a. Developing, documenting, and describing in detail the ARC IT environment and ISS implementation tasks, which are to be performed in the ARC Information Systems Security Strategic Plan.
b. Completing risk assessments or validating the results of existing risk assessments.
c. Providing the necessary strategic planning, cost benefit analysis, and design for a successful migration to MS Windows 2003 Server for ARC Airports- nationwide.
d. Implementing security mitigation measures, some of which are ARC-wide and some of which apply to individual systems.
e. Supporting and assisting ARC in attaining Federal Information Security Management Act (FISMA) (http://csrc.nist.gov/policies/FISMA-final.pdf) compliance. Updating the ARC ISS Program Strategic Plan, Business Continuity & Disaster Recovery Plan, ARC Rules of System Use, and other policies, practices, and procedures that could be enacted to support the ISS implementation within ARC.
f. Performing other IT and ISS implementation tasks as assigned by the COTR to assist ARC in implementing a new ARC ISS Program Management Plan.
g. Providing staff to assist in conducting all activities associated with a Systems Test & Evaluation.
k. Develop a comprehensive assessment of current ARC HQ information systems architecture, IT platforms and applications
l. Propose recommendations and, upon COTR approval, provide implementation of ARC system upgrades and enhancements in the areas of: COTS application deployments/roll-outs, systems migration, single sign-on systems, automated security patch updates, and network systems monitoring, maintenance and management.
m. Develop ARC functional area standard operating procedures (SOPs) and performance metrics.
n. Assist in the development, production and standardization of necessary ARC technical and functional documentation.
o. Assist in creating, reviewing, and implementing FAA Information Systems Security policy, practices, and procedures whenever ARC is a stakeholder in the results.
p. Recommend/provide protection from external interfaces that directly link into the ARC network environment.
q. Develop a software distribution system and processes, specific to ARC, to include distribution of critical software security patches and fixes.
r. Develop recommendations for security mitigation measures, some of which are ARC-wide and some of which apply to individual systems.
s. Provide Security Certification and Accreditation support as required.
t. Perform Systems Test and Evaluation (ST&E) activities as needed to support Security Certification
and Accreditation