AI-Enabled Continuous Authority-to-Operate (ATO) Frameworks for Information Systems
Main Article Content
Abstract
Static authorization to operate, based on the NIST RMF recommendations is typical for classical information systems of the government. Such static approach creates significant security gaps, hence it is important to consider Continuous Authorization to Operate options for the Department of Defense. This paper assesses possibilities to enable Continuous Authorization to Operate using the opportunities provided by the AI, including NLP and anomaly detection. The design science research approach was utilized to develop the hybrid prototype with NLP-based control mapping and ML-based monitoring system. Decision-making process transparency was ensured through the Explainable AI technology, specifically SHAP value analysis. The test results demonstrated 91.4% accuracy of control mapping, 87.9% anomaly detection precision, and 75% authorization cycle time reduction. On the other hand, there were integration problems associated with legacy DevSecOps, as well as the problem of stakeholder trust, which proved to be the most significant barriers to implementing AI solutions. It was found that 78% of compliance stakeholders would be ready to adopt AI technologies provided there is proper explainability and governance. Therefore, it can be stated that the best role of AI is that of an augmenter rather than that of a replacement for human actions. The present research paper is a contribution to existing FedRAMP and cATO automation literature.