IT Security Compliance
Delivering Results that Safeguard Valuable IT Assets.
Macfadden helps clients develop aggressive and dynamic security programs to ensure IT systems are certified, accredited and properly authorized for production. We provide federal clients with direct support to Information Systems Security Officers (ISSO) in the development and implementation of IT security policies and procedures that ensure compliance with OMB/NIST and FISMA guidelines. Our team of security experts helps clients assess risks and vulnerabilities, establish security management policies and procedures and contingency/operations plans and obtain required Certification & Accreditations (C&A).
Areas of Expertise
- Risk & Vulnerability Assessment
- Security Policy Development
- FISMA Compliance
- Certification & Accreditation
- Independent Verification & Validation (IV&V)
- Disaster Recovery
- Contingency Planning
Success Stories
U.S. Food and Drug Administration
On behalf of the FDA, Macfadden managed a large-scale project to bring the Center for Food Safety and Applied Nutrition’s (CFSAN) IT systems and applications into compliance with a basic security framework while establishing a compliant, well-managed security program. Macfadden drafted, coordinated, edited and finalized more than 500 system documents, policies and procedures. Macfadden developed all of the related IT Policies and Procedures to effect the requirements of NIST 800-53 where specific FDA guidance was not provided.
Macfadden participated in establishing the Agency’s overall Systems Development Life Cycle (SDLC) framework and assisted CFSAN system owners and administrators in performing FISMA evaluations. As part of this project, Macfadden prepared risk analyses, contingency plans, certifications and accreditations as well as annual Privacy Act verification.
Our team at FDA has performed more than 80 Certifications & Accreditations (C&A) for over fifteen systems in two FDA Centers and have automated the complex NIST 800-53 checklist and linked this to the NIST 800-60 Risk Assessment as well as the FIPS 100 and FIPS 200 requirements as a unified package.
As a result of Macfadden’s known capabilities, expert knowledge and reputation at FDA, CNI Information Technology, LLC, selected Macfadden as the prime subcontractor for their $100 million five-year contract to assist in establishing a “Gold Standard" security program within FDA. Leading the effort, Macfadden serves in an advisory role to key Chief Information Security Officer (CISO) staff and developed many of the supporting processes involved in ensuring that over one hundred FISMA-eligible systems at FDA meet all the requirements of NIST SP 800-53.
U.S. Peace Corps
Helping promote world peace and friendship, Macfadden’s IT team developed IT security documentation to ensure appropriate policies, guidelines and procedures were in place to maintain the confidentiality, availability and integrity of the Peace Corps' automated information system.
U.S. Department of Defense (DoD)
Supporting the Office of the Inspector General (OIG), Macfadden provided a comprehensive virtual private network (VPN) allowing remote users to connect to OIG's local area network. Utilizing Fiberlink's VPNterprise, the system enables secure and reliable global access for more than 1,200 simultaneous users, allowing for remote management and a 24/7 help desk.


Macfadden continues to support emergency preparedness efforts as a part of USAID's Stamping Out Pandemic and Avian Influenza (STOP AI) team. 





