healthcarereimagined

Envisioning healthcare for the 21st century

  • About
  • Economics

VA Lighthouse Sets Federal Innovation Standards

Posted by timmreardon on 09/24/2023
Posted in: Uncategorized.

Share this story

Facebook

Twitter

LinkedIn

Reddit

Email

In this article

  • Lighthouse Delivery Infrastructure
  • How do we address this problem?
  • Accelerating delivery without compromising security

As VA strives to provide Veterans with increasingly high-quality and secure digital experiences, the VA Lighthouse Developer Experience program plays a significant role in making this a reality.

Throughout the 2022 calendar year, Lighthouse focused on enabling VA’s Office of Information and Technology (OIT) teams to deliver valuable software applications with higher quality and reduced risk through agile development and continuous delivery.

This focus has led to the development of Lighthouse Delivery Infrastructure with its Secure Release pipeline, which simplifies software development at VA, making it more efficient, repeatable, and secure.

Lighthouse Delivery Infrastructure

All high-quality software (API or otherwise) requires a standard set of development and operations-centric infrastructure and tools to achieve sustainability and scalability. To address this reality, the Lighthouse Delivery Infrastructure provides a suite of infrastructure, tools, and development guidelines that enable rapid and secure development, deployment, and operation of high-quality VA APIs within the VA Enterprise Cloud (VAEC).

In short, the overarching goal of the Lighthouse Delivery Infrastructure is to deliver products that work for Veterans by prioritizing the effectiveness and collaboration of software product delivery teams within VA OIT.

However, offering capabilities to efficiently develop and deploy software (like APIs) is only part of the solution. To truly realize time and cost savings, we must be able to secure and authorize software equally efficiently.

Federal Government agencies are required to leverage the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) to authorize software for operation with an Authority to Operate (ATO).

ATOs manage risk by identifying and evaluating applicable NIST RMF controls for new and existing applications. A tremendous amount of work and responsibility goes into certifying applications for use and granting an ATO. It requires an Authorizing Official (AO) to accept the benefits and risks of the application’s initial release into production and all subsequent releases. As an application is enhanced, its ATO must evolve to reflect its ever-changing security and risk posture.

Obtaining and maintaining an ATO at VA is rigorous; it takes months (and often more than a year) for new applications to get an ATO. Similarly, a significant amount of time is required to maintain an ATO as an application evolves.

This may be tenable for legacy software development with low-frequency release cadences, but not for software releasing into Production on a weekly or even daily basis.

To meet agile teams where they are, a continuous ATO (cATO) process is necessary, and VA OIT established one.VA’s Chief Information Officer (CIO) Kurt DelBene and Chief Information Security Officer (CISO) Lynette Sherrill granted full approval to the cATO, which is making a huge impact.

How do we address this problem?

To pair modern, agile software development with a cATO process, Lighthouse has leveraged ongoing authorization under NIST RMF. Importantly, NIST encourages organizations to employ iterative and incremental approaches to ensure security and privacy requirements and controls are implemented, verified, and validated on an ongoing basis.

Lighthouse is demonstrating a continuous learning culture that embraces guiding principles to be better, faster, and more secure by incrementally improving their approved cATO process. This process leverages the strengths of VA Enterprise Cloud (VAEC) and Lighthouse Delivery Infrastructure, as well as embedding independent application security assessors into software development teams.

This means software development teams not only benefit from having a significant set of security controls inherited from VAEC and the platform, but every code commit automatically triggers the Secure Release pipeline that runs vulnerability scans for images and containers, source code, and third-party dependencies. And security remains a key focus throughout the entire lifecycle of a product, extending to continuous runtime monitoring in production.

Once a team satisfies requirements enforced by the Secure Release pipeline, they obtain a signed image that allows for deployment of the product to a live production environment. These requirements include the remediation of vulnerabilities detected in scanning, and verification that security requirements are met by their application security assessor.

Accelerating delivery without compromising security

By investing in automation and user-centered design principles to increase transparency and traceability between software development teams and security specialists, Lighthouse’s cATO process enables teams to deliver high-quality, secure software empowered by innovative cybersecurity technology.

The VA Lighthouse Developer Experience program champions operational excellence as VA continues to modernize its technology and systems to enhance users’ experience with digital tools in the most secure way possible. Ongoing authorization allows VA to ship secure, authorized software 80% faster, placing VA as a frontrunner in the federal civilian agency space.

Article link: https://digital.va.gov/operational-excellence/va-lighthouse-sets-federal-innovation-standards/

Share this:

  • Click to share on X (Opens in new window) X
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on LinkedIn (Opens in new window) LinkedIn
Like Loading...

Related

Posts navigation

← A chip design that changes everything: 10 Breakthrough Technologies 2023 – MIT Technology Review
What’s next for the world’s fastest supercomputers – MIT Technology Review →
  • Search site

  • Follow healthcarereimagined on WordPress.com
  • Recent Posts

    • Why AI predictions are so hard – MIT Technology Review 01/07/2026
    • Will AI make us crazy? – Bulletin of the Atomic Scientists 01/04/2026
    • Decisions about AI will last decades. Researchers need better frameworks – Bulletin of the Atomic Scientists 12/29/2025
    • Quantum computing reality check: What business needs to know now – MIT Sloan 12/29/2025
    • AI’s missing ingredient: Shared wisdom – MIT Sloan 12/21/2025
    • Hype Correction – MIT Technology Review 12/15/2025
    • Semantic Collapse – NeurIPS 2025 12/12/2025
    • The arrhythmia of our current age – MIT Technology Review 12/11/2025
    • AI: The Metabolic Mirage 12/09/2025
    • When it all comes crashing down: The aftermath of the AI boom – Bulletin of the Atomic Scientists 12/05/2025
  • Categories

    • Accountable Care Organizations
    • ACOs
    • AHRQ
    • American Board of Internal Medicine
    • Big Data
    • Blue Button
    • Board Certification
    • Cancer Treatment
    • Data Science
    • Digital Services Playbook
    • DoD
    • EHR Interoperability
    • EHR Usability
    • Emergency Medicine
    • FDA
    • FDASIA
    • GAO Reports
    • Genetic Data
    • Genetic Research
    • Genomic Data
    • Global Standards
    • Health Care Costs
    • Health Care Economics
    • Health IT adoption
    • Health Outcomes
    • Healthcare Delivery
    • Healthcare Informatics
    • Healthcare Outcomes
    • Healthcare Security
    • Helathcare Delivery
    • HHS
    • HIPAA
    • ICD-10
    • Innovation
    • Integrated Electronic Health Records
    • IT Acquisition
    • JASONS
    • Lab Report Access
    • Military Health System Reform
    • Mobile Health
    • Mobile Healthcare
    • National Health IT System
    • NSF
    • ONC Reports to Congress
    • Oncology
    • Open Data
    • Patient Centered Medical Home
    • Patient Portals
    • PCMH
    • Precision Medicine
    • Primary Care
    • Public Health
    • Quadruple Aim
    • Quality Measures
    • Rehab Medicine
    • TechFAR Handbook
    • Triple Aim
    • U.S. Air Force Medicine
    • U.S. Army
    • U.S. Army Medicine
    • U.S. Navy Medicine
    • U.S. Surgeon General
    • Uncategorized
    • Value-based Care
    • Veterans Affairs
    • Warrior Transistion Units
    • XPRIZE
  • Archives

    • January 2026 (2)
    • December 2025 (11)
    • November 2025 (9)
    • October 2025 (10)
    • September 2025 (4)
    • August 2025 (7)
    • July 2025 (2)
    • June 2025 (9)
    • May 2025 (4)
    • April 2025 (11)
    • March 2025 (11)
    • February 2025 (10)
    • January 2025 (12)
    • December 2024 (12)
    • November 2024 (7)
    • October 2024 (5)
    • September 2024 (9)
    • August 2024 (10)
    • July 2024 (13)
    • June 2024 (18)
    • May 2024 (10)
    • April 2024 (19)
    • March 2024 (35)
    • February 2024 (23)
    • January 2024 (16)
    • December 2023 (22)
    • November 2023 (38)
    • October 2023 (24)
    • September 2023 (24)
    • August 2023 (34)
    • July 2023 (33)
    • June 2023 (30)
    • May 2023 (35)
    • April 2023 (30)
    • March 2023 (30)
    • February 2023 (15)
    • January 2023 (17)
    • December 2022 (10)
    • November 2022 (7)
    • October 2022 (22)
    • September 2022 (16)
    • August 2022 (33)
    • July 2022 (28)
    • June 2022 (42)
    • May 2022 (53)
    • April 2022 (35)
    • March 2022 (37)
    • February 2022 (21)
    • January 2022 (28)
    • December 2021 (23)
    • November 2021 (12)
    • October 2021 (10)
    • September 2021 (4)
    • August 2021 (4)
    • July 2021 (4)
    • May 2021 (3)
    • April 2021 (1)
    • March 2021 (2)
    • February 2021 (1)
    • January 2021 (4)
    • December 2020 (7)
    • November 2020 (2)
    • October 2020 (4)
    • September 2020 (7)
    • August 2020 (11)
    • July 2020 (3)
    • June 2020 (5)
    • April 2020 (3)
    • March 2020 (1)
    • February 2020 (1)
    • January 2020 (2)
    • December 2019 (2)
    • November 2019 (1)
    • September 2019 (4)
    • August 2019 (3)
    • July 2019 (5)
    • June 2019 (10)
    • May 2019 (8)
    • April 2019 (6)
    • March 2019 (7)
    • February 2019 (17)
    • January 2019 (14)
    • December 2018 (10)
    • November 2018 (20)
    • October 2018 (14)
    • September 2018 (27)
    • August 2018 (19)
    • July 2018 (16)
    • June 2018 (18)
    • May 2018 (28)
    • April 2018 (3)
    • March 2018 (11)
    • February 2018 (5)
    • January 2018 (10)
    • December 2017 (20)
    • November 2017 (30)
    • October 2017 (33)
    • September 2017 (11)
    • August 2017 (13)
    • July 2017 (9)
    • June 2017 (8)
    • May 2017 (9)
    • April 2017 (4)
    • March 2017 (12)
    • December 2016 (3)
    • September 2016 (4)
    • August 2016 (1)
    • July 2016 (7)
    • June 2016 (7)
    • April 2016 (4)
    • March 2016 (7)
    • February 2016 (1)
    • January 2016 (3)
    • November 2015 (3)
    • October 2015 (2)
    • September 2015 (9)
    • August 2015 (6)
    • June 2015 (5)
    • May 2015 (6)
    • April 2015 (3)
    • March 2015 (16)
    • February 2015 (10)
    • January 2015 (16)
    • December 2014 (9)
    • November 2014 (7)
    • October 2014 (21)
    • September 2014 (8)
    • August 2014 (9)
    • July 2014 (7)
    • June 2014 (5)
    • May 2014 (8)
    • April 2014 (19)
    • March 2014 (8)
    • February 2014 (9)
    • January 2014 (31)
    • December 2013 (23)
    • November 2013 (48)
    • October 2013 (25)
  • Tags

    Business Defense Department Department of Veterans Affairs EHealth EHR Electronic health record Food and Drug Administration Health Health informatics Health Information Exchange Health information technology Health system HIE Hospital IBM Mayo Clinic Medicare Medicine Military Health System Patient Patient portal Patient Protection and Affordable Care Act United States United States Department of Defense United States Department of Veterans Affairs
  • Upcoming Events

Blog at WordPress.com.
  • Reblog
  • Subscribe Subscribed
    • healthcarereimagined
    • Join 153 other subscribers
    • Already have a WordPress.com account? Log in now.
    • healthcarereimagined
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Copy shortlink
    • Report this content
    • View post in Reader
    • Manage subscriptions
    • Collapse this bar
 

Loading Comments...
 

    %d