|
|
 |
Networking and Security Experience
|
|
KRM has an extensive background providing networking-related services and support. Please review some of our more prominent experiences below.
|
| Department of Veterans Affairs NEBOSS Support |
5/4/2010
|

KRM Associates Inc. has worked with the Department of Veterans Affairs on a series of projects spanning over a decade. These projects have ranged in scope across departmental divisions, and have ranged in nature from healthcare to networking.
Currently KRM provides customer support, network engineering and security engineering for a secure data network for the Department of Veteran Affairs with over 300,000 network customers, functioning through the Network Engineering, Business and Operations Support Services (NEBOSS).
Responsibilities include customer support in configuring, installing, testing, and documenting system architectures and component configurations with routers, Virtual Private Networks (VPN), firewalls, intrusion detection systems, host protection tools, and other Information Assurance products.
KRM provides Tier I/Tier II help desk staffing and support to the Department of Veterans Affairs.
Our current technical support includes:
- Assistance with the installation/configuration of the Cisco VPN client on a Windows OS platform.
- Troubleshooting connectivity issues to the VA gateway via Cisco VPN client / SSL VPN client
- Consolidate (wildcard mask) IP address restriction on VPN client accounts.
- Assistance with the installation/configuration of host based firewall applications as well as host based Antivirus applications.
- Provide assistance for VA sponsored dial-up internet access via Sprint Remote Access for those that do not have Internet access at home. This includes the installation of the dial-up client as well as any connectivity issues a user may experience.
Our staff has utilized the following software/hardware:
- RealSecure Desktop Protector by ISS
- McAfee Virus scan 8.x
- Cisco VPN client version 4.x
- Cisco 3000 Series VPN Concentrators
- Cisco ACS server version 4.0
- Sprint ISP dialer Version 3.5.x
- RealSecure Proventia 8.0 (Host Intrusion Prevention System)
Our engineers configure/manage devices that:
- Proxy/filter outbound web requests.
- Proxy/filter inbound web requests to *va.gov destinations.
- Filter inbound and outbound SMTP.
- Manage DNS for the va.gov zone as well as configure all new inbound web requests which include DNS resolution load balancing, caching, proxying, and content switching.
- Configuring/maintain operational control of Site-2-Site VPN connections, Business Partner Gateway connections, and LAN extensions.
- Configuring/maintaining a local LAN for our primary facility as well as two backup sites.
Experience with the following software/hardware:
- Cisco PIX 506/515/525/535 running code versions 6.3.x as well as 7.x
- Cisco ASA 5540s running code version 7.x
- Cisco Catalyst 4000 and 6500 series switches – routing capabilities, switching capabilities, fire walling capabilities as well as content switching (layers 4 thru 7) capabilities.
- Cisco content engine running Release 5.5.5
- Cisco 2800 and 7200 series routers running code version 12.x
- Cisco Global Site Selector
- Cisco 3000 Series VPN Concentrators
- Cisco ACS server version 4.0 (for client VPN Authentication as well as TACACS authentication)
- Cisco 3550 switches running code version 12.x
- NetCache Appliance running version 6.x
- WebWasher CSM Suite running version 5.x
- F5 Big IP - Application Delivery Solution
- Ironport C600 with code version 5.x
KRM operates a security test and evaluation laboratory to assure that independent testing and assessment can be conducted on appropriate systems and technologies. Additionally, KRM employs the latest in vulnerability scanning, penetration testing, and analysis technologies to assure that the results include the most-current vulnerabilities and remediation methodologies available today.
Security Testing Laboratory:
Provides technical support related to Host Intrusion Protection Systems (HIPS) specifically the IBM/ISS product suite including Proventia and BlackICE. Design and support networks incorporating the following technology areas: Gigabit Ethernet and ATM switches, routers, firewalls, intrusion detection devices, VPNs, and PKI. Identify and resolve security incidents utilizing various security scanners and tools. KRM provides hands-on technical installations and troubleshooting for mission critical HIPS environments, which include HQ and National customer offices. KRM also provides technical support utilizing vulnerability scanners and application of patches including Harris Stat and Patchlink.
|
|
| ENTISAS™ Project Developed for Tri-Care TMA |
5/31/2007
|
KRM developed the ENTISAS™ program successfully for the DOD (Department of Defense)TMA (TriCare Management Activity). This program was delivered 5/31/2007.
ENTISAS (Enterprise Information Security Assessment System) is an Enterprise-wide Information Security repository useful for analyzing security risks, threats and vulnerabilities as well as mitigation plans and protections profiles and other information security elements across multiple organizations and organizational elements.
KRM modified the Enterprise Information Security Analysis System (ENTISAS™) system, based on the Risk Database system originally developed for OCTAVE. KRM has also developed a web-enabled front-end and enhanced security for the ENTISAS™ repository. Additionally, KRM has modified the product to accept data feeds from various vulnerability scanning systems.
Click Here to learn more about ENTISAS™.
This product has been DITSCAP certified. |
|
| VA Network & Security Operations Center (NSOC) |
6/1/2006
|
KRM provided 24/7 support for the Security Operations Center for VA. KRM provided support to monitor computer and network traffic, and analyzed network traffic activity and systems logs to determine causes of problems and security breaches. Additionally, KRM personnel reported and tracked network and system problems, resolved simple computer and hardware problems independently, and coordinated with other IT groups to resolve complex problems and issues. |
|
| VA Health Information Security Division (HISD) Support |
6/1/2006
|
KRM provided support for the Veteran's Administration Health Information Security Division in Martinsburg, West Virginia. The scope of this project included:
An overall goal to establish and operate a world-class HISD that would develop, implement, and evaluate security solutions addressing health data and health information systems, including security standards, access control, and access to health data by external groups.
The VA and other CHIS user organizations established a documented, repeatable, on-going process to measurably improve the security of their sensitive data, and demonstrated its value to its user community by:
- Raising awareness of healthcare specific information systems, to include risks, vulnerabilities, and protection requirements for new and emerging technologies.
- Examining and analyzing vulnerabilities and devising techniques for the cost-effective security and protection of private health information maintained on VHA sensitive system.
- Developing standards, metrics, tests, and validation programs to:
- Promote, measure, and validate security in systems and services.
- Provide system-specific role-based access to staff members.
- Establish minimum security requirements for healthcare systems.
- Developing guidance to ensure security is included in the system planning, implementation, management, and operational phases of the system life cycle.
- Assisting VHA in planning and implementing best security practices.
|
|
| VA Healthcare Information Security Sharing, Analysis, and Assessment Center (HISSAAC) Internet Portal |
11/1/2002
|
KRM utilized extensive experience in healthcare information technology, information security and web development to design and support the implementation of a web-portal for information sharing. The goal of the HIISAAC was to provide the V.A. a medium for enterprise wide sharing of analysis and assessment results to improve decision-making regarding the security risks of medical information systems. |
|
| DOD Defense Health Information Assurance Program (DHIAP) |
7/1/2002
|
KRM provided subcontract support to the Advanced Technology Institute (ATI) in the execution of the Defense Healthcare Information Assurance Program (DHIAP), sponsored by the Telemedicine and advanced Technology Research Center (TATRC) for the U.S. Army Medical Research and Material Command at Ft. Detrick, MD. This program consisted of identifying potential risks and vulnerabilities in the protection of military medical healthcare information, providing recommendations for operational improvements and designing and delivering practical solutions. KRM focused on the development of methodology and metrics for performing technical business case analysis for information assurance technologies and solutions relating both tangible and intangible costs and benefits. KRM efforts involved technologies related to identification, authentication, encryption, auditability and related information security approaches. KRM designed and developed the original data analysis system for Risk Analysis utilizing web-based technology and a Coldfusion front end to an Oracle Database. |
|
| U.S. Army MRMC and TATRC Support |
7/1/2001
|
KRM performed an analysis of the application of the U.S. Army Medical Research and Material Command (USAMRMC), Telemedicine and Advanced Technology Research Center (TATRC) developed Organizationally Critical Threat and Vulnerability Evaluation (OCTAVE) process for application to the VA healthcare system. The analysis included a review of lessons learned within DOD healthcare and comparison of the environment and challenges within DOD to those applicable to the VA environment. Also included analysis of the Risk Information Management Resources (RIMR) and the Risk Database (RDB) system that stores information on multiple OCTAVES. This technology is based on an Oracle database and supports analysis of multiple solutions designed for data gathering. |
|
| West Virginia Healthcare Data Information Sharing |
6/1/2001
|
KRM was contracted by the WV Healthcare Authority to develop healthcare information sharing policies, procedures, and systems for HCA's data sharing efforts pertaining to the private sector. This effort compliments the current public sector healthcare information that HCA has compiled and will provide more comprehensive information. This effort is intended to result in the establishment of a pilot project with the participants being the organizations sharing the data. |
|
|
|
|
|