top of page
Appendix A - ATO Readiness Task List
Phase | ID | Task | Min Weeks | Max Weeks |
|---|---|---|---|---|
Security Control Baseline Selection | BASE-1 | Determine Applicable Authorization Regime (RMF, FedRAMP, or CMMC) | 0.2 | 0.6 |
Security Control Baseline Selection | BASE-2 | Define Preliminary Authorization Boundary | 0.4 | 1 |
Security Control Baseline Selection | BASE-3 | Select Applicable Security Controls | 0.6 | 1 |
Container Hardening | CONT-1 | Containerize Custom Software Using Hardened Base Container Images | 2 | 5 |
Container Hardening | CONT-2 | Implement Application Security and Development (ASD) STIG Requirements for Containers | 2 | 3 |
Container Hardening | CONT-3 | Implement Container Security Requirements Guide (SRG) | 0.6 | 1 |
Container Hardening | CONT-4 | Remediate Container Vulnerabilities Identified by Static Scanning | 0.6 | 2 |
Container Hardening | CONT-5 | Address Runtime Security Findings | 0.6 | 2 |
Container Hardening | CONT-6 | Address Policy Enforcement Findings | 0.2 | 1 |
DevSecOps Platform Setup | PLAT-1 | Set Up Internal DevSecOps Platform | 2 | 4 |
DevSecOps Platform Setup | PLAT-2 | Package and Deploy Custom Software to Internal DevSecOps Platform | 1 | 4 |
DevSecOps Platform Setup | PLAT-3 | Integrate Custom Software with Platform-Provided Services | 1.4 | 2.4 |
DevSecOps Baseline Evidence Automation | EVID-1 | Implement Automated Container Build and Deployment Pipeline | 1 | 1.4 |
DevSecOps Baseline Evidence Automation | EVID-2 | Integrate Automated SBOM Generation in the Pipeline | 1.4 | 2.2 |
DevSecOps Baseline Evidence Automation | EVID-3 | Integrate Automated Vulnerability Scanning in the Pipeline | 0.6 | 2 |
DevSecOps Baseline Evidence Automation | EVID-4 | Integrate Automated OpenSCAP Container Scanning in the Pipeline | 0.6 | 1 |
DevSecOps Baseline Evidence Automation | EVID-5 | Leverage OSCAL/Compliance-as-Code for Control Tracking | 0.6 | 1 |
DevSecOps Baseline Evidence Automation | EVID-6 | Refine Application Audit Logging | 0.6 | 1.4 |
DevSecOps Extra Supporting Automation | ESA-1 | Implement Container Image Signing | 0.2 | 0.6 |
DevSecOps Extra Supporting Automation | ESA-2 | Implement Anti-Virus Scanning with ClamAV | 0.4 | 1 |
DevSecOps Extra Supporting Automation | ESA-3 | Integrate Static Application Security and Secret Scanning | 1 | 3 |
DevSecOps Extra Supporting Automation | ESA-4 | Integrate Automated Test Coverage | 0.6 | 1.4 |
DevSecOps Extra Supporting Automation | ESA-5 | Implement Fuzz Testing | 0.6 | 1.4 |
Preliminary ATO Documentation Generation | GEN-1 | Determine Final Authorization Boundary | 0.4 | 0.6 |
Preliminary ATO Documentation Generation | GEN-2 | Create Custom Software Architecture Diagrams | 0.4 | 1.2 |
Preliminary ATO Documentation Generation | GEN-3 | Create Ports, Protocols, Services Documentation | 0.2 | 0.8 |
Preliminary ATO Documentation Generation | GEN-4 | Create Security Control Compliance Narratives | 0.8 | 1.6 |
Preliminary ATO Documentation Generation | GEN-5 | Create System Security Plan | 1.5 | 3 |
Preliminary ATO Documentation Generation | GEN-6 | Create SRG/STIG Compliance Documentation | 1 | 3 |
Preliminary ATO Documentation Generation | GEN-7 | Create Continuous Monitoring Plan Documentation | 0.4 | 0.6 |
Preliminary ATO Documentation Generation | GEN-8 | Create Plan of Actions & Milestones | 1.5 | 4 |
Preliminary ATO Documentation Generation | GEN-9 | Create Privacy Documents | 0.4 | 0.8 |
Preliminary ATO Documentation Generation | GEN-10 | Create Threat Model Documentation | 0.6 | 1 |
Preliminary ATO Documentation Generation | GEN-11 | Create User Account and Identity Documentation | 0.4 | 1 |
Preliminary ATO Documentation Generation | GEN-12 | Create Operator Setup and Configuration Security Guide | 0.6 | 2 |
Preliminary ATO Documentation Generation | GEN-13 | Compile Initial ATO Package | 0.2 | 1 |
bottom of page