Sarbari GuptaGuest
Chelsea RobertsHost
and I'm sure some greater vulnerabilities that are probably still being uncovered to this day and trying to identify some of those weaknesses that may exist must not be a very easy activity, especially across agencies that all do it different ways and they all have different interpretations and different perspectives on what security and cybersecurity means to them.

And I'm curious for a more technical audience, can you give us just a really quick high level or layman's terms explanation as to what the difference is between an RMF ATO and Zero Trust?

It's a five-stage process of documenting how you're implementing the various requirements for security, the different controls that NIST has put together.

ATO means that the agency has considered the various sets of security controls that apply to their systems.

They have been assessed in an independent way to ensure that the controls that they've implemented are operating as intended and that they're doing continuous monitoring, et cetera.

Now, Zero Trust is a much broader model of how you achieve security compliance.

There are five pillars and civilian side, seven pillars on the government, on the DOW side.


It's just more strategic, more high level, I would say, Zero Trust, as opposed to the RMF, whether it's the NIST version or the DoD version, which is a little more intense.

From my understanding, at least on the surface, I think a lot of people are like zero trust.

and I'm sure some greater vulnerabilities that are probably still being uncovered to this day and trying to identify some of those weaknesses that may exist must not be a very easy activity, especially across agencies that all do it different ways and they all have different interpretations and different perspectives on what security and cybersecurity means to them.

And I'm curious for a more technical audience, can you give us just a really quick high level or layman's terms explanation as to what the difference is between an RMF ATO and Zero Trust?

It's a five-stage process of documenting how you're implementing the various requirements for security, the different controls that NIST has put together.

ATO means that the agency has considered the various sets of security controls that apply to their systems.

They have been assessed in an independent way to ensure that the controls that they've implemented are operating as intended and that they're doing continuous monitoring, et cetera.

Now, Zero Trust is a much broader model of how you achieve security compliance.

There are five pillars and civilian side, seven pillars on the government, on the DOW side.


It's just more strategic, more high level, I would say, Zero Trust, as opposed to the RMF, whether it's the NIST version or the DoD version, which is a little more intense.

From my understanding, at least on the surface, I think a lot of people are like zero trust.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.