In our ongoing series exploring the Department of Defense’s Continuous Authorization to Operate (cATO) model, we now turn our attention to two critical components: the Secure Software Supply Chain (SSSC) and DevSecOps practices. These elements form the backbone of a robust cATO implementation, ensuring both security and agility in software development and deployment.
Continuous Authorization to Operate (cATO) is changing the way organizations approach cybersecurity and compliance in dynamic IT environments. By embedding security directly into development and operational workflows, cATO enables real-time assessment, assurance, and authorization, promoting agility without compromising security. An environment with effective personnel and processes is critical to achieving the intended goals and objectives of a cATO.
As software systems grow increasingly complex and interdependent, static and periodic compliance assessments fall short of ensuring security. Threats evolve faster than traditional systems and accreditation processes can adapt, creating vulnerabilities or weaknesses in the software supply chain and operational lifecycle.
The cATO approach addresses these challenges by shifting from static, point-in-time approvals to a dynamic, continuous assessment and authorization model. This shift requires integrating SSSC and DevSecOps as critical enablers of security, resilience, and agility.
The software supply chain encompasses all components, dependencies, and processes involved in developing, deploying, and maintaining software applications. A compromised supply chain can lead to breaches that affect downstream systems, organizations, and even national security, as seen in incidents like the SolarWinds attack (SolarWinds, 2021) and XY/libzma.
Key principles for securing the software supply chain include:
[1] https://github.com/tukaani-project/xz/commit/e93e13c8b3bec925c56e0c0b675d8000a0f7f754
DevSecOps integrates security into every stage of the software development lifecycle (SDLC), fostering a culture of “secure by design.” By automating security practices and embedding them into CI/CD pipelines, DevSecOps enables organizations to meet cATO requirements effectively.
Key DevSecOps practices include:
The intersection of SSSC and DevSecOps represents the synergy required for achieving cATO competency. Here’s how organizations can align these practices to enable secure, compliant, and resilient IT systems:
When organizations integrate SSSC and DevSecOps into their cATO strategies, they unlock several benefits:
As organizations navigate increasingly complex cybersecurity landscapes, the adoption of cATO frameworks, supported by secure software supply chains and DevSecOps practices, is no longer optional—it’s essential. By embedding security into every layer of development and operations, organizations can achieve continuous assurance and resilience while staying compliant with evolving regulations.
With the right combination of people, processes, and technologies, cATO empowers organizations to innovate securely, keeping pace with the demands of modern IT ecosystems.
References
In our previous posts, we introduced the foundations of cATO and explored the pivotal role of Continuous Monitoring (ConMon) in keeping federal systems secure and compliant. Now, we’re focusing on another crucial element of cATO: Active Cyber Defense (ACD). ACD is a proactive strategy designed to help agencies like the Department of Defense (DoD) and the Army combat increasingly sophisticated cyber threats.
If you’re in the federal or defense world, you know the importance of an Authorization to Operate (ATO). It’s essentially a green light for systems to run, confirming they meet required security standards. However, the traditional ATO process is slow and rigid. You might secure approval today, but your system could face new vulnerabilities six months later. This is where cATO comes in.
cATO ensures systems maintain continuous compliance, allowing for faster deployment of technologies without sacrificing security. Unlike traditional ATOs, cATO emphasizes real-time risk assessments, continuous monitoring, and adaptive security measures, aligning with agile development practices.
ACD is a critical requirement for achieving and maintaining cATO for the DoD and its components. To qualify, organizations must demonstrate three key competencies:
Think of ACD as moving from a “set it and forget it” strategy to one that is proactive, adaptive, and predictive. It’s not just about deploying tools—it’s about staying vigilant, hunting for threats, and even countering adversaries when necessary.
ACD aligns with cATO’s focus on continuous compliance. By adopting strategies outlined in NIST SP 800-53 and leveraging methodologies like the MITRE ATT&CK Framework, agencies can build robust defenses tailored to their mission requirements and threat landscapes.
ACD relies on actionable intelligence to predict, identify, and counteract threats. To effectively implement the ACD pillar of cATO, several key components must be put in place.
Let’s break it down:
1. Threat Intelligence and Analysis
2. Automated Threat Response: When a threat is detected, speed is key. This involves having robust mechanisms for detecting and mitigating threats as they emerge rather than relying on periodic scans or updates. The DoD memo on cATO emphasizes that “systems must be able to show a real, or near real-time ability to deploy appropriate countermeasures to thwart cyber adversaries” 1,2.
3. Hunt Teams and Incident Response: Automation doesn’t replace the need for skilled personnel. Hunt teams are the boots on the ground, proactively looking for signs of malicious activity and taking action to stop it. They analyze threat data, assess risks, and respond to incidents, guided by the latest intelligence. Agencies can quickly contain and recover from breaches with a well-defined incident response plan.
4. Deception Technology: Deception technology is a fascinating piece of the ACD puzzle. It creates decoys or traps within the network, drawing attackers away from real assets. By luring attackers into a controlled environment, agencies can gather intelligence on their tactics and buy themselves extra time to respond.
5. Continuous Monitoring and Real-Time Analytics: ACD must be integrated with the Continuous Monitoring (ConMon) pillar of cATO. This integration ensures that security data collected from various environments (development, test, and production) is used to inform and power active incident response. The flow of information between these systems is crucial for making real-time risk decisions and responding to threats efficiently.

A recent SIGNAL media article by Evan Lynch highlights the U.S. Army’s implementation of the cATO framework, marking a significant shift in how the Army monitors and addresses cybersecurity risks. This initiative aligns closely with the principles of ACD we’ve been discussing and offers valuable insights for organizations implementing ACD and working towards cATO.
Key aspects of the Army’s cATO framework include:
The Army is leading by example with its adoption of cATO. Two of the key systems under this initiative include:
Leonel Garciga, the Army CIO, states this development marks a major shift in how Army officials monitor and address threats. He explained, “It’s really about understanding the risk of the software you’re delivering as opposed to our more compliance-based culture that we have today… We’re really focused on the threat-based understanding of what the environment looks like and making decisions on software we’re building based on the risks that we’re creating with that software.” 4
To earn and maintain cATO, organizations need to demonstrate they can handle threats as they emerge—not just during a biannual review.
We’re excited about the potential of Active Cyber Defense in cATO. ACD is an essential capability for achieving and maintaining cATO. It’s the linchpin of a security strategy that’s as dynamic as the threats it faces. The DoD is actively putting these principles into action, demonstrating that the concepts of ACD and cATO are not just theoretical but are actively being implemented at the highest levels of defense.
We see it as a game-changer for our clients to effectively integrate cutting-edge threat intelligence, advanced virtualization technologies, automated orchestration tools, and cloud-based security solutions within DevSecOps platforms. All of these come together to create a robust, dynamic defense system that’s always on, always learning, and always one step ahead of the bad guys.
If you’re interested in learning more about Continuous Authorization to Operate (cATO) and how to implement it effectively for your organization, contact BreakPoint Labs. Our team of experts can guide you through the process and help you develop a robust cybersecurity strategy tailored to your specific needs.
References
1 GovCIO Media & Research. (2022, February 4). DOD Releases New Continuous ATO Initiative for ‘Active’ Cybersecurity. https://govciomedia.com/dod-releases-new-continuous-ato-initiative-for-active-cybersecurity/
2 U.S. Department of Defense. (2022, February 3). Continuous Authorization To Operate (cATO). https://media.defense.gov/2022/Feb/03/2002932852/-1/-1/0/CONTINUOUS-AUTHORIZATION-TO-OPERATE.PDF
3 FedTech Magazine. (2022, September 9). ATO to cATO Cybersecurity Transition in The Federal Government. https://fedtechmagazine.com/article/2022/09/understanding-transition-authorization-operate-continuous-ato-perfcon
4. Lynch, E. (2024, May 28). U.S. Army Officials Launch New Way to Constantly Monitor Risks. SIGNAL Media. https://www.afcea.org/signal-media/cyber-edge/us-army-officials-launch-new-way-constantly-monitor-risks
In an earlier post, we introduced Continuous Authorization to Operate (cATO), a framework that grants an organization’s systems or networks continuous authorization to assess whether they meet required security standards. In this part of our series on DoD cATO Evaluation Criteria, we discuss the critical role of Continuous Monitoring (ConMon), its integration with DevSecOps, and the challenges and best practices for its implementation.
ConMon lies at the heart of cATO, enabling real-time security monitoring rather than relying on periodic checks. Acting as a constant pulse check, ConMon identifies security risks as they arise, preventing issues from being discovered months later during an audit.
ConMon integrates seamlessly with existing security infrastructure, such as Security Information and Event Management (SIEM) systems, which aggregate and analyze security data, and Intrusion Detection/Prevention Systems (IDS/IPS), which monitor and prevent unauthorized access. By leveraging these tools, ConMon automates real-time security event responses, minimizing manual intervention. This proactive approach is critical for Components navigating an ever-evolving cyber threat landscape, and an essential element of the shift toward cATO.
Traditionally, the Authority to Operate (ATO) process involved a one-time assessment conducted every few years. While effective at the time, it left vulnerabilities unaddressed between assessments. cATO changes this by enabling continuous compliance and security without requiring lengthy review pauses. ConMon feeds real-time data into dashboards, helping agencies spot and address risks immediately.

For DoD Components, ConMon isn’t just a nice-to-have—it’s an essential aspect of a robust cybersecurity strategy. Without it, organizations are effectively flying blind between assessments, leaving potential security issues undetected.
ConMon continuously monitors network traffic, identifies vulnerabilities, and tracks configuration changes, ensuring that risks are addressed in real-time. This continuous feedback loop is key to maintaining a cATO, where security is constantly proven rather than checked periodically. By automating monitoring and ensuring immediate detection of security issues, ConMon provides federal agencies with the confidence that their systems remain secure and compliant.
While ConMon offers significant advantages, its implementation within the DoD information network (DODIN) can come with its challenges. The complexity of legacy systems, many of which were not built for real-time monitoring, poses a significant hurdle. However, deploying agent-based monitoring solutions can help gather security metrics without major modifications to existing infrastructure. Additionally, containerization technologies and API gateways can enable older systems to communicate with modern monitoring frameworks like ConMon.
Beyond technical challenges, implementing ConMon requires a cultural shift with endorsement at management and technical leadership levels. Security practices need to be integrated into every phase of software development, fostering a mindset of continuous improvement and security vigilance. DoD Components should consider a phased adoption approach, starting with their most critical systems and expanding as teams become proficient in using ConMon tools and interpreting the data they provide.
Other regulated industries, such as finance and healthcare, provide excellent examples of how continuous monitoring has been successfully implemented to meet strict regulatory requirements, like PCI-DSS and HIPAA. Banks, for instance, use real-time monitoring tools to detect and flag suspicious transactions, catching fraud as it happens. Similarly, healthcare providers leverage ConMon to secure patient data and Personally Identifiable Information (PII), proving that continuous monitoring not only improves security but also streamlines operations even in large, complex environments.
ConMon enables mission owners to respond to security threats as they arise, eliminating the need to wait for scheduled reviews. This real-time response minimizes downtime and keeps systems secure. A recent case study in the public sector demonstrated how ConMon reduced response times to cyber threats, potentially saving millions by automating vulnerability detection.
By automating many security tasks, ConMon reduces the need for manual assessments. This frees up resources for higher-priority initiatives and cuts costs associated with lengthy manual reviews.
ConMon helps mission owners detect security risks early, preventing them from escalating into more significant issues. This proactive approach ensures risks are understood and managed in accordance with the expectations of a DoD Authorizing Official (AO). It also supports continuous awareness and visibility into any security control deviations while reducing the risk of unauthorized access.
By integrating ConMon within cATO, agencies can maintain compliance without pausing operations for lengthy reviews. Instead, they stay secure, and risks are continuously understood and managed, all while keeping mission-critical systems running smoothly.
DevSecOps integrates security into every stage of the software development lifecycle, ensuring that applications are secure from development through deployment. One of the strengths of DevSecOps is its use of automated pipelines, where security checks are conducted continuously, allowing for faster development cycles while maintaining robust security standards.
Within the Continuous Integration/Continuous Deployment (CI/CD) pipeline, ConMon can be integrated to assess the security of code before it is deployed to production. By continuously scanning code repositories for vulnerabilities and ensuring that security checks are automated during the build process, ConMon ensures that new releases are secure from the outset.
ConMon complements this by providing real-time visibility into security risks throughout the DevSecOps pipeline. By combining these two approaches, mission owners can continuously monitor and secure their applications at every phase of the lifecycle, ensuring that security risks are immediately identified and addressed.
To implement ConMon successfully, DoD Components should start with – or leverage an existing – thorough assessment of their current IT infrastructure. By identifying mission relevant terrain – cyber (MRT-C) where real-time monitoring is critical, they can prioritize the systems that require ConMon integration. A phased roadmap for implementation, focusing on high-risk areas first, can provide a meaningful prioritization for the transition. Additionally, understanding how existing authorization boundaries are defined can be useful to scope transition efforts to a cATO. Finally, DoD Components should also invest in training teams to use ConMon tools effectively and interpret the data they provide.
Amid the constantly shifting cybersecurity landscape, older methods of periodic security reviews can’t keep up with the pace of modern threats. That’s where ConMon and cATO come in. Instead of waiting for audits, ConMon allows organizations to detect vulnerabilities and respond to risks in real-time, ensuring compliance and security are maintained without slowing down operations.
For many DoD Components, adopting cATO is no longer just a choice—it’s becoming the norm. It ensures systems stay secure and compliant without the constant need for manual security checks, allowing mission-critical operations to continue uninterrupted.
At BreakPoint Labs, we specialize in helping DoD mission owners navigate the complexities of ConMon and cATO. With our expertise, we can help organizations implement these essential cybersecurity frameworks seamlessly and effectively. Contact us today to strengthen your agency’s security posture and ensure continuous compliance.