Show pageOld revisionsBacklinksAdd to bookExport to PDFODT exportBack to top This page is read only. You can view the source, but not change it. Ask your administrator if you think this is wrong. ====== Authorization to Operate (ATO) ====== [[dido:99_annexes:annex-b-terms-and-definitions:start|Go up to Terms and Definitions]] ===== Discussion ===== An Authorization to Operate (ATO) records a risk-based management decision by an [[dido:99_annexes:annex-b-terms-and-definitions:a:authorizing_authority|Authorizing Authority]] to permit a system to operate within a defined [[dido:99_annexes:annex-b-terms-and-definitions:a:accreditation_boundary|Accreditation Boundary]], operational environment, scope, and period. The Authorizing Authority bases the decision on the system’s security and privacy posture, assessment results, identified risks, implemented controls, mission or business requirements, and supporting [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]]. An ATO explicitly assigns responsibility for accepting the residual risk associated with operating the system. The authorization may include conditions, limitations, monitoring obligations, expiration criteria, or requirements for corrective action. Crucible does not issue an ATO. Crucible produces controlled artifacts, assessment results, [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]], [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]], and compliance evidence that may support an Authorizing Authority’s decision. ===== Definition ===== //risk-based management decision by an authorizing authority that permits operation of a system within a defined scope and explicitly accepts the associated residual risk// ===== Source ===== Adapted from the National Institute of Standards and Technology Risk Management Framework and NIST Special Publication 800-37 Revision 2. ===== Note ===== An ATO applies only to the system, authorization boundary, operating conditions, environment, and period identified by the authorization decision. An ATO does not establish that the system is free from risk. It establishes that the responsible Authorizing Authority accepts the identified residual risk under the stated conditions. An ATO differs from [[dido:99_annexes:annex-b-terms-and-definitions:a:accreditation|Accreditation]]. Accreditation formally recognizes that an organization, process, facility, or capability satisfies defined criteria, while an ATO permits a specified system to operate based on an explicit risk decision. ===== Example ===== An Authorizing Authority reviews the security assessment report, compliance findings, remediation status, system security plan, risk assessment, and supporting evidence for a deployed Crucible environment. The Authorizing Authority issues an ATO that permits the environment to operate for a defined period subject to continuous monitoring and specified corrective actions. ---- <WRAP centeralign> © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc. </WRAP> dido/99_annexes/annex-b-terms-and-definitions/a/ato.txt Last modified: 2026/07/18 12:33by 127.0.0.1