Security Assessment & Authorization

  • Home
  • Security Assessment & Authorization

Security Assessment & Authorization

DGC provides full-spectrum Security Assessment and Authorization (SA&A) services to help federal agencies achieve, maintain, and renew Authority to Operate (ATO) for systems across a range of impact levels. Our team of security control assessors (SCAs), system security engineers, and RMF practitioners guide clients through each phase of the Risk Management Framework (RMF) as defined in NIST SP 800-37 Rev. 2, ensuring that security documentation, control implementation, and evidence collection meet federal and agency-specific standards. DGC supports system categorization, control selection, control implementation review, and the execution of security control assessments (SCAs) in preparation for ATO package submission.

We integrate automation, eGRC tools, and compliance-as-code techniques where possible to streamline documentation, improve traceability, and support continuous authorization efforts. Our team is experienced with ATO efforts for cloud-based, hybrid, and on-premises environments, including FedRAMP, High Value Assets (HVAs), and cross-domain solutions. Whether managing a new system accreditation or renewing a complex enterprise authorization, DGC delivers SA&A services that are technically sound, documentation-rich, and strategically aligned with mission risk tolerance. Our approach ensures that federal systems are not only compliant, but secure, resilient, and ready to support operational goals.

Past Performance

At the FDA, DGC was selected as the IT consulting partner that would help to address significant security deficiencies that were identified during a federal audit and had drawn the attention of Congress. The DGC team built out a project schedule to conduct security assessments on 110 FDA systems in order of importance, starting with any systems that had fallen out of compliance and had an expired Authorization to Operate (ATO), followed closely by FDA High-Value Assets (HVAs) and systems with High Federal Information Processing Standard 199 (FIPS-199) security categorizations. Our targeted approach to security assessments allowed the FDA to rapidly return to full ATO compliance for all systems and gave them confidence that their most important data was protected at the highest level. DGC developed and implemented an efficient and sustainable work cycle to support the FDA’s Security Authorization (SA) process.