| Certification & Accreditation for the VHA |
|
|
|
|
VetsAmerica was a subcontractor to STG, Inc. and assisted in completing Security Certifications and Accreditations (C&As) on the Veterans Health Administration’s systems in accordance with the NIST SP800-37 and 800-53 Guidelines, and the Certification and Accreditation processes.
The firm participated in three different phases of the project, which performed C&As on over 140 VA Medical Centers (VAMC) across the nation. In the first phase, VetsAmerica's focus was on field data capture for system testing requirements and policy reviews, interviews with Information Security Officers, and providing testing results to the Point of Contact. In this phase, VetsAmerica staff served as team leads of field data capture teams. In the second phase, VetsAmerica participated in the analysis and summarization of the test results and the development of final reports for each VAMC. In the third phase, VetsAmerica assisted in aggregating metadata across VAMCs and analyzing trends in various testing results to identify systemic problems across the VA and in individual VA information system networks. As part of this phase, VetsAmerica also performed a gap analysis between 800-53 and 800-53A to identify areas in which testing procedures needed to be updated for emerging NIST requirements.
|














