Information System Security Officer
Current• Lead congressional system through Authorize to Operate by categorizing the information system and applying allocated, inherited and hybrid security controlso Ensure that the Information Technology Security Directive 5-410.1, FIPS, and NIST policies are followed to categorize and protect the CIA triad (Confidentiality, Integrity and Availability) of the congressional system.o Responsible for leading the congressional system through Authorize to Operate (ATO) using the System Development Life Cycle (SDLC) and the Risk Management Framework (RMF) requirements with the guidance of NIST SP 800-37 Rev 1.o Produce and propose a Work Breakdown Structure using MS Project encompassing all security related tasks to the Authorizing Official.o Provide bi-weekly briefings to the LOC Chief Information Security Officer (CISO) and weekly meetings with the System Owners.o Categorize the congressional system based on PII contents according to FIPS 199 and record it on Archer.o Conduct a Privacy Threshold Assessment (PTA) and a Privacy Impact Assessment (PIA) interview with the Information System Business Owner (ISBO) to classify the sensitivity of PII data.o Identify Common Controls to generate a Security Requirements Traceability Matrix (SRTM) and proceed with the selection of Security Controls for the congressional system utilizing NIST SP 800-53 Rev. 4.o Develop the Data Flow; Network; and Boundary diagrams using MS Visio, as part of the System Security Plan (SSP) on Archer and uploading supporting documentation on Confluence for a collaboration environment across team members.o Complete the Security Assessment & Authorization (SA&A) by producing a Contingency Plan, Configuration Management Plan, Continuous Monitoring Plan, Incident Response Plan, Security Assessment Plan, Security Assessment Report and other related documentation utilized by the Federal Information Security Management Act (FISMA).