Replacing the DoD Information Assurance Certification and Accreditation Process (DIACAP) should let owners, operators and defenders of IT systems better manage risks.