Skip to main content
GSA Logo

Cloud Economics

About MCaaS

A&A Milestones

We understand that ATO is an important and complex process your application as a tenant on the MCaaS platform. We recommend working closely with your ISSO/ISSM from an early phase to set expectations and resolve any unknowns before the assessment and authorization process. Below is an overly simplified A&A milestone to help you understand your ATO journey.

Below is the list of documents and steps that take you towards the assessment phase for reference:

TasksAssignment Responsibility
Complete SSP Draft - Sections 1-12Program Team
ISSO Review: Section 1-12 of SSP for Architecture Review and quality controlISSO
Submit sections 1-12 of SSP for Architecture ReviewISSO
Complete SSP Draft - Section 13Program Team
Complete PTA/PIAProgram Team
Complete FIPS-199Program Team
Complete Digital Identity AcceptanceProgram Team
Complete ISA documentation if requiredProgram Team
Complete BIAProgram Team
Complete Continuity of Operations PlanProgram Team
Complete Configuration Management PlanProgram Team
Complete Incident Response PlanProgram Team
Complete Rules of Behavior for systemProgram Team
Fully instantiate environment for assessment (Essentially means that your SaaS, IaaS, PaaS is configured for GSA usage)Program Team
Complete OS/DB ScanningISSO/SecOps
Complete Web Scanning for GSA implementation site (Netsparker scan from SecOps)ISSO/SecOps
Remediate High and Critical Findings from Netsparker or WebApp scanProgram Team
Rescan to ensure remediationISSO/SecOps
Remediate any Architecture Review questionsProgram Team
Submit section 13 to ISSO for review and acceptanceProgram Team
Remediate any control comments from ISSOProgram Team
ISSO submits section 13 to ISSM for acceptance and movement forward for assessment if no issues remainISSO
    On this page:
    test