ArcLight6 Consulting home
Security posture

How we secure our own house

We ask customers to let us examine their controls. It would be poor form not to say how ours work. This page describes how ArcLight6 handles controlled information, who has access to it, how we treat vendors, and what happens when something goes wrong.

Last reviewed
Not yet reviewedSet a real date before publishing
Review cadence
To be setConfirm before publishing
Owner
To be namedConfirm before publishing

A security posture page that nobody has re-read in two years is worse than none, so the review date is stated plainly. If it looks stale, treat it as stale and ask us.

Draft: not yet confirmed by ArcLight6

Every statement below is marked Confirm before publishing because it was drafted from what this site already says publicly, not from any audit of ArcLight6's controls. Each one needs to be confirmed, corrected, or removed by someone who can stand behind it. Until then this page is held out of search.

What we do, and how

Controlled Unclassified Information

  • CUI is handled only in environments approved for it, and is never accepted through this website's forms.Confirm before publishing
  • Our contact and support forms carry an explicit instruction not to include classified information or CUI, and route to a person rather than a queue.Confirm before publishing
  • Customer CUI is segregated by engagement, and access is limited to the engineers assigned to that engagement.Confirm before publishing
  • Media holding customer information is sanitised or destroyed before disposal or reuse.Confirm before publishing

Internal controls and frameworks

  • We work to NIST SP 800-171 for CUI environments, and align internal practice with the same standard we assess against.Confirm before publishing
  • Multi-factor authentication is required for remote access, email, and all privileged accounts.Confirm before publishing
  • Endpoints are centrally managed, patched on a defined schedule, and monitored.Confirm before publishing
  • Access is reviewed on a defined cadence, and removed the same day someone leaves or changes role.Confirm before publishing
  • A System Security Plan and a Plan of Action & Milestones are maintained for our own environment.Confirm: do not publish if untrue

Personnel security and clearances

  • Individuals are screened before being granted access to customer information.Confirm before publishing
  • Clearance status is verified through official channels and is discussed with customers directly rather than published.Confirm before publishing
  • The team holds CISSP, C|CISO, CDPSE, CASP+ and Security+, and roles are defined against the DoD 8570/8140 baseline.Already public: confirm still accurate
  • Security awareness training is completed at onboarding and at least annually thereafter.Confirm before publishing

Vendors and supply chain

  • Vendors with access to customer information are assessed before use, and reassessed on a defined cadence.Confirm before publishing
  • Flow-down security requirements from customer contracts are passed to subcontractors in writing.Confirm before publishing
  • We keep an inventory of the services that process customer information, and of what each one holds.Confirm before publishing
  • This website loads its runtime and fonts from third-party CDNs; no customer information passes through them.Accurate as built: confirm wording

Incident response

  • A written incident response plan names who is called, in what order, and within what timeframe.Confirm before publishing
  • Customers are notified of incidents affecting their information within the timeframe their contract specifies, and DoD reporting obligations are met where they apply.Confirm: contractual, do not overstate
  • The plan is exercised.Confirm before publishing
  • Logs are retained long enough to reconstruct an incident weeks after the fact.Confirm before publishing

This website

  • The site is static: no customer database, no server-side session state, and no account system.Accurate as built
  • The readiness self-assessment scores entirely in your browser. Answers are not transmitted, logged, or stored on any server.Accurate as built
  • Support tickets are handled in the helpdesk portal, which is a separate system with its own authentication.Confirm before publishing
Responsible disclosure

Found something? Tell us.

If you have found a vulnerability in this website or in anything else we run, we want to hear about it before someone else finds it. Report it to security@arclight6.com. Tell us what you found and how to reproduce it; give us a reasonable window to fix it before publishing.

We do not run a paid bug bounty. We will acknowledge your report, keep you updated while we fix it, and credit you if you would like to be credited. Machine-readable contact details are published at /.well-known/security.txt.Confirm security@ address exists and is monitored

ArcLight6 Consulting LLC · 2020 N Academy Blvd #290, Colorado Springs, CO 80909 · 1-719-301-6280