The Lever Group can assist in developing your IT Security Controls. Our focus is on developing replicable and
effective processes to ensure that your agency’s controls are minimizing risk in your IT systems. Because The Lever
Group has extensive experience integrating National Institute of Standards and Technology (NIST) security guidance and
the Capital Planning and Investment Control (CPIC) process, we can offer the unique knowledge and skills necessary to
address your IT security needs.
The Lever Group Approach
To assist you and your agency, The Lever Group uses a comprehensive approach to identify areas of improvement in
your IT Security Controls.
The unique feature of The Lever Group approach is the attention paid to continuous monitoring of your IT Security
Controls to ensure that they are working as intended. We work with you to develop a process that addresses the security
and privacy needs specific to your agency. By working with you, we emphasize the necessity of making IT security and privacy
an ongoing process, internalized by the agency.
The Lever Group views IT security as being integrated with the CPIC cycle, not standing alone. Each phase of the
investment life cycle has different requirements that must be met before moving on to the next phase. All too often,
security is an afterthought. Addressing security controls after a program has been initiated allows unwanted holes to develop.
By creating a continuous monitoring structure, The Lever Group is able to integrate the required security controls
into your agency’s CPIC cycle. This integration ensures that all new security and privacy programs are developed early
in the planning process, thereby reducing the possibility of problems later in the life cycle.
Our experience positions us to help your agency develop the required documentation for successful OMB reporting using our
“Quick-Start” approach. Developing the IT Security and Privacy component is an integral part of the QuickStart process.
Our understanding of the various OMB requirements allows us to offer the necessary guidance to develop your IT Security and
Privacy program and its related OMB documents.
For more information about our Security Controls services, please review our
Security Controls Capabilities Brief
|