diff --git a/.DS_Store b/.DS_Store deleted file mode 100644 index 0b5b10b..0000000 Binary files a/.DS_Store and /dev/null differ diff --git a/.jekyll-metadata b/.jekyll-metadata new file mode 100644 index 0000000..035aed3 Binary files /dev/null and b/.jekyll-metadata differ diff --git a/CNAME b/CNAME index 5a16f74..9ad4dc8 100644 --- a/CNAME +++ b/CNAME @@ -1 +1 @@ -atoasap.org \ No newline at end of file +openato.org diff --git a/_config.yml b/_config.yml index 15b3934..a40a908 100644 --- a/_config.yml +++ b/_config.yml @@ -1,4 +1,4 @@ -title: ATO ASAP +title: OpenATO description: # baseurl: /compliance-as-code # the subpath of your site, e.g. /blog # url: https://govthinktank.github.io/compliance-as-code/ # the base hostname & protocol for your site, e.g. http://example.com @@ -6,10 +6,10 @@ description: # GitHub information # This is used for adding an edit this page link to the footer github_info: - organization: ato-asap + organization: openato repository: website -url: "https://ato-asap.github.io" # the base hostname & protocol for your site +url: "https://openato.github.io" # the base hostname & protocol for your site plugins: - jekyll-sitemap - jekyll-redirect-from diff --git a/_data/.DS_Store b/_data/.DS_Store deleted file mode 100644 index 5008ddf..0000000 Binary files a/_data/.DS_Store and /dev/null differ diff --git a/_data/footer.yml b/_data/footer.yml index e7f4f11..3f033ad 100644 --- a/_data/footer.yml +++ b/_data/footer.yml @@ -32,7 +32,7 @@ links: footer big_footer_signup_form: false # Configuration for footer heading. (optional) -heading: ATO ASAP +heading: OpenATO # Configuration for agency logo(s) (shown side by side). # If the logo is external add external: true @@ -47,7 +47,7 @@ contact: # Comment out links you don't want to use (RSS is an example) social_links: - text: GitHub - href: https://github.com/ato-asap + href: https://github.com/OpenATO external: true type: github # - text: Facebook diff --git a/_data/header.yml b/_data/header.yml index 64077b3..0673bf0 100644 --- a/_data/header.yml +++ b/_data/header.yml @@ -22,8 +22,11 @@ type: extended-mega # If the logo is external add external: true # logo: # src: /assets/img/logos/logo.png -# alt: ATO ASAP +# alt: OpenATO # external: #true +logo: + src: /assets/img/logos/OpenATO.png + alt: OpenATO # this is a key into _data/navigation.yml primary: diff --git a/_guide/.DS_Store b/_guide/.DS_Store deleted file mode 100644 index 5008ddf..0000000 Binary files a/_guide/.DS_Store and /dev/null differ diff --git a/_guide/introduction.md b/_guide/introduction.md index 0f9eb71..896bf07 100644 --- a/_guide/introduction.md +++ b/_guide/introduction.md @@ -9,6 +9,6 @@ categories: --- -Welcome to the ATO ASAP Guide. +Welcome to the OpenATO Guide. -Our goal with this guide is to make it easy for everyone in government (public and private sector) to understand the authory to operate (ATO) process and how they can better address security as it pertains to their specific role. \ No newline at end of file +Our goal with this guide is to make it easy for everyone in government (public and private sector) to understand the authory to operate (ATO) process and how they can better address security as it pertains to their specific role. diff --git a/_includes/.DS_Store b/_includes/.DS_Store deleted file mode 100644 index 5008ddf..0000000 Binary files a/_includes/.DS_Store and /dev/null differ diff --git a/_layouts/.DS_Store b/_layouts/.DS_Store deleted file mode 100644 index 5008ddf..0000000 Binary files a/_layouts/.DS_Store and /dev/null differ diff --git a/_layouts/guide.html b/_layouts/guide.html index 64a3e20..6a79610 100644 --- a/_layouts/guide.html +++ b/_layouts/guide.html @@ -10,7 +10,7 @@
  1. - ATO ASAP Guide + OpenATO Guide
  2. @@ -36,4 +36,4 @@

    {{ page.title }}

    - \ No newline at end of file + diff --git a/_people/.DS_Store b/_people/.DS_Store deleted file mode 100644 index 5008ddf..0000000 Binary files a/_people/.DS_Store and /dev/null differ diff --git a/_people/fen-labalme.md b/_people/fen-labalme.md index 6ac110f..e8fe334 100644 --- a/_people/fen-labalme.md +++ b/_people/fen-labalme.md @@ -7,13 +7,12 @@ image: fen-labalme.jpg categories: - Security and compliance linkedin: https://www.linkedin.com/in/fenlabalme/ -twitter: https://twitter.com/openprivacy github: https://github.com/openprivacy -gitlab: +gitlab: https://gitlab.com/openprivacy drupal: speakerdeck: website: --- -Fen leads security and compliance for [CivicActions](https://civicactions.com). \ No newline at end of file +Fen leads security and compliance for [CivicActions](https://civicactions.com). diff --git a/_people/luke-fretwell.md b/_people/luke-fretwell.md deleted file mode 100644 index 82b994c..0000000 --- a/_people/luke-fretwell.md +++ /dev/null @@ -1,19 +0,0 @@ ---- -type: team -published: 1 -author: luke-fretwell -name: Luke Fretwell -image: luke-fretwell.png -categories: - - -linkedin: https://www.linkedin.com/in/lukefretwell/ -twitter: https://twitter.com/lukefretwell -github: https://github.com/lukefretwell -gitlab: -drupal: -speakerdeck: -website: - ---- - -Luke Fretwell is a team member of ATO ASAP. \ No newline at end of file diff --git a/_people/marlena-medford.md b/_people/marlena-medford.md deleted file mode 100644 index 2c67c67..0000000 --- a/_people/marlena-medford.md +++ /dev/null @@ -1,19 +0,0 @@ ---- -type: team -published: 1 -author: marlena-medford -name: Marlena Medford -image: marlena-medford.jpg -categories: - - Artificial intelligence -linkedin: https://www.linkedin.com/in/marlena-medford/ -twitter: https://twitter.com/marlenamedford -github: -gitlab: -drupal: -speakerdeck: -website: - ---- - -Marlena Medford is a team member of ATO ASAP. \ No newline at end of file diff --git a/_posts/.DS_Store b/_posts/.DS_Store deleted file mode 100644 index 5008ddf..0000000 Binary files a/_posts/.DS_Store and /dev/null differ diff --git a/_posts/2021-02-19-hello-world.md b/_posts/2021-02-19-hello-world.md index e539f53..075a669 100644 --- a/_posts/2021-02-19-hello-world.md +++ b/_posts/2021-02-19-hello-world.md @@ -2,16 +2,16 @@ layout: post title: "Hello world" date: 2021-02-19 08:00:00 -0800 -description: Welcome to ATO ASAP. +description: Welcome to OpenATO. author: fen-labalme categories: image: card-power.png --- -Stay tuned. We're just getting started. +Stay tuned. We're just getting started. In the meantime, take a look around: * [We're open.](/open) * [Join us](/join) -* [News](/news) \ No newline at end of file +* [News](/news) diff --git a/_posts/2021-02-29-fcw-ato-asap-lets-finally-fix-the-security compliance problem.md b/_posts/2021-02-29-fcw-ato-asap-lets-finally-fix-the-security compliance problem.md index c6e9a35..f50cb70 100644 --- a/_posts/2021-02-29-fcw-ato-asap-lets-finally-fix-the-security compliance problem.md +++ b/_posts/2021-02-29-fcw-ato-asap-lets-finally-fix-the-security compliance problem.md @@ -14,4 +14,4 @@ From the post: > If we collaborate and take deliberate steps to integrate automation, we can unlock the bureaucratic inertia that has stalled compliance modernization and fix the ATO problem once and for all. -Full post: [ATO ASAP: Let’s finally fix the security compliance problem](https://fcw.com/articles/2021/02/04/comment-lazzeri-automate-ato.aspx) \ No newline at end of file +Full post: [ATO ASAP: Let’s finally fix the security compliance problem](https://www.nextgov.com/modernization/2021/02/ato-asap-lets-finally-fix-the-security-compliance-problem/258357/) diff --git a/_posts/2021-03-22-fcw-streamlining-government-security-with-a-federal-compliance-library.md b/_posts/2021-03-22-fcw-streamlining-government-security-with-a-federal-compliance-library.md index 2b9b384..c67464d 100644 --- a/_posts/2021-03-22-fcw-streamlining-government-security-with-a-federal-compliance-library.md +++ b/_posts/2021-03-22-fcw-streamlining-government-security-with-a-federal-compliance-library.md @@ -16,4 +16,4 @@ From the post: > By building a Federal Compliance Library based on open, iterative, collaborative principles, the federal government technology community will go further, faster. -Full post: [ATO ASAP: Streamlining government security with a Federal Compliance Library](https://fcw.com/articles/2021/03/22/comment-lazzeri-ato-asap.aspx) \ No newline at end of file +Full post: [ATO ASAP: Streamlining government security with a Federal Compliance Library](https://fcw.com/articles/2021/03/22/comment-lazzeri-ato-asap.aspx) diff --git a/_posts/2024-03-11-cybersecurity-notes.md b/_posts/2024-03-11-cybersecurity-notes.md new file mode 100644 index 0000000..27a618e --- /dev/null +++ b/_posts/2024-03-11-cybersecurity-notes.md @@ -0,0 +1,17 @@ +--- +layout: post +title: "Cybersecurity: Open and Transparent" +date: 2024-03-11 08:00:00 -0800 +description: Data Centricity is key. +author: fen-labalme +categories: featured +image: card-power.png +--- + +Obtaining an ATO is required for every internet-based system in the federal government. The documentation for an ATO is called a system security plan or SSP. Creating the SSP can take months, and very few SSPs are clear, complete or well written. In particular, details about how, say, access control or audit logs are managed may be broadly covered with few specifics regarding the system at hand. Further complicating the process, is a shroud of secrecy that forces every ISSO building a SSP has to reinvent the wheel for every technology component that their system is using. + +After inspecting hundreds of SSPs, we have found that the information contained within rarely requires secrecy to maintain the security of the system. And when such sensitive information exists it is usually misplaced and should not be in the SSP to begin with. To be clear, the results of assessing an SSP, that may include a list of discovered vulnerabilities, can reasonably be considered sensitive and maintained in a secure fashion. But there's a little reason for the SSP itself to remain secret, or even for the secure management of the general component-level assessment processes. (Tailored, specific assessment processes aimed at a particular implementation and environment may be crafted to exercise specific features of a system, and therefore may have a need to remain secret. But this is the exception and not the rule.) + +The threat landscape is evolving along with Moore's Law at an exponential rate. Humans do not evolve so quickly. And there is an increasing need to be proactive in the expanding open source software world. SBOM can show you CVEs that exist, but you need to know, your developers need to know what the risks are and what needs to be protected and what the business case is. Where open source development appears to be getting more opaque, we believe this is the perfect time to introduce open source assessment and open source ATOs. + +Creating an SSP in an open and transparent manner can help to improve communication and collaboration between different parts of an organization and even across orgaanizations. A library of separable, reusable components enables wide review and support to address changes in the threat landscape existing security vulnerabilities that might otherwise have been overlooked. diff --git a/_sass/uswds/.DS_Store b/_sass/uswds/.DS_Store deleted file mode 100644 index a89b55b..0000000 Binary files a/_sass/uswds/.DS_Store and /dev/null differ diff --git a/_site/404.html b/_site/404.html index bd823ce..f20b129 100644 --- a/_site/404.html +++ b/_site/404.html @@ -5,7 +5,7 @@ -Not found (404) | ATO ASAP +Not found (404) | OpenATO @@ -68,8 +68,13 @@ href="/" title="Home"> + OpenATO + - ATO ASAP ALPHA + OpenATO ALPHA @@ -224,11 +229,11 @@

    Not found (404)

    -Help improve this page +Help improve this page

    @@ -320,7 +325,7 @@

    Not found (404)

    - +
    @@ -332,7 +337,7 @@ @@ -235,11 +241,11 @@

    Our work

    -Help improve this page +Help improve this page

    @@ -331,7 +337,7 @@

    Our work

    - +
    @@ -343,7 +349,7 @@ @@ -369,7 +374,7 @@ @@ -343,7 +348,7 @@
    -

    The ATO ASAP community is dedicated to providing a harassment-free experience for everyone, regardless of gender, gender identity and expression, sexual orientation, disability, physical appearance, body size, race, or religion. We do not tolerate harassment of participants in any form.

    +

    The OpenATO community is dedicated to providing a harassment-free experience for everyone, regardless of gender, gender identity and expression, sexual orientation, disability, physical appearance, body size, race, or religion. We do not tolerate harassment of participants in any form.

    -

    This code of conduct applies to all ATO ASAP sponsored spaces, including our blog, mailing lists, and wiki, as well as any other spaces that ATO ASAP hosts, both online and off. Anyone who violates this code of conduct may be sanctioned or expelled from these spaces at the discretion of the ATO ASAP Anti-Abuse Team.

    +

    This code of conduct applies to all OpenATO sponsored spaces, including our blog, mailing lists, and wiki, as well as any other spaces that OpenATO hosts, both online and off. Anyone who violates this code of conduct may be sanctioned or expelled from these spaces at the discretion of the OpenATO Anti-Abuse Team.

    -

    Some ATO ASAP-sponsored spaces may have additional rules in place, which will be made clearly available to participants. Participants are responsible for knowing and abiding by these rules. +

    Some OpenATO-sponsored spaces may have additional rules in place, which will be made clearly available to participants. Participants are responsible for knowing and abiding by these rules. Definitions

    Harassment includes:

    @@ -231,11 +236,11 @@

    Code of conduct

  3. Unwelcome sexual attention
  4. Pattern of inappropriate social contact, such as requesting/assuming inappropriate levels of intimacy with others
  5. Continued one-on-one communication after requests to cease
  6. -
  7. Deliberate “outing” of any aspect of a person’s identity without their consent except as necessary to protect other ATO ASAP members or other vulnerable people from intentional abuse
  8. +
  9. Deliberate “outing” of any aspect of a person’s identity without their consent except as necessary to protect other OpenATO members or other vulnerable people from intentional abuse
  10. Publication of non-harassing private communication
  11. -

    The ATO ASAP community prioritizes marginalized people’s safety over privileged people’s comfort. The ATO ASAP Anti-Abuse Team will not act on complaints regarding:

    +

    The OpenATO community prioritizes marginalized people’s safety over privileged people’s comfort. The OpenATO Anti-Abuse Team will not act on complaints regarding:

    + @@ -323,11 +329,11 @@

    Resources

    -Help improve this page +Help improve this page

    @@ -419,7 +425,7 @@

    Resources

    - +
    @@ -431,7 +437,7 @@ + @@ -286,11 +292,11 @@

    Introduction

    -Help improve this page +Help improve this page

    @@ -382,7 +388,7 @@

    Introduction

    - +
    @@ -394,7 +400,7 @@ + @@ -294,11 +300,11 @@

    Problem

    -Help improve this page +Help improve this page

    @@ -390,7 +396,7 @@

    Problem

    - +
    @@ -402,7 +408,7 @@ + @@ -287,11 +293,11 @@

    Resources

    -Help improve this page +Help improve this page

    @@ -383,7 +389,7 @@

    Resources

    - +
    @@ -395,7 +401,7 @@ + @@ -284,11 +290,11 @@

    Solution

    -Help improve this page +Help improve this page

    @@ -380,7 +386,7 @@

    Solution

    - +
    @@ -392,7 +398,7 @@ + @@ -299,11 +305,11 @@

    Stakeholders

    -Help improve this page +Help improve this page

    @@ -395,7 +401,7 @@

    Stakeholders

    - +
    @@ -407,7 +413,7 @@ @@ -260,7 +265,7 @@

    Project board

    Contribute

    Contribute

    -

    Everyone is welcome. Learn how you can contribute to ATO ASAP.

    +

    Everyone is welcome. Learn how you can contribute to OpenATO.

    @@ -300,42 +305,6 @@

    Fen Labalme

    -
  12. -
    -
    -
    - Luke Fretwell -
    -
    -
    -

    Luke Fretwell

    -
    -
    -

    -
    - -
    -
  13. - -
  14. -
    -
    -
    - Marlena Medford -
    -
    -
    -

    Marlena Medford

    -
    -
    -

    -
    - -
    -
  15. -
  16. @@ -361,6 +330,10 @@

    Mary Lazzeri

    News

    +

    Cybersecurity: Open and Transparent

    +

    Data Centricity is key.

    +

    March 11, 2024

    +

    FCW: Streamlining government security with a Federal Compliance Library

    FCW published a guest editorial we wrote on building a Federal Compliance Library to help streamline the authority to operate process.

    March 22, 2021

    @@ -382,7 +355,7 @@

    Day One Project: Compliance as Code and Imp

    Get started

    -

    Learn and contribute to ATO ASAP.

    +

    Learn and contribute to OpenATO.

    Join us

    @@ -404,11 +377,11 @@

    Get started

    -Help improve this page +Help improve this page

    @@ -500,7 +473,7 @@

    Get started

    - +
    @@ -512,7 +485,7 @@

    @@ -338,7 +343,7 @@ @@ -336,7 +341,7 @@
    @@ -247,11 +257,11 @@

    Day One Project: Compliance as Code and Imp -Help improve this page +Help improve this page

    @@ -343,7 +353,7 @@

    Day One Project: Compliance as Code and Imp
    - +

    @@ -355,7 +365,7 @@ @@ -344,7 +351,7 @@
  17. -
  18. -
    -
    -
    - Luke Fretwell -
    -
    -
    -

    Luke Fretwell

    -
    -
    -

    -
    - -
    -
  19. - -
  20. -
    -
    -
    - Marlena Medford -
    -
    -
    -

    Marlena Medford

    -
    -
    -

    -
    - -
    -
  21. -
  22. @@ -290,6 +259,7 @@

    Mary Lazzeri

    + @@ -307,11 +277,11 @@

    Mary LazzeriHelp improve this page +Help improve this page

    @@ -403,7 +373,7 @@

    Mary Lazzeri -

    + @@ -415,7 +385,7 @@
  23. LinkedIn
  24. -
  25. Twitter
  26. +
  27. GitLab
  28. @@ -224,6 +229,8 @@

    Connect

    Posts

    @@ -251,11 +258,11 @@

    Posts

    -Help improve this page +Help improve this page

    @@ -347,7 +354,7 @@

    Posts

    - +
    @@ -359,7 +366,7 @@ @@ -253,11 +258,11 @@

    Posts

    -Help improve this page +Help improve this page

    @@ -349,7 +354,7 @@

    Posts

    - +
    @@ -361,7 +366,7 @@ @@ -335,7 +340,7 @@ @@ -352,7 +376,7 @@ @@ -366,7 +371,7 @@ @@ -264,11 +269,11 @@

    FCW: ATO ASAP: Let’s finally fix the security com -Help improve this page +Help improve this page

    @@ -360,7 +365,7 @@

    FCW: ATO ASAP: Let’s finally fix the security com
    - +
    @@ -372,7 +377,7 @@

    @@ -376,7 +381,7 @@ @@ -366,7 +371,7 @@ @@ -372,7 +378,7 @@ \ No newline at end of file + diff --git a/pages/playbook.html b/pages/playbook.html index 38ddd65..edcc948 100644 --- a/pages/playbook.html +++ b/pages/playbook.html @@ -1,13 +1,13 @@ --- layout: default -title: ATO ASAP Playbook +title: OpenATO Playbook description: excerpt: permalink: /playbook hero: image: callout: - alt: "ATO ASAP Playbook" + alt: "OpenATO Playbook" text: link: text: Link to more about that priority