Lucky - a couple of questions re ATO vs. JAB approval. You said ATO is specific to only 1 agency. I thought an ATO could still be used by another agency w/modifications to their specific needs; is that not true? For ex. HUD could ATO say SaaS prod A, but the HHS could acquire the ATO and tweak it for their needs? Am I wrong? If 2 separate agencies want to use the same product - then the JAB provisional approval route must be followed?
Jackie, every Agency that leverage a cloud service provider JAB P-ATO must maintain an Agency ATO which demonstrates the Agency's acceptance of risk regarding the use of a particular cloud service provider. The Agency ATO cannot be leveraged by a different Agency due to the difference in the risk Appetite of each Agency. Each Agency must maintain it's separate Agency ATO.
Very helpful thanks 🙏
Lucky - a couple of questions re ATO vs. JAB approval. You said ATO is specific to only 1 agency. I thought an ATO could still be used by another agency w/modifications to their specific needs; is that not true?
For ex. HUD could ATO say SaaS prod A, but the HHS could acquire the ATO and tweak it for their needs? Am I wrong?
If 2 separate agencies want to use the same product - then the JAB provisional approval route must be followed?
Jackie, every Agency that leverage a cloud service provider JAB P-ATO must maintain an Agency ATO which demonstrates the Agency's acceptance of risk regarding the use of a particular cloud service provider. The Agency ATO cannot be leveraged by a different Agency due to the difference in the risk Appetite of each Agency. Each Agency must maintain it's separate Agency ATO.