RMF assessment and authorization

We prepare, document, and maintain the evidence a system needs to earn and keep its Authority to Operate.

What the work includes

  • Security control implementation and validation
  • System Security Plans and Plans of Action and Milestones
  • eMASS package maintenance and artifact uploads
  • Transitions from NIST SP 800-53 Rev. 4 to Rev. 5

Frameworks and tools: NIST SP 800-37, NIST SP 800-53 Rev. 5, eMASS

CMMC and NIST SP 800-171 readiness

For contractors that handle Controlled Unclassified Information, we find the gaps, close them, and document the result.

What the work includes

  • Gap assessment against NIST SP 800-171 requirements
  • Control implementation across on-premise and cloud systems
  • System Security Plan, policies, and procedures
  • Remediation tracking through a Plan of Action and Milestones

Frameworks and tools: CMMC Level 2, NIST SP 800-171, DFARS 252.204-7012

Vulnerability and configuration compliance

We scan, assess against the applicable STIGs, fix what the results show, and hand back checklists an assessor can use.

What the work includes

  • ACAS and Tenable scanning, including standalone and air-gapped systems
  • DISA STIG assessments with SCAP and completed checklists
  • Prioritized remediation of critical and high findings
  • Patch deployment validation

Frameworks and tools: ACAS, Tenable.sc and Nessus, DISA STIGs, SCAP

Systems and endpoint administration

Day-to-day administration of servers, workstations, and identity, done by people who also have to pass the audit.

What the work includes

  • Windows Server and Windows 11 administration
  • RHEL and Linux administration
  • VMware vSphere provisioning and lifecycle
  • Active Directory, Group Policy, Microsoft Intune, and Entra ID

Frameworks and tools: Windows Server, RHEL, VMware vSphere, Microsoft Intune, Entra ID

Cloud engineering and security

We design, build, and secure workloads on AWS, and move existing systems there without losing data.

What the work includes

  • Architecture and deployment of production workloads
  • Migrations from legacy hosting
  • Least-privilege IAM policies, security groups, and network controls
  • Automated build and deployment pipelines

Frameworks and tools: AWS, IAM, CI/CD

Data governance and records management

We configure the controls that keep regulated information classified, retained, and prevented from leaving.

What the work includes

  • Microsoft Purview records management configuration
  • Data Loss Prevention policies
  • Retention schedules aligned to DoD and National Archives requirements
  • Safeguards for Controlled Unclassified Information

Frameworks and tools: Microsoft Purview, DLP, NARA requirements

Secure AI integration

We connect large language model services to the systems you already run, with access limited to what each user is allowed to see.

What the work includes

  • Integration of managed model services such as Amazon Bedrock
  • Access controls and least-privilege design for AI features
  • Review of data flows before sensitive information is connected

Frameworks and tools: Amazon Bedrock, IAM

Not sure which of these you need?

Describe the system and the requirement you are trying to meet. We will tell you plainly whether we are the right fit.