Wednesday, October 15, 2008

IA is being asked to do more

Information Assurance is the catch-all for security. The IA team polices everything from facility security violations to role-based access to sensitive data in a database.



IA is infamous for stalling a project in the 11th hour to blow all budgets and deployment schedules. Today, IA spreads the message loud and clear to include IA in all meetings and all thoughts regarding the products and requirements that we are working on. Think of IA in your designs and in your schedules to allow time for STIG'ing (security scans of hardware and software configurations) and ATO (Authority To Operate) paperwork to be filed.

In addition to managing the concerns about allowable versions of software on military networks (JTF-GNO), IA scans the Ports and Protocols (PnP) to ensure proper firewalls, DMZ (De-militarized Zone), MAC (Mission Assurance Category), and proxy servers.

Recent domains issues cover the privacy concerns of data:
  • PII (Personally Identifiable Information)
  • PKI (Public Key Information)
  • PHI (Protected Health Information, Health Insurance Portability and Accountability Act- HIPAA)

With the broad scope of concerns that IA is concerned with, IA has not been responsive to daily requests for information or attendance to meetings. IA still engages in the 11th hour with a heroic effort to verify the designs, documentation, and configuration.


Information Assurance members should have CISSP (Certified Information Systems Security Professional) certification to ensure their familiarity with the CBK (Common Body of Knowledge) and the current resources to manage:

  • CIA triad (confidentiality, integrity, and availability)
  • the ten domain areas of interest
  • access control
  • application security
  • cryptography
  • information security
  • risk management
  • operations security
  • physical security
  • security architecture and design
  • telecommunications
  • network security

No comments:

Program Manager

As a technical leader, I develop a talent pipeline that can deliver client's expectations in a motivating and productive environment.

I have performed multi-discipline engineering on space launch vehicles, satellite command and control software, electronic medical records, and large data center operations.


I am seeking additional opportunities to deliver solutions internationally

resume MBA-Bard Center


I have delivered management and technology consulting solutions for Deloitte, BearingPoint, Department of the Interior, TRICARE Military Health System, Defense Information Systems Agency (DISA), Raytheon, Lockheed, Northrop, and Boeing on various projects in manufacturing, software development, systems engineering, testing, and ITIL management.