Certification and Accreditation
Problem: Federal client requested IT services for Certification and Accreditation (C&A) for implementing information security. C&A was required for evaluating, describing, testing and authorizing systems prior to or after a system was deployed in a world-wide mission critical applications.
Work Performed: Created security configuration guidelines and checklists to support application and database systems to be used in the certification process. These checklists were used as deliverables in management assessment of the operational and technical security controls in accrediting an information system.
Performed lockdown of operating systems, application servers and database servers for certification. Performed remediation of any security findings requirements for certification.
Benefits: Security Configuration Guidelines and Checklists provided consistent and repeatable methods to securely lockdown application and database servers.
Security Configuration Guidelines provided increased security awareness across all server administrators to follow proven security processes.
Security Configuration Guidelines and checklists helps to reduce misconfiguration of security lockdown of servers.