cATO – The New Frontier: Active Cyber Defense (ACD) (Part 3 of 5)

Recap: From SSSC to Active Cyber Defense

In Part 1, we covered the origins of Continuous Authorization to Operate (cATO), tracing how the OSD memo reframed authorization away from the slow, point-in-time ATO process and toward continuous, data-driven risk management built on three pillars: Secure Software Supply Chain (SSSC), Active Cyber Defense (ACD), and Continuous Monitoring (CONMON). Part 2 dug into the first of these, SSSC, showing how the evaluation criteria assess an organization’s DevSecOps Platform, processes, and people to ensure software entering the pipeline is trustworthy from the start. In this installment, we turn to the second pillar, ACD, and examine what the Department requires organizations to demonstrate once a system is live and operating.

Engaging a Certified Cybersecurity Service Provider (CSSP)

Active Cyber Defense (ACD) demonstrates an organization’s ability to actively detect, respond to, and recover from cyber threats in real time rather than relying solely on periodic assessments. A central requirement of ACD is engaging a Certified Cybersecurity Service Provider (CSSP) in accordance with “DoDI 8530.01 – Cybersecurity Activities Support Procedures”. This engagement can take one of three forms: external, in which case the organization must maintain a documented Service Level Agreement covering both on-premises and cloud-hosted systems; internal, in which case the organization must document its own ACD methodology; or inherited, where the organization relies on an established shared services environment and documents that inheritance relationship. In all three cases, the CSSP is expected to deploy sensors and detection tools appropriate to the environment, and the CSSP itself must be trained on the DevSecOps principles of the software factories it is monitoring, since generic network monitoring is not sufficient for a modern CI/CD pipeline.

Independent Validation Through Penetration Testing

In addition to the CSSP relationship, ACD requires independent, external validation of the organization’s security posture through penetration testing. Organizations must complete a penetration test within 90 days of authorization and annually thereafter, using an approved method such as a Cyber Operations Rapid Assessment (CORA), a Red/Blue Team exercise, or standard penetration testing. These assessments are meant to evaluate the effectiveness of people, processes, and technology together, probing the authorization boundary for exploitable weaknesses and providing the Authorizing Official with independent evidence that the organization’s defenses hold up under real adversarial pressure rather than theoretical review.

Incident Response and Continuity Planning

ACD also requires a full incident-response and continuity capability including a documented Continuity of Operations Plan (COOP) and Disaster Recovery Plan (DRP), with evidence that these plans have been tested through tabletop walkthroughs, simulations, or backup and restoration exercises. It likewise requires a documented Incident Response Plan (IRP) backed by clear policies, defined roles, training, and communication procedures demonstrated through periodic tabletop exercises rather than left as an untested document.

Ongoing Detection, Vulnerability Management, and Audit Logging

Finally, ACD requires organizations to show tangible, ongoing detection and remediation capabilities. This includes active behavior monitoring and intrusion detection/prevention systems, along with a vulnerability management program that publishes clear remediation timelines, tracks findings through Plans of Action and Milestones (POA&Ms), and follows the vulnerability-scanning procedures outlined in “DoDI 8530.01 – Cybersecurity Activities Support Procedures” with critical and moderate vulnerabilities mitigated within a timeframe approved by the Authorizing Official. Audit log analysis, covering collection, alerting, review, and retention ties these pieces together, feeding the real-time detection and response capability that ultimately gives the AO confidence to make ongoing, risk-informed authorization decisions.

Ongoing Coming Up in This Series

With SSSC ensuring trustworthy software and ACD ensuring an organization can respond to threats once systems go live, we now turn to the third and final pillar. Part 4 breaks down Continuous Monitoring (CONMON), covering the documentation, automated dashboards, and audit practices organizations must demonstrate to maintain the real-time risk visibility a cATO depends on.

 

Here at Andrew Morgan we help organizations obtain the highest value from their human capital, organizational, and technical investments to lower costs and optimize how they work, with capabilities spanning business process improvement, systems engineering and integration, analytics and reporting, infrastructure modernization, regulatory risk/compliance, and security and information assurance. If you are looking for a partner to help navigate your organization or program through this new way of working, we would love to hear from and engage with you directly.