Independent Verification and Validation: 640 Controls, Unbiased
A six-month tiger-team IV&V assessment of the FBI’s classified mobile solution against National Security System policies and directives.
Federal Bureau of Investigation
In support of the FBI’s classified mobile program, Emerging Tech was requested to conduct an Independent Verification and Validation (IV&V) assessment of the current classified solution. The assessment was conducted rigorously by a tiger team for a 6-month period to ensure the solution was in compliance with National Security System (NSS) policies and directives.
What the Work Delivered
- Analyzed over 600 individual security controls, then developed remediations to mitigate the open security findings.
- Collected and documented over 200+ individual pieces of evidence including, architecture, configuration settings, profiles, reports, SOPs, TTPs etc.
- Created a comprehensive classified report of all findings, including a get-well plan, and debriefed FBI’s senior leadership, including the Chief Information Officer (CIO) & Associate Deputy Director (ADD).
How We Delivered It
End-to-End Testing
Developed & implemented end-to-end testing process including a tailored test plan, individual test cases, government acceptance process, remediations, and periodic retesting schedule.
Dedicated On-Site Team
Deployed a dedicated on-site team that consisted of engineers, auditors, administrators, testers, quality assurance personnel, and technical team leads.
Network Security Testing
Executed network security testing across multiple demilitarized zones (DMZs) to collect security evidence from firewalls, routers, switches, gateways, and other network devices.
Code Review
Performed security code reviews of commercial applications using a code analysis tool to identify flaws, and then shared results with government leads.
Vulnerability Assessment
Conducted vulnerability assessments and penetration testing to identify weaknessess in the implemented security controls and documented get-well plans to assit in remediation efforts.
Controls Testing
Created a detail-oriented IV&V approach that tested 640 individual security controls resulting in the identification of 85 unique security vulnerabilities, and then collaborated with vendors to implement individual mitigation plans.
Final Assessment Report
Generated the final IV&V assessment report which provided an unbiased evaluation, and identified all critical, high, and medium risks that needed to be addressed to protect the FBI’s classified data.
Have a Program that Looks Like This One?
Let’s talk about how we can help.