Capabilities
Eight capability areas, delivered as programs an organization can own.
RISC develops, manages, and executes continuity-based and security programs using standardized methods drawn from federal continuity and defense infrastructure protection doctrine.
01
Business Continuity Programs
Development and execution of continuity programs built on a standardized program management cycle, so essential functions are sustained through disruption.
RISC uses a standardized continuity program management cycle, which provides consistency across an organization’s business continuity programs. Establishing standardized planning and procedural objectives and requirements ensures sustainment of essential functions during a catastrophic emergency, and use of the cycle facilitates development and implementation of resilient continuity programs.
Continuity of operations and continuity of government
Our consultants are certified emergency and continuity of operations managers, working across both continuity of operations (COOP) and continuity of government (COG) requirements — from plan development and procedural documentation through exercise, assessment, and sustainment of the program over time.
Continuity readiness is expressed in levels: as the threat environment changes, the posture, alert and notification procedures, staffing of alternate facilities, and communications checks all change with it. We plan each level explicitly so that a change in posture is a set of rehearsed actions rather than an improvisation.
Reference: Federal Continuity Directive 1 (FCD-1), Annex A.
02
Business Impact Analysis
A strategic approach to identifying the threats, hazards, and disruptions that could keep an organization from executing its essential functions.
A business impact analysis (BIA) predicts the consequences of the disruption of a business function or process, and gathers the information needed to develop recovery strategies. Identifying and evaluating the impact of disruption provides the basis for investment in recovery strategies as well as in prevention and mitigation.
RISC conducts the BIA using a structured questionnaire directed at managers and staff with detailed knowledge of how the organization delivers its products and services, then documents potential impacts, assesses significant interruption scenarios in financial terms where possible, and prioritizes the order of restoration. Processes with the greatest operational and financial impact are restored first. The BIA is the foundation for the continuity plan and the IT disaster recovery plan that follow.
Impacts we quantify
- Lost sales and income
- Delayed sales or income
- Increased expenses — overtime labor, outsourcing, expediting costs
- Regulatory fines
- Contractual penalties or loss of contractual bonuses
- Customer dissatisfaction or defection
- Delay of new business plans
Disruption scenarios we plan against
- Physical damage to a building or buildings
- Damage to or breakdown of machinery, systems, or equipment
- Restricted access to a site or building
- Interruption of the supply chain, including supplier failure or transportation disruption
- Utility outage, such as an electrical power outage
- Damage to, loss, or corruption of information technology — voice and data communications, servers, computers, operating systems, applications, and data
- Absenteeism of essential employees
Timing matters: a disruption of minutes may be a minor inconvenience, while the same disruption sustained for hours — or occurring at a peak point in the operating year — can carry a substantial share of annual loss. Impact categories and scenarios referenced from Department of Homeland Security continuity guidance.
03
Business Process Analysis
Understanding how the work actually gets done — the processes, the parties, the information exchanged, and the documents produced.
Business process analysis (BPA) is a methodology for the analysis of a business with a view to understanding the processes and improving the efficiency and effectiveness of its operations. It describes the processes involved, parties participating, information exchanged and documents produced.
Where a business impact analysis establishes what an organization cannot afford to lose, the business process analysis establishes how that work is actually performed — which makes it the natural companion to the BIA and the basis for continuity procedures that people can follow under pressure.
RISC utilizes Five Basic Questions to develop and execute a sound BPA. The questions are worked through with the managers and staff who own each process, in sequence, and the answers are documented as the process description, the participating parties, the information exchanged, and the documents produced.
Referenced: Department of Homeland Security.
04
Special Security Programs
The depth of knowledge and experience required to develop, manage, and execute special security programs across the security disciplines.
RISC has more than 30 years of hands-on experience developing, monitoring, assessing, and managing special security programs. Our consultants have served as Special Security Officers (SSOs) within major government organizations, and have proven experience as Contractor Special Security Officers (CSSOs), Facility Security Officers (FSOs), and COMSEC custodians.
Consultants have served as branch chiefs across personnel, industrial, information, protection, and physical security disciplines, and have built major security programs for both public sector and private sector organizations. We have developed and delivered security training programs, including training built specifically for CSSOs and FSOs.
Program areas
- SCI security official (SCI-SSO) and COMSEC custodian duties
- Special access program security
- SCIF and SAPF accreditation and certification, CONUS and OCONUS
- End-to-end personnel security adjudication process management
- Direction of emergency operations centers for government and private sector organizations
- Management of Department of State security guard programs in the Middle East and Northern Africa
Industrial security instruments
- National Industrial Security Program Operating Manual (NISPOM), DoD 5220.22-M
- Facility clearances (FCLs)
- DD Form 254 contract security classification specifications
- DD Form 441 security agreements
- The wider suite of contractor program security requirements mandated across defense and intelligence programs
05
DoD Critical Infrastructure Protection
Risk management-based skills to develop, manage, and execute critical infrastructure protection programs.
Critical infrastructure protection (CIP) is a national program to ensure the security of the vulnerable and interconnected infrastructures of the United States. The federal government maintains a standardized description of critical infrastructure to facilitate monitoring and preparation for disabling events, and requires private industry in each critical economic sector to assess its vulnerabilities to physical and cyber attack, plan to eliminate significant vulnerabilities, develop systems to identify and prevent attempted attacks, and alert, contain, and rebuff attacks before rebuilding essential capabilities in the aftermath.
RISC consultants have developed, monitored, assessed, and managed Defense critical infrastructure protection and business continuity programs for a major DoD organization, and apply that experience as a repeatable, risk management-based method rather than a one-off assessment.
Critical Asset Identification Process — nine steps
RISC uses the Critical Asset Identification Process (CAIP) to help organizations — national, state, and local government, as well as private sector and not-for-profit organizations — identify their critical assets and clearly identify the threats, hazards, and vulnerabilities that could preclude a required function in a contested environment.
- Mission decomposition and required capability identification
- Task asset (TA) identification
- Task critical asset (TCA) nomination and submission
- TCA validation
- Validated component and TCA lists submitted to the appropriate organizational authority
- Competent authority compilation and release of the organization-wide TCA list
- Organization infrastructure sector interdependency analysis in support of TCAs
- Competent authority nomination of potential defense critical assets to the organizational approval authority
- Organizational approval authority review and approval of nominated critical assets
Reference: DoDM 3020.45, Volume 1.
06
Procurement Support
Comprehensive procurement support, from market research to contract closeout, ensuring efficient and strategic acquisitions.
RISC provides comprehensive procurement support across the acquisition lifecycle, beginning with market research and continuing through award, administration, and contract closeout. The objective is efficient, strategic acquisition — work packaged so that requirements, schedule, and cost are defensible to the organizations that must approve them.
This support is frequently paired with our continuity and security work, where a program requires new capability, services, or facility improvements to close a gap identified in an assessment.
07
Transition & Transformation Support
Smooth transitions and robust transformations through strategic planning, stakeholder engagement, and continuous improvement.
RISC facilitates transitions and organizational transformations through strategic planning, structured stakeholder engagement, and continuous improvement. Transitions are where continuity is most often lost: responsibilities move, documentation lags, and essential functions quietly lose their owners.
We plan the change, keep the stakeholders who depend on the function engaged through it, and measure the result so the new arrangement is demonstrably at least as capable as the one it replaced.
08
Security Management Systems
A Plan-Do-Check-Act management system for organizations that need a durable security and continuity program rather than a single engagement.
For organizations building a program from a standing start, RISC applies the Plan-Do-Check-Act (PDCA) model: plan — establish the management system; do — implement and operate the management system; check — monitor and review the management system; and act — maintain and improve it.
The result is a security and continuity program with defined ownership, review intervals, and a mechanism for improvement, rather than a document that ages on a shelf. We use this approach with smaller organizations and not-for-profits — including religious organizations, counseling centers, and cultural centers — that need a sound program proportionate to their size.
How to buy from us
Contract codes and registrations
RISC’s top five NAICS codes, shown with their official 2022 titles. These are five of the 28 NAICS codes registered on RISC’s SAM.gov entity record — contracting officers can pull the full list from the entity profile.
- 541611Administrative Management and General Management Consulting Services Primary
- 541512Computer Systems Design Services
- 541690Other Scientific and Technical Consulting Services
- 561621Security Systems Services (except Locksmiths)
- 541618Other Management Consulting Services
- Product and service codes (PSC)
- DA01 · DE01 · DJ01 · DK01 · R408 · R499 · R610 · R704 · S206
- Unique Entity ID (UEI)
- KYLMC43JX8G1
- CAGE code
- 4DDV6
- SAM.gov registration
- Active through 1 June 2027
Five of 28 NAICS codes registered on RISC’s SAM.gov entity record. The complete NAICS and PSC listing is available on the SAM.gov entity profile under UEI KYLMC43JX8G1, and on request.
Next
Applied by sector
Each capability area is delivered against the standards and culture of the customer’s sector.