Security Consulting
The Systems Security Life Cycle begins with the development of security
policies, procedures, and then security plans. Cynergy's security consulting services assist organizations in establishing
these foundational components. Cynergy can provide services at the CSO, CIO, DAA, ISSM, ISSO levels.
Risk Assessments
Risk assessments and penetration testing are performed by Cynergy in the
areas:
- Computer Security (both network and host based assessments)
- Operational Security
- Personnel Security
- Physical Security
Certification
and Accreditation Services
Cynergy offers our government customers C&A services using DITSCAP,
DoD 8500 Series, DCID 6/3, NIACAP, NIST 800 series, FISMA or HIPAA processes. These activities include:
- Security policy, requirements, and plan development
- SSAA or SSP development and maintenance
- Risk assessments
- Security Testing and Evaluation
- Certification Testing and Evaluation
- Development of statements of residual risk
Cynergy also has a wide variety of assessment tools available to our customers.
These tools can be specifically tailored to a customer's particular needs.
Security
Engineering
Cynergy performs security engineering services in the areas of security
requirements development, security analysis, security architecture design and implementation, and testing and evaluation.
Cynergy understands security engineering to be a function of the overall
engineering process and therefore seeks to integrate security solutions into the customer's systems life cycle, rather then
viewing it as an external process:
Security engineering services focus on the mitigation of risk relative
to confidentiality, integrity, availability and accountability. To that affect, solutions are designed around:
- Protection controls
- Detection mechanisms
- Correction solutions
Confidentiality solutions can include: cryptographic
solutions such as TACLANES, symmetric key encryption solutions (such as KG's), Electronic Key Management System support (EKMS),
Communication Security to include the implementation of STU's and STE's), VPN solutions, guard support (particularly in the
area of guard SSAA preparation), PKI implementation support
Integrity solutions would include the above mentioned
protection mechanisms, but will additionally include support for system baseline, and evaluation, data base security support,
virus protection controls
Availability solutions include support for the development
of contingency plans, system evaluation for criticality, back up and restore, hot site support, contingency training
Accountability solutions involve the robust development
of access control mechanisms to include biometric solutions, token based solutions, PKI, design and implementation of role
based access controls.
Technologies: The Security Engineering department of
Cynergy employee’s professionals who specialize in technologies protecting computing environment, the boundary enclave,
the networking environment and supporting systems. This includes a wide range of products; to include the most commonly used
products such as CISCO, Checkpoint, Sidewinder, Radiant Mercury and so forth...
Information Security Training
Cynergy has a dynamic, experienced, and knowledgeable training group that
stands ready to provide those courses our customers need. Courses can be tailored to fit the specific focus of specific organizations,
or courses can be offered to mixed audiences on a general level.