Episode

Streamlining the ATO Process Makes Software Deployments More Efficient, Secure | CyberCast

Podcast
GovCIO Media & Research Podcasts
Published
Sep 8, 2026
Duration seconds
370
Processing state
not_requested
Canonical source
https://govciomedia.com/podcasts/
Audio
https://traffic.libsyn.com/secure/governmentcio-media-govcast/CyberCast_Victoria_Yan_Pillitteri_audio.mp3?dest-id=785468
JSON
/v1/public/podcasts/govcio-media-research-podcasts-236090/episodes/streamlining-the-ato-process-makes-software-deployments-more-efficient-secure-cybercast
Markdown
/podcast/govcio-media-research-podcasts-236090/streamlining-the-ato-process-makes-software-deployments-more-efficient-secure-cybercast.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/govcio-media-research-podcasts-236090/episodes/streamlining-the-ato-process-makes-software-deployments-more-efficient-secure-cybercast/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/govcio-media-research-podcasts-236090/streamlining-the-ato-process-makes-software-deployments-more-efficient-secure-cybercast.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Federal agencies can make the authorization to operate (ATO) process more efficient by treating security as an ongoing part of software development rather than a checklist to complete before deployment, according to Victoria Yan Pillitteri, cybersecurity lead at the National Institute of Standards and Technology. Speaking with GovCIO Media & Research at the Carahsoft DevSecOps Conference, Pillitteri outlined common misconceptions that can slow the ATO process, including treating authorization as a one-time compliance exercise or simply a hurdle to clear for approval. Pillitteri explained how NIST guidance gives agencies flexibility to tailor the ATO process to their specific missions, systems and risk tolerances rather than taking a one-size-fits-all approach. She also discusses how clearly defining roles and responsibilities, strengthening risk management practices and building security into software development from the beginning can help agencies streamline authorization while deploying software more efficiently and securely.