Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

A  |  B  |  C  |  D  |  E  |  F  |  G  |  H  |  I  |  J  |  K  |  L  |  M  |  N  |  O  |  P  |  Q  |  R  |  S  |  T  |  U  |  V  |  W  |  X  |  Y  |  Z

authorization to operate

Abbreviations / Acronyms / Synonyms:

accreditation
approval to operate
ATO
Security Authorization (to Operate)
Security Authorization(to Operate)

Definitions:

  Official management decision given by a senior Federal official or officials to authorize operation of an information system and to explicitly accept the risk to agency operations (including mission, functions, image, or reputation), agency assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security and privacy controls. Authorization also applies to common controls inherited by agency information systems. Note 1: The system is authorized to operate for a specified period in accordance with terms and conditions established by the authorizing official. Note 2: Formerly known as "approval to operate." Term was replaced in the risk management framework in 2010.
Sources:
CNSSI 4009-2022 from OMB Circular A-130 (2016)
NIST SP 800-161r1-upd1 [11/1/2024 errata update] from NIST SP 800-53 Rev. 5
NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016)
NIST SP 800-53 Rev. 5 from OMB Circular A-130 (2016)
NIST SP 800-53A Rev. 5 from OMB Circular A-130 (2016)

  Formal recognition that a laboratory is competent to carry out specific tests or calibrations or types of tests or calibrations.
Sources:
CNSSI 4009-2022 under accreditation from NIST HB 150-2016, NVLAP

  See Authorization (to operate).
Sources:
NIST SP 800-30 Rev. 1 under Security Authorization (to Operate)
NIST SP 800-39 under Security Authorization(to Operate)

  Authorization to Operate; One of three possible decisions concerning an issuer made by a Designated Authorizing Official after all assessment activities have been performed stating that the issuer is authorized to perform specific PIV Card and/or Derived Credential issuance services.
Sources:
NIST SP 800-79-2 under ATO