Oceus provides a Risk Management Framework (RMF), a duplicate testing system to conduct complete security posture reviews of all networking appliances, security concentrators, firewalls, and other virtual machines.
Oceus will define the security baseline and provide the list of Security Technical Implementation Guides (STIGs) and other security settings required for fielding. Oceus engineering staff will use the RMF to test the operational impacts of the STIG process and ensure the network remains usable throughout the process. Our engineering staff will validate and document required network changes and Methods of Procedure (MOPs) to update configuration data to the Solution baseline. Oceus will perform an initial STIG checklist review of all identified components to start a STIG validation report. This effort becomes the starting point of the STIG process.
Oceus creates a STIG baseline and begins applying the STIGs to patch all the Category (CAT) I vulnerabilities. Patches are applied, and Oceus proceeds to the CAT II and CAT III vulnerabilities. Oceus provides feedback on all outstanding CAT IIs and CAT IIIs not patched due to operational implications or if they hinder system operations. Oceus provides the customer sponsor with a STIG mitigation plan for all unpatched or open vulnerabilities to aid in answering the RMF checklist. Oceus will also provide input to the Customer Plan of Action and Milestones (PoAM) documentation.