WINSTON & MILLER

Services

Six services that earn the ATO and keep it.

Every service is led by a 30-year DoD information assurance practitioner. Each one feeds the same outcome: a system your authorizing official can sign for.

RMF Assessment & Authorization

We take systems from categorization to a signed authorization decision under DoDI 8510.01 and NIST SP 800-37.

  • System categorization and control selection (CNSSI 1253, NIST SP 800-53 Rev. 5)
  • System Security Plan, Security Assessment Report support and Plan of Action & Milestones
  • ATO, IATT and reauthorization packages built and managed in eMASS
  • Assessor and authorizing official coordination through to the decision

ISSO and ISSM support

Qualified security officers who own the system's security posture day to day.

  • Information System Security Officer and Manager staffing, full-time or surge
  • DoD 8140-qualified personnel
  • Security impact analysis for configuration changes
  • Incident reporting, audit review and account management oversight

NIST SP 800-171 and CMMC readiness

Readiness for defense contractors that handle Controlled Unclassified Information.

  • Gap assessment against all 110 NIST SP 800-171 Rev. 2 requirements
  • System Security Plan and POA&M development
  • SPRS score calculation, submission and annual affirmation support
  • Preparation for Level 2 self-assessment or third-party assessment

Continuous monitoring and vulnerability management

The work that keeps an ATO current between assessments.

  • ACAS/Nessus scan analysis and remediation tracking
  • DISA STIG and SRG compliance review
  • POA&M burn-down and eMASS record upkeep
  • Ongoing authorization and cATO readiness

Policy and documentation

Policies and procedures written to the control and ready for assessor review.

  • Cybersecurity policy and procedure sets mapped to NIST SP 800-53
  • Incident response, contingency and configuration management plans
  • Interconnection agreements and system boundary documentation

Role-based training

Training that fits the role, not a checkbox.

  • Security awareness training for system users
  • Role-based training for administrators and privileged users
  • ISSO onboarding and desk procedures

Teaming, subcontracting or a direct award

Primes and program offices can request a capability statement, past performance detail and labor category alignment.

Request a capability statement