Services
Federal Assessments
The Federal Risk and Authorization Management Program (FedRAMP) is a government program that mandates stringent security requirements that cloud service providers (CSPs) must meet to sell cloud services to the Federal Government under an approved FedRAMP Authority to Operate (ATO). ConMon Solutions provides advisory and readiness services to companies seeking a FedRAMP ATO. Services provided include a capability assessment and security documentation including policies and procedures, security plans, and other required documentation.
RMF Process Mitigation
The Risk Management Framework (RMF) is generally associated with the NIST SP 800-37 guide for “Applying the Risk Management Framework to Federal Information Systems describes the process that must be followed to secure, authorize, and manage IT systems. RMF defines a process cycle that is used for initially securing the protection of systems through an Authorization to Operate (ATO) and integrating ongoing risk management (continuous monitoring).
- Assessor/assessment team selected
- Security and privacy assessment plans developed
- Assessment plans are reviewed and approved
- Control assessments conducted in accordance with assessment plans
- Security and privacy assessment reports developed
- Remediation actions to address deficiencies in controls are taken
- Security and privacy plans are updated to reflect control implementation changes based on assessments and remediation actions
- Plan of action and milestones developed
Privacy Assessments
The Federal Risk and Authorization Management Program (FedRAMP) is a government program that mandates stringent security requirements that cloud service providers (CSPs) must meet to sell cloud services to the Federal Government under an approved FedRAMP Authority to Operate (ATO). ConMon Solutions provides advisory and readiness services to companies seeking a FedRAMP ATO. Services provided include a capability assessment and security documentation including policies and procedures, security plans, and other required documentation.
Cloud Security Assessments
The Cybersecurity Maturity Model Certification (CMMC) builds on the existing NIST SP 800-171 and requires a CMMC Third Party Assessment Organization (C3PAO) attestation. The CMMC is a new framework targeting DoD contractors with the objective of ensuring that companies in the defense industrial base (DIB) supply chain are securing federal contract information (FCI) and controlled unclassified information (CUI) that is stored, processed, or transmitted. ConMon Solutions provides assessment readiness services to contractors seeking CMMC certification. Services include a CMMC pre-assessment that maps your existing security controls to the anticipated CMMC model, a detailed GAP Analysis and documentation preparation.
Payment Card Industry Assessments
The Federal Risk and Authorization Management Program (FedRAMP) is a government program that mandates stringent security requirements that cloud service providers (CSPs) must meet to sell cloud services to the Federal Government under an approved FedRAMP Authority to Operate (ATO). ConMon Solutions provides advisory and readiness services to companies seeking a FedRAMP ATO. Services provided include a capability assessment and security documentation including policies and procedures, security plans, and other required documentation.
Financial Services Assessments
The Cybersecurity Maturity Model Certification (CMMC) builds on the existing NIST SP 800-171 and requires a CMMC Third Party Assessment Organization (C3PAO) attestation. The CMMC is a new framework targeting DoD contractors with the objective of ensuring that companies in the defense industrial base (DIB) supply chain are securing federal contract information (FCI) and controlled unclassified information (CUI) that is stored, processed, or transmitted. ConMon Solutions provides assessment readiness services to contractors seeking CMMC certification. Services include a CMMC pre-assessment that maps your existing security controls to the anticipated CMMC model, a detailed GAP Analysis and documentation preparation.
Healthcare Assessments
The Federal Risk and Authorization Management Program (FedRAMP) is a government program that mandates stringent security requirements that cloud service providers (CSPs) must meet to sell cloud services to the Federal Government under an approved FedRAMP Authority to Operate (ATO). ConMon Solutions provides advisory and readiness services to companies seeking a FedRAMP ATO. Services provided include a capability assessment and security documentation including policies and procedures, security plans, and other required documentation.
SOC Examinations
The Cybersecurity Maturity Model Certification (CMMC) builds on the existing NIST SP 800-171 and requires a CMMC Third Party Assessment Organization (C3PAO) attestation. The CMMC is a new framework targeting DoD contractors with the objective of ensuring that companies in the defense industrial base (DIB) supply chain are securing federal contract information (FCI) and controlled unclassified information (CUI) that is stored, processed, or transmitted. ConMon Solutions provides assessment readiness services to contractors seeking CMMC certification. Services include a CMMC pre-assessment that maps your existing security controls to the anticipated CMMC model, a detailed GAP Analysis and documentation preparation.
Third Party Risk Assessments
The Federal Risk and Authorization Management Program (FedRAMP) is a government program that mandates stringent security requirements that cloud service providers (CSPs) must meet to sell cloud services to the Federal Government under an approved FedRAMP Authority to Operate (ATO). ConMon Solutions provides advisory and readiness services to companies seeking a FedRAMP ATO. Services provided include a capability assessment and security documentation including policies and procedures, security plans, and other required documentation.
Vulnerability Assessments
The Federal Risk and Authorization Management Program (FedRAMP) is a government program that mandates stringent security requirements that cloud service providers (CSPs) must meet to sell cloud services to the Federal Government under an approved FedRAMP Authority to Operate (ATO). ConMon Solutions provides advisory and readiness services to companies seeking a FedRAMP ATO. Services provided include a capability assessment and security documentation including policies and procedures, security plans, and other required documentation.
Cybersecurity Assessments
The Cybersecurity Maturity Model Certification (CMMC) builds on the existing NIST SP 800-171 and requires a CMMC Third Party Assessment Organization (C3PAO) attestation. The CMMC is a new framework targeting DoD contractors with the objective of ensuring that companies in the defense industrial base (DIB) supply chain are securing federal contract information (FCI) and controlled unclassified information (CUI) that is stored, processed, or transmitted. ConMon Solutions provides assessment readiness services to contractors seeking CMMC certification. Services include a CMMC pre-assessment that maps your existing security controls to the anticipated CMMC model, a detailed GAP Analysis and documentation preparation.
