Information System Security Professional
CurrentAs a Defense Counterintelligence and Security Agency (DCSA) (formerly Defense Security Service) Information Systems Security Professional (ISSP), I perform the following:* Review, validate, and verify contractor Information System Security Plans, supporting documentation, and evaluating computer systems for accreditation of contractor information systems to process Federal Information following the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF). I provide the Authorizing Official (AO) with a recommendation to issue either an Authority to Operate (ATO) letter or a Denial ATO (DATO) letter. In RMF this is the Security Control Assessor role in RMF.* Lead and conduct on-site oversight visits of contractor facilities for Security Vulnerabilities Assessments (SVA), reviewing Continuous Monitoring documentation, and other supporting documents as well as interviewing Facility Security Officers, Information System Security Managers, Information System Security Officers, and System Administrators.* Conduct Administrative Inquiries regarding information spills; this is typically when information of one level of classification has been introduced to a computer system at a different clearance level. These investigations include gathering the facts, conducting reviews of the events, as well as providing cleanup details to the organization that committed the spill.* I meet with company officials from corporate leadership, to managers, to front office staff and I have effective communications with everyone.* Conduct operating system reviews per Security Technical Implementation Guidelines (STIG) using DoD tools such as Security Content Automation Protocol (SCAP) Compliance Checker (SCC) and STIG viewer.* Collaborated on a pilot program developing guidance for ISSP’s (agency-wide) to analyze Controlled Unclassified Information (CUI) located throughout Industry.