Overview
The Authority to Operate (ATO) process allows the CWMS software to continue to operate on G6 infrastructure. Without an ATO, the servers would be shut off and district offices would have to find alternate ways to complete their water management mission. The ATO is a continuous process, with a large formal review occurring every three years by a Security Control Assessor-Validator (SCA-V) team. The CWMS team regularly tracks changes to Security Technical Implementation Guidance (STIG) from the Defense Information Systems Agency (DISA) and verifies that CWMS software is operating and developed in a secure and reasonable fashion.
Accomplishments
The team completed work for the ATO renewal, including:
- Updated STIG checklists
- Updated eMass record
- Updated information on relevant Plan of Action and Milestones (POA&Ms)
- Implemented RMI/TLS to meet security objectives
- Created code backup plan
The SCA-V review was completed successfully because of these actions. But due to issues between CIO/G6 and NetComm, the ATO was not renewed by the August 2023 deadline. An extension was granted until 2025 to complete the ATO process.