Federal Assessments
Ensure your cloud environment meets the highest Department of Defense (DoD) security requirements for handling classified data. Schellman is an accredited 3PAO authorized to perform DoD IL6 assessments, helping cloud service providers (CSPs) achieve compliance to support federal agencies and DoD mission owners handling classified information. In addition to IL6 assessments, Schellman can perform NIST based assessments for classified systems, classified AICPA System and Organization Control (SOC) examinations, and penetration testing of classified systems.
Impact Level 6 (IL6) is the highest level of authorization within the DoD Cloud Computing (CC) Security Requirements Guide (SRG), designed for cloud environments processing classified information at the Secret level. IL6 builds upon the controls and requirements defined by FedRAMP and enforces the most stringent security controls to prevent unauthorized access, ensuring CSPs can securely support Department of Defense (DoD) and other federal agencies. Achieving IL6 compliance is essential for cloud providers looking to operate within classified government environments.
Achieving DoD IL6 authorization is essential for CSPs looking to handle (process, transmit, and store) classified information for federal agencies. Given the heightened security requirements, IL6 compliance not only enables CSPs to operate in classified environments but also demonstrates their commitment to the most rigorous cybersecurity standards.
Key benefits include:
We begin each project with your end goals in mind and to provide preparation for future key project activities. Effective communication and timely coordination of project planning activities are central to our methodology with our clients.
Core CSP Activities
Submit documentation and evidence key controls
Schellman 3PAO Activities
Schellman conducts an independent readiness assessment and issues a formal Readiness Assessment Report (RAR) per the FedRAMP Ready program guidelines.
Core CSP Activities
Develop and submit core security program documentation including the System Security Plan (SSP) and related policies and procedures to the Agency or JAB.
Schellman 3PAO Activities
Schellman performs readiness review of the SSP and supporting documentation.
While client is finalizing its SSP, Schellman begins to collaborative draft the security assessment plan.
Core CSP Activities
Stage 1: Review and approve SAP prior to submission to the Agency or JAB
Stage 2: Assist Schellman by providing any required documentation and testing evidence. Document any Plan of Action and Milestones (POA&M) generated from the assessment.
Schellman 3PAO Activities
Stage 1: Draft and submit the SAP to the Agency or JAB for approval.
Stage 2: Conduct testing of all in-scope controls, complete detailed control finding matrices, and issue SAR.
Core CSP Activities
Submit security assessment package.
Schellman 3PAO Activities
Provide clarification to the Agency or JAB and/or client as required to complete the authorization process.
Core CSP Activities
Conduct annual continuous monitoring activities as specified in the FedRAMP Annual Assessment Guidance.
Schellman 3PAO Activities
Conduct annual assessment of core controls as well as 1/3 of the remaining NIST control set along with review of POA&Ms and remediation. Conduct annual penetration testing and oversee scanning activities as required.
Nick Rundhaug is a Managing Director and Federal Practice Leader with Schellman. Nick has over 20 years of experience in the information technology field with 15 years’ experience in Federal frameworks for information technology. With a background as a network engineer and assessor, Nick specializes in the areas of cryptography, networking, and security mechanisms in cloud environments.