FedRAMP, A&A and C&A Services - Assessment and Authorization - FISMA, Software Assurance...
- FedRAMP Assessment and Consultation...
- A&A Assessment and Authorization...
- C&A Certification & Accreditation Assessments...
- Security Test and Evaluation (ST&E)...
- Software Assurance Malicious Code Assessments...
- COOP, Disaster Recovery, Contingency - Planning and Testing
- PVM - Patch and Vulnerability Management
To help secure information systems within the Federal government, including the critical infrastructure of the United States, TestPros uses established standardized assessment methods and procedures to assess the security controls in federal information systems.
Our FedRAMP, A&A and C&A processes will determine if security controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements of the agency.
TestPros FedRAMP, A&A and C&A assessments take into consideration the entire system, network, and application lifecycle from a security standpoint. In short, the process is a manual audit of policies, procedures, controls, and contingency planning.
The employment of standard assessment methods and procedures promotes more consistent, comparable, and repeatable security assessments. TestPros will also develop specific FedRAMP and/or A&A test and evaluation procedures and methods for unique and non-standard environments.
For those systems that exhibit security vulnerabilities, TestPros will produce recommendations for bringing the appropriate security controls into compliance.
The outcome of the FedRAMP and A&A process is to put together a collection of documents that describe the security posture of the systems, an evaluation of the risks, and recommendations for correcting deficiencies. It is what's known as a Certification Package.
Our skilled and experienced FedRAMP/A&A/C&A Assessment Teams can help in many areas, including:
Security Operations...
- Ongoing Compliance Monitoring
- Real-time Network Traffic and Device-based Content Monitoring
- Configuration Management (CM) and Patch Management (PVM)
- Managed Security 'help desk' services
- Multi-level Security and Interoperability
FedRAMP, A&A, C&A Assessment...
- Regulatory Compliance (FedRAMP, FISMA, OMB Circular A-130 III, FIPS 199)
- Assessment and Authorization (NIST SP 800-37, DIACAP, DITSCAP, DCID 6/3, ISO 27002 - ISO 17799)
- Risk Assessments, System Security Plans (NIST SP 800-53, SP 800-26, SP 800-18)
- DIACAP DoD IA C&A Process, DCID 6/3
- Business Continuity and IT Systems Contingency Plans (NIST SP 800-34)
- Security Control Assessments (SCA) and Security Test & Evaluation (ST&E)
- Physical Security Assessments, Disaster Recovery Plans and Testing, COOP Plans and Testing...
Please contact us for additional information.