Our mission: Safeguard
Business in Cyber World
KLC Capability Statement
SMAC Software
Brochure
|
KLC profile:
(Qualification)
-
Certification:
8(a) Certified & SDB
-
DUNS#:
128430050
-
CAGE#:
4WEW4
-
NAICS Code: 541512,
541511, 541513,
541519, 511210, 518210
-
Past Performance: DoD, DISA, Veterans Affairs
(VA),
Royal Bank of Scotland,
Boeing, Akamai, HP, CIGNA
|
Core Services:
|
|
|
Qualification |
Description |
|
KLC's Qualification |
KLC Consulting has over 20 years of
Information Security and IT Audit services experience. We have also created the first
network address changer for Windows with over 1.5
million users. Our mission is to enable federal and
state government and fortune 1000 companies to secure
the IT environment and reduce risks. Our experience
covers different industries including government,
defense, financial services, retail and aerospace.
We have DoD
8570.01-M certified
security, IT audit, and privacy professionals including
- Certified
Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Information Systems Auditor (CISA)
- Certified Software
Secure Lifecycle Professional (CSSLP)
- Certified Information Privacy Professionals (CIPP,
CIPP/G)
- Certified ISO 27001 Lead Auditor
- Cisco Certified
Network Professionals (CCNP)
- Juniper Certified
Professionals.
- Security+
- A+
|
|
Services |
Description |
Cyber Security Assessment
(Contact KLC) |
-
Independent Verification and
Validation (IV&V)
-
Help government
and private sectors assess the current state of
information security controls based on the government standards (NIST
800,FISMA, DIACAP,
FFIEC, PCI, HIPAA, GLBA), and industry standards (ISO 27001 / 27002.)
-
Provide expert guidance to
remediate findings
-
Penetration Testing - Networking
and Application
|
DIACAP
Certification & Accreditation (C&A)
(Contact KLC) |
-
KLC and partners have significant
experience and expertise to successfully perform
DIACAP and obtain
IATO / ATO for different DoD agencies including:
-
Army
-
Navy
-
Air Force
-
Marine Corp
-
Provide guidance and approach for
DIACAP
-
Professionals performing
DIACAP meet DoDD
8570.01-M security certification requirements
-
Approach on
DIACAP C&A
-
Conduct STIG, ST&E, PoA&M
during the DIACAP
process
-
Conduct IV&V for projects
(providing no conflict of interests)
-
Prepare
DIACAP package
-
Obtain Interim ATO (IATO) or
ATO
|
Third-Party Service Provider
(Vendor) Risk Management
(Contact KLC) |
Conduct fix cost
third-party service provider security risk assessment
based on ISO 27002 security standards. We strive to
provide our customers the understanding of interdependency risks
with the vendors.
|
Information Security
Engineering
(Contact KLC) |
-
Network Infrastructure,
Application Security, Cloud Computing
-
Setup Intrusion Detection,
Prevention, log analyzer for situation awareness,
and counter-attack systems
-
Research and Development for
Custom Cyber Security Applications
-
Prepare the DIACAP and FISMA
Package for Certification and Accreditation (C&A)
-
Assist the C&A process and obtain
Authorization to Operate (ATO)
-
Assess, design, implement
processes and tools that will
provide continuous analysis, detection, and protection of your information
asset.
(information security
lifecycle)
-
Identity & Access Management
(IDAM)
-
Access / Entitlement Management
-
Mobile Security / Bring Your Own
Device (BYOD) Management
-
Certified engineers in Varonis,
Palo Alto Networks Firewall, Cisco, Juniper,
Microsoft, VMWare
|
IT Audit
/ Regulatory Compliance
(Contact KLC) |
Our certified IT Auditors
help federal and state government, financial and banking
institutions perform compliant assessment, and help
address issues of
the following:
-
DIACAP
-
FISMA
-
NIST 800 Series (800-53, 800-37, 800-37 and more)
-
Privacy Impact Analysis (PIA)
-
Sarbanes-Oxley
(SOX)
-
Gramm-Leach-Bliley
Act (GLBA)
-
Financial Regulations FDIC, OCC, OTS, NCUA, (FFIEC)
-
Payment Card Industry (PCI)
Security Standard
-
Health
Insurance Privacy and Accountability Act (HIPAA)
-
Pharmaceutical
/ FDA (21 CFR
Part 11)
-
Massachusetts State Data
Security Privacy Regulations (201
CMR 17)
|
|