Earth Resources Technology, Inc. (ERT)
3 services found

Earth Resources Technology, Inc. (ERT) services

Cybersecurity Services

Security Policy and Planning Services

ERT assists in development, review, and maintenance of system security plans, policies, procedures, and best practices; conducts annual testing of contingency and disaster recovery procedures; develops IT security documentation for system security plans, disaster recovery, and continuity of operations plans; provides expert advice and recommendations based on the National Institute of Standards and Technology (NIST)`s Special Publication (SP) 800 series, Federal Information Processing Standards (FIPS), and industry best practices.

Assessment and Authorization Services

ERT performs system testing and evaluation to assess the security posture of information technology systems; conducts vulnerability scans; performs compliance scans; assists ISSO to mitigate system risks and remediate vulnerabilities; manages the Assessment and Authorization (A&A) process for High and Moderate systems and applications per NIST guidance; develops and maintains A&A documentation; reviews for completeness and compliance with security policies, procedures, and guidance; develops and tracks all Plans of Action and milestones to ensure the highest level of security posture is maintained; and performs independent assessments of security controls for applications and systems.

Security Implementation Services

ERT develops, implements, and maintains an IT security program consistent with Federal laws and agency regulations, policies, procedures, and standards; ensures implementation of all organizational security policies, plans, and procedures; designs, implements, and integrates controls to meet security requirements within the risk management framework; evaluates new security technologies and applications, and recommends change options to the information system owner; applies robust configuration management and change control processes; ensures distribution, tracking, and timely implementation of approved security alerts, patches, and bug fixes; and delivers secure and compliant cloud solutions integrating existing agency architecture with that of service providers.