The completion of a system security plan is a requirement of the Office of Management and Budget (OMB) Circular A-130, the Computer Security Act, and the Federal Information Security Management Act (FISMA).
Though mandated by federal requirements, Radius Technology Group views the creation of a comprehensive security plan as a genuine opportunity for an agency to align its strategic business goals and IT systems and resources with a consistent and comprehensive focus towards security and risk mitigation.
A system security plan is invaluable in establishing the overall security framework. The plan provides a means of continually assessing an agency's security posture as it relates not only to established regulatory requirements, but also to the overall business objectives, policies and programs throughout the organization.
Radius Technology Group’s team of forward thinking security professionals assist agencies in establishing security plans and addressing opportunities to continually improve security controls as they relate to the organization's goals. Our team employs a methodical, vulnerability and mitigation conscious approach to assisting in the following areas: |
• |
Outline security measures for a system |
• |
Detail the measures currently in place |
• |
Identify and define targeted implementation and planned milestones |
• |
Assign responsibility and accountability for system security measures |
• |
Define security awareness and responsibility of system users
|
Radius Technology Group’s vast auditing and security management experience allows us to align past “lessons learned,” to current real word scenarios, and generate future considerations towards the security management of enterprise life cycles.
Success Story While providing assistance to Alcohol, Tobacco and Firearms, we successfully completed its security awareness plan (mandated by DOJ). Additionally, we developed, implemented and maintain its information security website. Our team has supported all ATF’s specialized individual security training which help end users complete their system security plans, risk assessments and contingency plans. This individualized training helped ATF achieve its FY2003 goal of certifying and accrediting all 57 of its systems.
|
Please review other components of our Management Operations Suite:
|
• |
Risk Management |
• |
Certification and Accreditation |
• |
Capital Planning/Resource Management |
• |
Enterprise Architecture |