The ongoing authorization granted authorization at the time of release and removed it as the bottleneck for lead time and deployment frequency. High performing DevOps organizations employing this approach often achieve lead time and deployment frequency that is measured in hours, which is considered \u201celite\u201d in <a href=\"https:\/\/cloud.google.com\/devops\/state-of-devops\">The State of DevOps Report<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Preparing teams for ongoing authorization<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">cATO is not a waiver or a shortcut to compliance with the RMF. Instead, the method tackles requirements at every step of the software development lifecycle to reduce risk. When done correctly, adopting this ongoing authorization strategy is still about authorizing the system, not \u201cauthorizing the people and the process\u201d or employing \u201ccATO pipelines.\u201d That said, the inputs that result in secure and authorized outputs for a trustworthy and transparent environment are the right people, processes, and technologies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To start, leaders must foster a culture of security awareness across the organization by eliminating bureaucratic barriers and recruiting the right technical talent. To shift left on anything, we have to make space for it. For example, cutting low-value work out of developer schedules or removing backlogs gives them time to work on security with their regular tasks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Programs should have at least one dedicated independent technical assessor for their teams, who work for their Security Controls Assessor and Authorizing Official, to help get the software to production more efficiently. And because security doesn\u2019t happen in a silo, build open lines of communication between security, development, and operations teams to synchronize the latest mission requirements.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Building a security baseline<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A critical technical component of continuous authorization is maximizing common control inheritance. The RMF allows applications deployed on top of cloud and platform environments to inherit the underlying controls. Organizations like software factories or service-level programs with thousands of apps can quickly see time and cost savings by architecting for these authorized common controls providers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The DoD has the opportunity to drive greater efficiency by providing centralized, inheritable security baselines and cloud services for department-wide use, or at a minimum, mission-wide use. Enterprise-wide common controls would enhance the entire department\u2019s cyber posture and support faster software delivery for every service and component.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Building a transparent system<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Successful cATO implementations require organizations to deeply understand a system and the cascading effects of any changes to it. Organizations must focus on transparency and traceability, embracing an everything-as-code mindset to ensure controls remain within the approved configurations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Processes require digitization and, when feasible, automation, including documentation and evidence assessment. The most commonly used governance, risk and compliance platforms weren\u2019t built for ongoing authorizations; systems with the ability to handle modular evidence packages may need to replace antiquated platforms. Give the team\u2019s independent technical assessors access to logs, code repositories, and dashboards to monitor controls and communicate changes to authorizing officials as necessary.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One misconception is that pipelines are a magic wand for cATO. While they are an essential tool, there is much more required for ongoing authorization. A smart way to use pipelines is to incorporate scans that evaluate software against service-level agreements and block it from the production environment if issues remain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At the end of the day, an organization pursuing cATO must produce a secure system and deliver new capabilities within an acceptable risk profile. Ongoing authorizations are the most effective way for DoD to streamline software delivery and ensure a future where fewer bad things happen because of bad software.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/bryon-kroger\/?lipi=urn%3Ali%3Apage%3Ad_flagship3_profile_view_base_recent_activity_content_view%3BA2%2FCe44cTZK2wbEAir6MfQ%3D%3D\"><i>Bryon Kroger<\/i><\/a><i> is the CEO and founder at Rise8 and co-founder of the U.S. Air Force\u2019s Kessel Run, the Department of Defense\u2019s first software factory, where he pioneered cATO.<\/i><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Staying current requires agile development practices that continuously integrate and deliver high-quality software with reduced risk.<\/p>\n","protected":false},"author":7,"featured_media":112597,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_canonical":"","_acf":"","_yoast_wpseo_primary_category":17,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","_smg_distribution_targets":[]},"categories":[33,17],"tags":[],"coauthors":[7971],"class_list":["post-50173","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-home","category-opinion"],"acf":{"subheadline":"By embracing ongoing authorizations, DOD empowers developers to release software at a rapid pace without compromising on security.","legacy_arc_id":"EUDI77Z5HVFWZPJLZIU3MX3N4I","arc_canonical_url":"\/opinion\/2024\/06\/28\/how-achievable-is-the-continuous-authority-to-operate-model\/","remove_feature_photo":false,"is_sponsored":false,"subtype":"","redirect_url":"","disable_inline_ads":false,"native_logo_pretext":"Presented By:"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>How achievable is the continuous Authority to Operate model? - Defense News<\/title>\n<meta name=\"description\" content=\"Staying current requires agile development practices that continuously integrate and deliver high-quality software with reduced risk.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/2024\/06\/28\/how-achievable-is-the-continuous-authority-to-operate-model\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How achievable is the continuous Authority to Operate model?\" \/>\n<meta property=\"og:description\" content=\"Staying current requires agile development practices that continuously integrate and deliver high-quality software with reduced risk.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/one.sightlinemg.com\/defensenews\/opinion\/2024\/06\/28\/how-achievable-is-the-continuous-authority-to-operate-model\/\" \/>\n<meta property=\"og:site_name\" content=\"Defense News\" \/>\n<meta property=\"article:published_time\" content=\"2024-06-28T20:37:28+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-08T18:48:07+00:00\" \/>\n<meta name=\"author\" content=\"Bryon Kroger\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Bryon Kroger\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\n\t    \"@context\": \"https:\\\/\\\/schema.org\",\n\t    \"@graph\": [\n\t        {\n\t            \"@type\": \"Article\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/opinion\\\/2024\\\/06\\\/28\\\/how-achievable-is-the-continuous-authority-to-operate-model\\\/#article\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/opinion\\\/2024\\\/06\\\/28\\\/how-achievable-is-the-continuous-authority-to-operate-model\\\/\"\n\t            },\n\t            \"author\": {\n\t                \"name\": \"migration\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\"\n\t            },\n\t            \"headline\": \"How achievable is the continuous Authority to Operate model?\",\n\t            \"datePublished\": \"2024-06-28T20:37:28+00:00\",\n\t            \"dateModified\": \"2026-08-08T18:48:07+00:00\",\n\t            \"mainEntityOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/opinion\\\/2024\\\/06\\\/28\\\/how-achievable-is-the-continuous-authority-to-operate-model\\\/\"\n\t            },\n\t            \"wordCount\": 963,\n\t            \"commentCount\": 0,\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/#organization\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/opinion\\\/2024\\\/06\\\/28\\\/how-achievable-is-the-continuous-authority-to-operate-model\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/499668.jpg.jpg\",\n\t            \"articleSection\": [\n\t                \"Home\",\n\t                \"Opinion\"\n\t            ],\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"CommentAction\",\n\t                    \"name\": \"Comment\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/opinion\\\/2024\\\/06\\\/28\\\/how-achievable-is-the-continuous-authority-to-operate-model\\\/#respond\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebPage\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/opinion\\\/2024\\\/06\\\/28\\\/how-achievable-is-the-continuous-authority-to-operate-model\\\/\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/opinion\\\/2024\\\/06\\\/28\\\/how-achievable-is-the-continuous-authority-to-operate-model\\\/\",\n\t            \"name\": \"How achievable is the continuous Authority to Operate model? - Defense News\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/#website\"\n\t            },\n\t            \"primaryImageOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/opinion\\\/2024\\\/06\\\/28\\\/how-achievable-is-the-continuous-authority-to-operate-model\\\/#primaryimage\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/opinion\\\/2024\\\/06\\\/28\\\/how-achievable-is-the-continuous-authority-to-operate-model\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/499668.jpg.jpg\",\n\t            \"datePublished\": \"2024-06-28T20:37:28+00:00\",\n\t            \"dateModified\": \"2026-08-08T18:48:07+00:00\",\n\t            \"description\": \"Staying current requires agile development practices that continuously integrate and deliver high-quality software with reduced risk.\",\n\t            \"breadcrumb\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/opinion\\\/2024\\\/06\\\/28\\\/how-achievable-is-the-continuous-authority-to-operate-model\\\/#breadcrumb\"\n\t            },\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"ReadAction\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/opinion\\\/2024\\\/06\\\/28\\\/how-achievable-is-the-continuous-authority-to-operate-model\\\/\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"ImageObject\",\n\t            \"inLanguage\": \"en-US\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/opinion\\\/2024\\\/06\\\/28\\\/how-achievable-is-the-continuous-authority-to-operate-model\\\/#primaryimage\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/499668.jpg.jpg\",\n\t            \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/499668.jpg.jpg\"\n\t        },\n\t        {\n\t            \"@type\": \"BreadcrumbList\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/opinion\\\/2024\\\/06\\\/28\\\/how-achievable-is-the-continuous-authority-to-operate-model\\\/#breadcrumb\",\n\t            \"itemListElement\": [\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 1,\n\t                    \"name\": \"Home\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/\",\n\t                    \"ad_zone\": \"home\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 2,\n\t                    \"name\": \"Opinion\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/opinion\\\/\",\n\t                    \"ad_zone\": \"opinion\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 3,\n\t                    \"name\": \"How achievable is the continuous Authority to Operate model?\"\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebSite\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/#website\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/\",\n\t            \"name\": \"Defense News\",\n\t            \"description\": \"Covering the politics, business and technology of defense | Defense News\",\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/#organization\"\n\t            },\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"SearchAction\",\n\t                    \"target\": {\n\t                        \"@type\": \"EntryPoint\",\n\t                        \"urlTemplate\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/?s={search_term_string}\"\n\t                    },\n\t                    \"query-input\": {\n\t                        \"@type\": \"PropertyValueSpecification\",\n\t                        \"valueRequired\": true,\n\t                        \"valueName\": \"search_term_string\"\n\t                    }\n\t                }\n\t            ],\n\t            \"inLanguage\": \"en-US\"\n\t        },\n\t        {\n\t            \"@type\": \"Organization\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/#organization\",\n\t            \"name\": \"Defense News\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/\",\n\t            \"logo\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/#\\\/schema\\\/logo\\\/image\\\/\",\n\t                \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/defensenews-logo-white.png\",\n\t                \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/defensenews-logo-white.png\",\n\t                \"caption\": \"Defense News\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/#\\\/schema\\\/logo\\\/image\\\/\"\n\t            }\n\t        },\n\t        {\n\t            \"@type\": \"Person\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\",\n\t            \"name\": \"migration\",\n\t            \"image\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec\",\n\t                \"url\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"contentUrl\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"caption\": \"migration\"\n\t            },\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/defensenews\\\/author\\\/migration\\\/\"\n\t        }\n\t    ]\n\t}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"How achievable is the continuous Authority to Operate model? - Defense News","description":"Staying current requires agile development practices that continuously integrate and deliver high-quality software with reduced risk.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/2024\/06\/28\/how-achievable-is-the-continuous-authority-to-operate-model\/","og_locale":"en_US","og_type":"article","og_title":"How achievable is the continuous Authority to Operate model?","og_description":"Staying current requires agile development practices that continuously integrate and deliver high-quality software with reduced risk.","og_url":"https:\/\/one.sightlinemg.com\/defensenews\/opinion\/2024\/06\/28\/how-achievable-is-the-continuous-authority-to-operate-model\/","og_site_name":"Defense News","article_published_time":"2024-06-28T20:37:28+00:00","article_modified_time":"2026-08-08T18:48:07+00:00","author":"Bryon Kroger","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Bryon Kroger","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/one.sightlinemg.com\/defensenews\/opinion\/2024\/06\/28\/how-achievable-is-the-continuous-authority-to-operate-model\/#article","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/defensenews\/opinion\/2024\/06\/28\/how-achievable-is-the-continuous-authority-to-operate-model\/"},"author":{"name":"migration","@id":"https:\/\/one.sightlinemg.com\/defensenews\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1"},"headline":"How achievable is the continuous Authority to Operate model?","datePublished":"2024-06-28T20:37:28+00:00","dateModified":"2026-08-08T18:48:07+00:00","mainEntityOfPage":{"@id":"https:\/\/one.sightlinemg.com\/defensenews\/opinion\/2024\/06\/28\/how-achievable-is-the-continuous-authority-to-operate-model\/"},"wordCount":963,"commentCount":0,"publisher":{"@id":"https:\/\/one.sightlinemg.com\/defensenews\/#organization"},"image":{"@id":"https:\/\/one.sightlinemg.com\/defensenews\/opinion\/2024\/06\/28\/how-achievable-is-the-continuous-authority-to-operate-model\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/499668.jpg.jpg","articleSection":["Home","Opinion"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/one.sightlinemg.com\/defensenews\/opinion\/2024\/06\/28\/how-achievable-is-the-continuous-authority-to-operate-model\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/one.sightlinemg.com\/defensenews\/opinion\/2024\/06\/28\/how-achievable-is-the-continuous-authority-to-operate-model\/","url":"https:\/\/one.sightlinemg.com\/defensenews\/opinion\/2024\/06\/28\/how-achievable-is-the-continuous-authority-to-operate-model\/","name":"How achievable is the continuous Authority to Operate model? - Defense News","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/defensenews\/#website"},"primaryImageOfPage":{"@id":"https:\/\/one.sightlinemg.com\/defensenews\/opinion\/2024\/06\/28\/how-achievable-is-the-continuous-authority-to-operate-model\/#primaryimage"},"image":{"@id":"https:\/\/one.sightlinemg.com\/defensenews\/opinion\/2024\/06\/28\/how-achievable-is-the-continuous-authority-to-operate-model\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/499668.jpg.jpg","datePublished":"2024-06-28T20:37:28+00:00","dateModified":"2026-08-08T18:48:07+00:00","description":"Staying current requires agile development practices that continuously integrate and deliver high-quality software with reduced risk.","breadcrumb":{"@id":"https:\/\/one.sightlinemg.com\/defensenews\/opinion\/2024\/06\/28\/how-achievable-is-the-continuous-authority-to-operate-model\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/one.sightlinemg.com\/defensenews\/opinion\/2024\/06\/28\/how-achievable-is-the-continuous-authority-to-operate-model\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/defensenews\/opinion\/2024\/06\/28\/how-achievable-is-the-continuous-authority-to-operate-model\/#primaryimage","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/499668.jpg.jpg","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/499668.jpg.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/one.sightlinemg.com\/defensenews\/opinion\/2024\/06\/28\/how-achievable-is-the-continuous-authority-to-operate-model\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/one.sightlinemg.com\/defensenews\/","ad_zone":"home"},{"@type":"ListItem","position":2,"name":"Opinion","item":"https:\/\/one.sightlinemg.com\/defensenews\/opinion\/","ad_zone":"opinion"},{"@type":"ListItem","position":3,"name":"How achievable is the continuous Authority to Operate model?"}]},{"@type":"WebSite","@id":"https:\/\/one.sightlinemg.com\/defensenews\/#website","url":"https:\/\/one.sightlinemg.com\/defensenews\/","name":"Defense News","description":"Covering the politics, business and technology of defense | Defense News","publisher":{"@id":"https:\/\/one.sightlinemg.com\/defensenews\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/one.sightlinemg.com\/defensenews\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/one.sightlinemg.com\/defensenews\/#organization","name":"Defense News","url":"https:\/\/one.sightlinemg.com\/defensenews\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/defensenews\/#\/schema\/logo\/image\/","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/defensenews-logo-white.png","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/defensenews-logo-white.png","caption":"Defense News"},"image":{"@id":"https:\/\/one.sightlinemg.com\/defensenews\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/one.sightlinemg.com\/defensenews\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1","name":"migration","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec","url":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","caption":"migration"},"url":"https:\/\/one.sightlinemg.com\/defensenews\/author\/migration\/"}]}},"jetpack_featured_media_url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/499668.jpg.jpg","jetpack_sharing_enabled":true,"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"Defense News","distributor_original_site_url":"https:\/\/one.sightlinemg.com\/defensenews","push-errors":false,"_links":{"self":[{"href":"https:\/\/one.sightlinemg.com\/defensenews\/wp-json\/wp\/v2\/posts\/50173","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/one.sightlinemg.com\/defensenews\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/one.sightlinemg.com\/defensenews\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/defensenews\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/defensenews\/wp-json\/wp\/v2\/comments?post=50173"}],"version-history":[{"count":1,"href":"https:\/\/one.sightlinemg.com\/defensenews\/wp-json\/wp\/v2\/posts\/50173\/revisions"}],"predecessor-version":[{"id":50176,"href":"https:\/\/one.sightlinemg.com\/defensenews\/wp-json\/wp\/v2\/posts\/50173\/revisions\/50176"}],"wp:attachment":[{"href":"https:\/\/one.sightlinemg.com\/defensenews\/wp-json\/wp\/v2\/media?parent=50173"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/defensenews\/wp-json\/wp\/v2\/categories?post=50173"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/defensenews\/wp-json\/wp\/v2\/tags?post=50173"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/defensenews\/wp-json\/wp\/v2\/coauthors?post=50173"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}