# authority to operate

A risk-management and security authorization process for approving information systems to operate after security controls, testing, documentation, and risk review.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## What FedRAMP 20x Means for You

DevFeed: [What FedRAMP 20x Means for You](<https://devfeed.tech/articles/what-fedramp-20x-means-for-you-13317.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/what-fedramp-20x-means-for-you>)

Published: 2025-04-02T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Automation](<https://devfeed.tech/topics/automation.md>), [authority to operate](<https://devfeed.tech/topics/authority-to-operate.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [cve remediation](<https://devfeed.tech/topics/cve-remediation.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [authority-to-operate](<https://devfeed.tech/tags/authority-to-operate.md>), [automation](<https://devfeed.tech/tags/automation.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [complexity](<https://devfeed.tech/tags/complexity.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cost](<https://devfeed.tech/tags/cost.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [cves](<https://devfeed.tech/tags/cves.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fedramp-20x](<https://devfeed.tech/tags/fedramp-20x.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article explains that FedRAMP 20x is intended to streamline the authority-to-operate process through automation and continuous validation. It says the core security and compliance controls are not changing and that the existing agency-based FedRAMP Rev. 5 authorization path remains active.

### Source excerpt

FedRAMP 20x is a new initiative designed to automate and simplify the FedRAMP process. Get the rundown on what is changing, and how Chainguard can help.

## A thought experiment on using low-vulnerability Chainguard Images to speed government software delivery

DevFeed: [A thought experiment on using low-vulnerability Chainguard Images to speed government software delivery](<https://devfeed.tech/articles/ship-software-to-uncle-sam-faster-with-zero-known-vulnerability-containers-13230.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/ship-software-to-uncle-sam-faster-with-zero-known-vulnerability-containers>)

Published: 2023-06-20T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [authority to operate](<https://devfeed.tech/topics/authority-to-operate.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard labs](<https://devfeed.tech/topics/chainguard-labs.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ato](<https://devfeed.tech/tags/ato.md>), [authority-to-operate](<https://devfeed.tech/tags/authority-to-operate.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-labs](<https://devfeed.tech/tags/chainguard-labs.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [government](<https://devfeed.tech/tags/government.md>), [image-cves](<https://devfeed.tech/tags/image-cves.md>), [secure-container-image](<https://devfeed.tech/tags/secure-container-image.md>), [secure-minimal-image](<https://devfeed.tech/tags/secure-minimal-image.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>)

### AI overview

This opinion article proposes studying whether Chainguard Images with zero-known or low vulnerability counts could reduce timelines and staff costs in government Authority to Operate processes. It presents this as a hypothesis requiring comparison with other ATO processes, not as a demonstrated result.

### Source excerpt

Discover how 0-known vulnerability containers from Chainguard Labs could accelerate software delivery to the government.