Develop audit scope and objectives, analyzing systems for general IT and security controls.
Implement frameworks and standards using NIST Cybersecurity framework, FERA, HIPAA, ISO 27001.
Implement RMF (Risk Management Framework) process for system accreditation.
Implement Sensitive Compartmented Information (SCI), Special Access Program (SAP) activities to meet NIST cybersecurity requirements for system assessment and authorization.
Develop risk assessment framework and conduct annual IT risk assessment.
Perform GAP assessment, mapping security requirements and implement complex IT management system.
Conduct business impact analysis and critically assessment for new projects and derive security deliverables.
Perform vulnerability scan, penetration testing, security operation procedure review, third part assessment.