Description
Security Although TDG founders have large system integration/development experience as demonstrated above, the company initially started with a niche focus of providing IT security consulting to address the ongoing need for security assessments and system certification and accreditation (C&A) in accordance with the NIST, NIACAP, and DIACAP regulations. What the TDG leadership team very quickly saw was that the true need was not for additional technical expertise but for a cultural change in the role that security must play in today ’s environment. To meet this need, TDG has created a three pronged approach to effect this sea change within Federal organizations: Process - TDG has created a proprietary security life cycle that integrates the previously unrelated and complex security requirements into a comprehensible and comprehensive approach to security. We apply this security life cycle in all our engagements. Cultural Change/Education – TDG, working with our academic partner, the Indiana University of Pennsylvania (IUP is NSA certified Center for Academic Excellence in Information Assurance Education), has developed a course that addresses the need for cultural change. Based on the NSA ’s CNSSI-4012 Standard for National Information Assurance Training Standard For Senior System Managers, the course uses the TDG Security Life Cycle to tie the disparate “guidance ” senior managers receive into a roadmap for developing an information assurance program. Performance Metrics – Tremendous resources are required to conduct security assessments and create C&A packages. Unfortunately, these efforts do not leave behind actionable metric data that senior government managers can use to manage and effect changes in the security posture of their organizations. TDG has developed a tool (System Security Scorecard (S-3)) to address this shortcoming that not only streamlines the assessment/C&A process but also provides a database of actionable security information that speeds the C&A process and also provides FISMA reporting data in an automated fashion. TDG understands the balance that a manager must maintain between operational needs and security requirements to protect key IT assets. We also understand that most federal agencies are spending two to three times what they should be spending on information security. Our goal is to “right-size ” that expenditure and ensure that federal agencies are developing risk-based, cost effective, adequate security programs. TDG has developed and/or reviewed over 250 site and system accreditation packages for the U.S. Army, Department of Housing and Urban Development, and Department of Commerce. TDG has taught the SSM course at the FAA ’s William J. Hughes Technical Center in Atlantic City, NJ and is currently also using the S-3 tool in support of our efforts at the technical center. The TDG staff credentials include Business Continuity Planning certification, CISSP certification, MS Security Certification, NSA ’s Information Assessment Methodology certification, the Army ’s IAM and IASO qualifications, and extensive experience staffing and operating help desk and security operations.