Cyberspace and its underlying infrastructure are vulnerable to a wide range of risk stemming from both physical and cyber threats and hazards. Craig’s Cybersecurity Engineers and Analysts use an agency and mission-based approach that supports the architectural methodology in NIST Special Publication “Managing IT Security Risk” (SP 800-39). Our cyber-security teams meet current Risk Management Framework and DoD 8570 requirements via the CISSP, CompTIA, Sec+ CE certification process and conduct Information Systems vulnerability assessments, risk mitigation, and Plan of Action and Milestone (POA&M) development and tracking.
Craig Personnel are certified to perform active threat assessment and penetration testing under DIACAP and RMF controls. DIACAP/RMF is the DoD Information Assurance Process to ensure risk management is applied to Information Systems.