Customers

Customer Case Studies –

   
Management consulting

   Information Assurance

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 



Case Studies

Information Assurance (IA) Customers


With over 30 years of experience, Carson's services are sought after by both government and industry. Representative samples of our IA contracts are showcased below.



HHS Security Engineering & Architecture

 

In August 2010, Carson Associates won a competitive contract to provide IT support to HHS in the following three focus areas:

  • FISMA IT security program support and oversight support for the CISOs for three HHS operating divisions
  • Enterprise security engineering policy and technical implementation
  • Security architecture planning


NIH
 

For NIH, Center for Information Technology (CIT), Carson provides IT security program management support services including the following:

  • System certification and accreditation (C&A)
  • Training
  • Development of policies and procedures
  • Continuous monitoring including POA&M oversight and validation
  • Vulnerability assessment and penetration testing
  • Incident response and forensics
  • FISMA compliance and reporting



OPM
 

Carson Associates provides IT security support services to support the OPM/EHRI IT Security Program including the following:

  • System certification and accreditation (C&A)
  • System annual security controls testing
  • Training
  • Enterprise architecture support
  • System development life cycle (SDLC) support
  • Management of POA&M
  • Policy and procedures development
  • Security program compliance reviews



NRC
 

Carson Associates has conducted independent FISMA audits/evaluations of NRC’s information security program on behalf of the Inspector General to assess its compliance with FISMA. The Carson team performed an in-depth review of the agency’s security policies and procedures, agency self-assessments, agency certification and accreditation process, system owner security practices and control techniques, privacy processes and controls, testing of system security controls, and plan of action and milestones (POA&M) process.

Internal and external vulnerability assessment scans and penetration testing were performed, using the SAINT® network vulnerability security assessment tool to identify network vulnerabilities that could be exploited.



NIH
 

Carson Associates has been providing IA services to NIH for the past 15 years. Through the NIH BPA (#HHSN263201000005B), Carson Associates provides IT security program support services for 27 NIH institutes and centers including the following services:

  • System certification and accreditation (C&A)
  • Security training
  • Development of policies and procedures
  • Continuous monitoring including POA&M oversight and validation
  • Vulnerability assessment and penetration testing
  • Incident response and forensics
  • FISMA compliance and reporting



Commercial Customers

 

 

Carson Associates has provided the following IA services for numerous commercial customers:

  • PCI DSS assessments
  • IT security program gap analysis
  • Penetration testing
  • Vulnerability assessment scanning
  • Web application testing
  • Social engineering
  • IT security policy development

Commercial customers have included Duquesne Light, SharpBanc, Congressional Bank, Encore Marketing International, eCommLink, Hanover Hospital, Advanced Radiology Solutions, Retail Data Systems, and more.