Authority to Operate (ATO)
What is Authority to Operate (ATO)?
A formal authorisation granted by a senior official to operate a federal information system at an acceptable level of risk. ATO is required under FISMA and FedRAMP and is based on the assessment of security controls.
Frameworks that govern authority to operate (ato)
What the standards actually require on authority to operate (ato)
Requirements naming authority to operate (ato) across 2 standards, quoted from the control text.
FedRAMP was established in 2011 by OMB Memorandum M-11-30 + implementing FISMA for cloud services used by US federal agencies. The FedRAMP Program Management Office (PMO) is housed within the General Services Administration (GSA).
FedRAMP-Program · FedRAMP Program establishment, PMO and authorization paths →Conduct Certification and Accreditation (C&A) per NZISM Chapter 4 covering: system categorisation per classification level + security control selection + security control implementation + Security Risk Management Plan + Certification by independent IRAP-equiva...
NZISM-2 · Certification and Accreditation (C&A) for Government Systems →Questions people ask about authority to operate (ato)
What is Authority to Operate (ATO)?
Why is Authority to Operate (ATO) important for compliance?
Which compliance frameworks address Authority to Operate (ATO)?
Where can I learn more about Authority to Operate (ATO)?
See how Authority to Operate (ATO) applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.