18F Thinks Security Authorizations Should Be Agile Too

NextGov: It’s said business eats cybersecurity for breakfast. But when it comes to agile development, security is integral to the process, and that means security has to be agile, as well.

Federal agencies have been embracing a shift to agile development methodologies—releasing projects in stages to get user feedback and rectify bugs early in the process and continuing to iterate and improve over time. But security is often a far less agile process, particularly when it comes to getting an authority to operate, or ATO—an arduous process that can stall deployment of even small-scale systems.

Read article