Mission Intelligence Systems
Risk · Authority

The ATO Is an Authority Problem, Not a Security One

Every fix aimed at the paperwork leaves the signature exactly where it was.

An authorization to operate is described as a security control and experienced as a schedule event. It is neither. It is one named person accepting residual risk in writing, inside a consequence structure that quietly rewards them for not signing yet.

Published

Key Takeaways

Research foundation

The governing framework is NIST SP 800-37 Rev. 2 and the structural fix is the Department of Defense CIO memorandum on continuous authorization. The measured drift comes from GAO-24-106591. The authority mechanism is Aghion and Tirole on formal versus real authority, with Snook on how practice separates from procedure. The red tape findings are a meta-analysis by George and colleagues and a study by Jacobsen and Jakobsen, both in Public Administration Review. Two caveats are carried in the text rather than buried here. The ACT-IAC paper is an advisory council white paper written with graduate students, so it is weaker as citable authority than the government documents beside it. And the red tape studies were conducted in Danish public schools, so what transfers is the shape of the asymmetry rather than any number.

Ask a federal program manager what is holding up delivery and the authorization will come up within two minutes. Ask what has been tried and you will hear about templates, inherited controls, automated evidence collection, a control library, a tracking dashboard and a working group. Ask what changed and the answer is usually some version of not much.

That pattern is worth stopping on, because a problem that survives six competent interventions is not the problem those interventions were aimed at.

What is actually being decided?

One person accepting risk on behalf of an organization, in writing, with their name on it.

NIST Special Publication 800-37 Revision 2, published on 20 December 2018, sets out the Risk Management Framework federal agencies apply. It is a careful document and it is clear about the authorization step. A named senior official reviews the residual security and privacy risk of operating a system and decides whether the organization will accept it. In most agencies that official is the chief information officer or the chief information security officer.

Notice what the framework can and cannot do. It names the role, defines the decision and specifies the evidence. It cannot allocate what happens to the person afterwards. That allocation is made somewhere else entirely, in how the agency responds to an incident and in what any given official believes will happen to them, and it is not symmetric.

Why does adding evidence make it slower?

Because more evidence lengthens the review without changing what the reviewer is carrying.

An ACT-IAC paper on improving the process states the asymmetry plainly. Declining, requesting further documentation or deferring a decision is legally defensible and institutionally safe for an authorizing official. Accelerating an authorization puts that official at risk if a breach follows. Both halves are true and neither requires anyone to behave badly.

Follow that through. A system that never ships produces no incident, no inspector general finding and no congressional letter. A system that ships and is breached produces all three, and the record shows a signature with a date on it. The two outcomes are not weighted equally by anyone who has watched the second one happen to a colleague.

Now add a control inheritance library and an automated evidence pipeline. The package arrives faster and it is larger. The official's exposure is unchanged, so the reading is unchanged, and the additional material is additional reading. This is the part that surprises people, and it should not. An intervention that improves supply into a queue whose service rate is set by something else lengthens the queue.

Where does the real authority sit?

Not with the person whose name is on the decision, which is the whole difficulty.

Aghion and Tirole drew the distinction in 1997 and it has held up. Formal authority is the right to decide. Real authority is effective control over what gets decided. The two come apart whenever the formal holder is not the informed party, and their model predicts that an uninformed principal will largely defer to the informed agent's recommendation. Real authority migrates to whoever holds the information.

An authorizing official is exactly that uninformed principal. They did not build the system, they cannot independently evaluate its residual risk, and the assessment team holds the knowledge. On the model, they should be rubber-stamping.

They are not, and the reason is the previous section. Deferring costs the informed agent nothing personal and costs the principal nothing at all, so the principal has a third move the model does not emphasize. They can neither evaluate nor safely approve, so they ask for more. That is not a transfer of authority. It is a request that the informed party do more work, issued by someone who cannot tell whether the additional work will change the answer.

This is also why escalation does not help. Sending an authorization to a more senior signer moves the formal authority further from the information, not closer to it, which is the same failure named in Risk Ownership Without Authority and in Who Controls Contingency. Naming an owner is not the same as giving that person the standing and the knowledge to act.

What happens while the signature is pending?

The work does not stop. It relocates, and it stops being visible.

Scott Snook studied the 1994 shootdown of two friendly helicopters over northern Iraq and found no rule breaker. He found practical drift, the slow separation of local practice from designed procedure under real operating conditions, each step locally reasonable and none of them reviewed against the whole. The failure was structural rather than moral, which is precisely what makes it hard to see from inside.

The authorization queue produces the same drift, and unusually there is a measurement of it. GAO reported in January 2024 that the twenty-four CFO Act agencies increased their FedRAMP authorizations by roughly sixty percent between July 2019 and April 2023, and that nine agencies reported using cloud services that were not authorized through the program at all. Cost data was limited, and the estimates agencies and providers did give ranged from tens of thousands of dollars to millions.

Read those two findings together. Adoption is climbing and unauthorized use is happening in the same population at the same time. Neither number is an accusation. They are what a mission looks like when it has to keep operating and the front door is slow.

Who feels the delay, and who decides about it?

Different people, and the gap between them explains why the problem is so durable.

George, Pandey, Steijn, Decramer and Audenaert published a meta-analysis in Public Administration Review in 2021 covering red tape, organizational performance and employee outcomes. Two of its findings matter here. The negative effect on both performance and employee outcomes is significant and in the small to medium range, so this is real and it is not enormous. And red tape an organization imposes on itself is more harmful than red tape imposed on it from outside. That second finding is the one to sit with, because most of what a program experiences as the authorization burden is agency-added rather than statutory.

Jacobsen and Jakobsen add the asymmetry. Studying Danish upper secondary schools with objective performance data, they found a small negative relationship between staff-perceived red tape and performance, and no relationship for manager-perceived red tape. The people doing the work register the drag. The people positioned to remove it do not, at least not in a way that tracks the outcome.

That is a finding about Danish schools and not about federal agencies, and it should be treated as a hypothesis to test locally rather than a fact to assert. The test is cheap. Ask the delivery teams and the authorization staff the same question about how much of the burden is required, separately, and compare the two answers.

What actually changes the decision?

Two things, and both of them are structural rather than procedural.

The first costs nothing and is rarely done. Separate the requirements FISMA and NIST actually impose from the ones the agency added, in one document, with a named owner for every item in the second list. The meta-analysis above says the second list is where the damage concentrates, and in most agencies nobody has ever written it down, so it cannot be argued with. An item whose owner cannot be found is an item nobody is defending.

The second changes what is being signed. The Department of Defense chief information officer issued a memorandum in February 2022 on continuous authorization to operate, setting out three competencies an authorizing official must see demonstrated before granting one. Adoption of an approved DevSecOps reference design. The ability to conduct active cyber defense in response to real-time threats. Ongoing visibility of activity inside the authorization boundary, with continuous monitoring of the controls. The memorandum is candid that current practice concentrates on obtaining the authorization and falls short on monitoring risk afterwards.

What that does to the asymmetry is the point. A point-in-time signature is a bet on a package. A continuous authorization is a bet on a monitored state that the official can watch, and watching is a form of protection the package never offered. The exposure changes because the evidence keeps arriving. An agency that adopts the vocabulary without the monitoring has changed nothing and has told itself otherwise, which is worse than not starting.

Why this is an Authority problem

Because the analysis is finished and the behavior has not changed.

Everyone in this process knows what the controls are, what the residual risk looks like and roughly how long the review will take. The knowledge is not the constraint. The constraint is that the one person who must act carries an exposure nobody has offered to share, and no amount of better evidence redistributes it. Authority in the sense this practice uses the word is the standing to decide combined with the ability to bear the decision, and an authorizing official has been handed the first half without the second.

The diagnostic takes about a minute. Ask three people in the program what would have to be true for the authorizing official to sign next week. If the answers are all about documents, the program is working on supply. If anybody answers in terms of what the official would be carrying afterwards, somebody there is looking at the actual constraint.

Evidence matrix

ClaimEvidence tierSource
The authorization is one named official accepting residual riskGovernment frameworkNIST SP 800-37 Rev. 2 (2018)
Deferring is institutionally safe; accelerating is personal exposureAdvisory council white paperACT-IAC (2025)
Formal and real authority separate when the decider is not the informed partyPeer reviewedAghion & Tirole (1997), JPE 105(1)
Practice separates from designed procedure with no rule brokenScholarly monographSnook (2000), Princeton University Press
Nine agencies used cloud services outside the authorization programGovernment auditGAO-24-106591 (January 2024)
Internally imposed red tape harms performance more than externalPeer reviewed meta-analysisGeorge et al. (2021), PAR 81(4)
Staff perception tracks performance; manager perception does notPeer reviewed, Danish schoolsJacobsen & Jakobsen (2018), PAR 78(1)
Continuous authorization changes what is signed, not how much is filedGovernment directiveDoD CIO memorandum (February 2022)
Adding evidence without moving consequence lengthens the queueFour A's interpretationBuilders Build, Authority

What to do with this

Before the next authorization review, write down the two lists. What the law and the framework require, and what this agency added. Give every item on the second list a named owner. Most of the argument about authorization timelines is conducted without either list existing, which is why it is conducted about documents.

References

  1. National Institute of Standards and Technology. Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy. NIST Special Publication 800-37, Revision 2, 20 December 2018. nvlpubs.nist.gov.
  2. U.S. Government Accountability Office. Cloud Security: Federal Authorization Program Usage Increasing, but Challenges Need to Be Fully Addressed. GAO-24-106591, January 2024. gao.gov/products/gao-24-106591.
  3. U.S. Department of Defense, Office of the Chief Information Officer. Continuous Authorization To Operate (cATO). Memorandum, February 2022. dodcio.defense.gov.
  4. Aghion, Philippe, and Jean Tirole. “Formal and Real Authority in Organizations.” Journal of Political Economy, vol. 105, no. 1, 1997, pp. 1–29. doi.org/10.1086/262063.
  5. Snook, Scott A. Friendly Fire: The Accidental Shootdown of U.S. Black Hawks over Northern Iraq. Princeton University Press, 2000. doi.org/10.1515/9781400840977.
  6. George, Bert, Sanjay K. Pandey, Bram Steijn, Adelien Decramer, and Mieke Audenaert. “Red Tape, Organizational Performance, and Employee Outcomes: Meta-analysis, Meta-regression, and Research Agenda.” Public Administration Review, vol. 81, no. 4, 2021, pp. 638–651. doi.org/10.1111/puar.13327.
  7. Jacobsen, Christian Bøtcher, and Mads Leth Jakobsen. “Perceived Organizational Red Tape and Organizational Performance in Public Services.” Public Administration Review, vol. 78, no. 1, 2018, pp. 24–36. doi.org/10.1111/puar.12817.
  8. ACT-IAC Cybersecurity Community of Interest. Improving the ATO Process: Cultural Change, Automation, and Cloud Adoption in Federal Agencies. American Council for Technology and Industry Advisory Council, September 2025. actiac.org. An advisory council white paper prepared with graduate students, weaker as citable authority than the government documents above.
DF

About the Author

Dan Flynn

Creator of The Four A's of Organizational Readiness™ · Enterprise Transformation Executive · Author, Builders Build

Dan Flynn has spent thirty years inside federal, defense, and commercial organizations: diagnosing the invisible conditions that determine whether capable people produce extraordinary results. He is the creator of The Four A's of Organizational Readiness™ framework, has reached more than 11,000 professionals across corporate, civic, and national security contexts, and took a federal data platform from one release every six months to seventy-two every two weeks by changing organizational conditions: not people.

His book, Builders Build: The Four A’s of Organizational Readiness™, is forthcoming.