Government Agencies are faced with a barrage of compliancy and evaluation requirements towards the management and security of information and systems. Radius Technology Group employs a risk-based approach to the certification and accreditation of systems following the framework set forth by the NIST publication 800-18, 800-53, OMB A-130, and PDD-63 (where applicable). Development of a quality certification and accreditation package is critical to provide assurance that IT systems contain adequate, functioning security controls.
We ensure that consideration for the adequacy of systems security controls have been made during all system life cycle phases including: |
• |
Defining the system and designing system requirements |
• |
Verifying compliance with the requirements during system development |
• |
Validating the adequacy before full system operation |
• |
Monitoring security controls throughout the system life cycle
|
We establish a definitive plan towards certification and accreditation taking into account all affected organizations and systems in concert with the overall strategic goals. Using the aforementioned certification controls we verify each component of the certification. Our verification process is on-going and consistently refined to reflect the appropriate control measures and certification requirements. Our comprehensive process includes often under reported areas such as privacy impact assessments, policy and program awareness, and system interconnections. We then validate our efforts with comprehensive reviews. Finally, we supply on-going post-accreditation support to ensure agency compliance.
Success Story Our command of certification and accreditation processes was displayed in support of the Bureau of Alcohol, Tobacco and Firearms (ATF). Radius Technology Group supplied detailed guidance to information technology organizations and system owners to certify and accredit all 57 of ATF’s information systems within 15 months. This resulted in an “A” grade from the Department of Justice’s CIO for Information Security.
Additionally, in support of the Department of Labor’s Employment Standard Administration (ESA) Radius provided systems testing and audit services to ensure all systems were in compliance with ESA IT Security standards. Further, Radius prepared all certification and accreditation packages for final approval. Our detailed and customer-focused support resulted in full "Authorization to Operate" for all ESA systems .
|
Please review other components of our Management Operations Suite:
|
• |
Risk Management |
• |
System Security Plan |
• |
Capital Planning/Resource Management |
• |
Enterprise Architecture |