26.03.2016 Views

GSN March 2016 Digital Edition

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Intelleges’ innovative approach helps government<br />

contractors assess their cybersecurity strengths<br />

By Steve Bittenbender<br />

As the federal government now requires<br />

defense contractors to assess<br />

the security of their information<br />

technology systems, a New York<br />

company has come up with an innovative<br />

way to help those companies<br />

evaluate their systems and identify<br />

opportunities for improvements<br />

and enhancements.<br />

Intelleges is a New York-based<br />

company that provides proprietary<br />

software to corporate leaders and<br />

government agencies that need to<br />

collect data and documentation for<br />

a variety of reasons. through a proprietary<br />

solution that allows its clients<br />

to develop customizable questionnaires<br />

and store the results and<br />

<br />

certified cloud-based system.<br />

Last fall, the Department of Defense’s<br />

Federal Acquisition Regula-<br />

<br />

guidelines requiring contractors<br />

and their subcontractors to safeguard<br />

sensitive defense data that it<br />

stores or handles. As defense contractors<br />

began to evaluate how they<br />

were protecting that critical information,<br />

some began reaching out<br />

to Intelleges to help them. That led<br />

to the development of the compa-<br />

24<br />

John Betancourt<br />

Founder, Intelleges<br />

ny’s Stacked Information<br />

Technology Cybersecurity<br />

Assessment Maturity<br />

<br />

<br />

company’s founder, said<br />

the company has been doing<br />

this work for its existing<br />

clients for more than<br />

15 years, but now with the<br />

government’s new regulation<br />

regarding cybersecurity,<br />

it’s essential that all government<br />

contractors – as well as other<br />

organizations that handle sensitive<br />

personal data such as an individual’s<br />

credit cards or personal health records<br />

– get an assessment as quickly<br />

as possible.<br />

As part of the Intelleges’ assessment<br />

system, the company created<br />

a matrix to determine a company’s<br />

strengths when it comes to IT security.<br />

The system, which is based<br />

on the Capability Maturity Model<br />

Integration scale, evaluates companies<br />

across 15 areas related to information<br />

technology. SIT-CAMM<br />

uses NIST and ISO 2700 standards<br />

in developing the questions for the<br />

assessment. Those questions are tailored<br />

specifically for each company.<br />

Among the items SIT-CAMM assesses<br />

includes: a company’s IT usage,<br />

its business process<br />

management, its regulatory<br />

compliance and its<br />

training program.<br />

<br />

software, we can create<br />

and distribute a series of<br />

electronic questionnaires<br />

designed to determine<br />

software, hardware and<br />

network usage, compliance,<br />

mission alignment,<br />

satisfaction levels, usability, and<br />

court<br />

said. “These questionnaires<br />

will provide insight into possible<br />

strengths, weaknesses, opportuni-<br />

<br />

department will need to address.”<br />

Companies then receive a rating<br />

based on where their assessed areas<br />

stand. Companies that are just beginning<br />

to identify their needs may<br />

be assessed at a Level 1, while those<br />

who have fully optimized their departments<br />

may receive a Level 5 rating.<br />

As part of its assessment, Intelleges<br />

will work with companies and identify<br />

ways to improve their scores in<br />

certain areas. That includes developing<br />

recommendations based on<br />

industry best practices. Those recommendations<br />

will help companies

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!