|
Past Performance
Customer: Air Force Personnel Center
Type of Service: Consulting and Technical Security Support
For the Personnel Data System (PDS)
Overview: : EADS North
America Defense Security and Systems Solutions, Inc. (DS3)
provided in-depth analysis of Internet Security Systems’ (ISS)
Internet Scanner reports of AFPC’s Automated Information
Systems, and also evaluated ISS Internet Scanner policies
used at AFPC and recommended changes to eliminate false positive
indications. We developed security documents (SSAA) for legacy
and new civilian and military systems including Personnel
Data System (PDS), the Military PDS modern system, the Department
of Defense Civilian Personnel Data System (DCPDS), the Integrated
Component Employee Benefits System (ICBES) and other Air
Force or DoD client-server, web based or interactive voice
response personnel data systems as tasked. We reviewed and
updated security documents and provided security test and
evaluation support. We provided technical support in the
evaluation of security products. We developed information
system security staff studies and reports that addressed
areas of information system security concerns associated
with life-cycle support. We provided technical support to
develop, maintain, and document state of the art secure windows
based LAN resident applications, as well as World Wide Web
pages in support of personnel systems as required by AFPC,
the Air Force or DoD users. We developed, reviewed and updated
Command, Control, Communications, Computers and Intelligence
Support Plan (C4ISP) program management support documents.
We provided technical experience to the small Computer and
Web Based Applications Development section by identifying
and recommending security features and/or procedural guidelines
to minimize risks to the small computer and web based applications,
to help them develop, maintain and document secure Windows
based LAN resident applications, as well as World Wide Web
pages. We determined the interface, process, communications,
support system and integration requirements needed to sustain
current solutions and provide security input for new Small
Computer and Web Base Applications development. We also performed
configuration management duties, hands-on security training
to Government as required, provided technical expertise to
security working groups and assisted in identifying and recommending
security features and/or procedural guidelines to minimize
risks to the data processed by personnel data systems. Typical
support services provided include:
- Performed DITSCAP Certification process on legacy and new
information systems
- Assisted in the development of required security documentation
in order to achieve Air Force Certificate of Networthiness
and Major Command Certificated to Operate
- Provided security engineering and technical expertise to
include Security, Test and Evaluation, countermeasure implementation,
vulnerability evaluations, issue resolution, patches and
applications
- Provided systems, network and hardware technical security
support in implementing hardware/software solutions to enhance
the overall system security posture
|