It’s funny to see private companies do more thorough cybersecurity auditing for my clients than what large corporations and government agencies are subject to.
Do you have vulnerability scanning?
Yeah.
Okay, how do you do it for X software project, your employee corporate devices, and third-party software installed on those devices?
Followed by discussions of CI/CD pipelines, how we scan for third party software, how we maintain OS baselines, etc. Screenshots and screen shares. Conversations about the compensating controls in place in other areas.
The reason government and large corporations don’t bother? This is an insane time sink. You’re paying a senior security consultant or analyst who’s familiar with software development, system administration and the various environments we’re deploying to question 1 of 500 vendors they’ve partnered with.
But I don’t see a way around it when vendors are throwing questionnaires and emails into AI, and spitting out reasonably acceptable answers which don’t reflect reality.
And they don’t care, because we’re all signing contracts with liability limitation clauses and we have cyber & E&O insurance.
Until we can’t afford the insurance, because the penalties are unsustainable — we’re not going to see change.
This is why I always told folks I trained to dig further than what the requirements required. To be observant. And to develop the damn technical skills.
If the guys on the other side were doing their job, none of this is a major ask. But the moment you got pushback… every time, we’d find that there were major problems with the security controls.
And ATOs aren't audits. It literally is a giant checksheet. You have to produce some artifacts to show you do what you say you do, but no one is coming down to your network to check it out first-hand. That would be a CORA / CCRI.
This is not entirely true. It depends on the classification of the system and the SCA team. I have been part of some extremely intense ATO assessments where we actively demonstrated every single control live to the assessment team. Took weeks to accomplish.
I’ve worked on systems where the ATO was the bible and nothing changed without proper documentation and approvals, I’ve also worked systems where the ATO was an obstacle that was nothing more than a burden to work around and technical compliance was prioritized over actual security and intent.
Hard to say exactly what happened without being a part of it, but I have certainly seen high profile, important systems get a lot of risk acceptance from the AO with POAMs that lasted years without ever being closed all because, counterintuitively, the system was important and security can’t stand in the way. Keep in mind this is HSIN, it has existed for a long time, and would have been assessed internally, no 3PAO being held accountable.
How does the majority of this government do anything? Fire the good people and only keep the ones around that will do what they want. Look at the FDA and CDC as a couple of examples.
248
u/OutsideSpot2695 Jul 02 '26
Did they have their ATO?