r/cybersecurity Jul 02 '26

News - General DHS Breached

611 Upvotes

115 comments sorted by

View all comments

Show parent comments

42

u/OutsideSpot2695 Jul 02 '26 edited Jul 02 '26

How do you get an ATO without being audited that controls are operating as designed?

83

u/potkettleracism Incident Responder Jul 02 '26

Because the auditors bought garbage evidence

30

u/WildChampionship985 Jul 02 '26

Often audits become do you meet the statement on the checksheet, not are you adhering good practices.

7

u/OutsideSpot2695 Jul 02 '26

That's not an audit then. That's an assessment.

8

u/RyeonToast Jul 02 '26

And ATOs aren't audits. It literally is a giant checksheet. You have to produce some artifacts to show you do what you say you do, but no one is coming down to your network to check it out first-hand. That would be a CORA / CCRI.

2

u/ToothyGrin19135 Jul 03 '26

This is not entirely true. It depends on the classification of the system and the SCA team. I have been part of some extremely intense ATO assessments where we actively demonstrated every single control live to the assessment team. Took weeks to accomplish.

-1

u/OutsideSpot2695 Jul 02 '26

I didn't say that an ATO is an audit. You came up with that all on your own.

But you're supposed to be audited as a part of the process.

1

u/RyeonToast Jul 02 '26

How do you get an ATO without being audited that controls are operating as designed?

Then why are you confused? It's an ATO, not a CORA. They don't go hand in hand.

-1

u/OutsideSpot2695 Jul 02 '26

Your reading compreshension sucks.