1. SERVICES
AFRRCS SECURITY ADVISOR
DESCRIPTION OF SERVICES
The Security Advisor will provide the knowledge and expertise to maintain, and further develop as required, the security program of AFRRCS, which includes making and implementing security recommendations for a framework of security features contributing to the successful provision of Land Mobile radio services to the First Responders Agencies.
The Security Advisor shall assist or participate in various work activities including:
General Security Activities:
- Work with appropriate personnel to document, evolve and further implement the AFRRCS security program and plan,
- Work with the RCMP, Policing Agencies and other First Responders to establish and implement a set of security standards that balance voice communications security with radio usability,
- Work with provincial organisations and associations that contribute to the security of AFRRCS and infrastructure.
- Implement security features that meet GoA standards,
- Perform Threat Risk Assessments on behalf of AFRRCS regarding the physical security of AFRRCS infrastructure;
- Review attempted breaches, successful breaches, and determine and implement mitigation requirements as necessary,
- Coordinate the reporting of attempted breaches and successful breaches to the appropriate policing authorities as required;
- Facilitate and provide training for AFRRCS and First Responder Agency personnel on security features,
- Establish security frameworks including tools, processes, and technologies to report on security integrity and status regularly,
- Lead incident response, mitigation, analysis and identify potential improvements when a breach is suspected or occurs,
- Provide security focussed review and analysis services to the AFRRCS Project Team including purchasing recommendations;
- Support AFRRCS personnel in communicating security plans processes and measures to First Responder Agencies, stakeholders or organizations or individuals,
- Build and maintain relationships with internal and external teams, AFRRCS radio users, and Service Alberta leadership to help drive adoption and awareness of AFRRCS security measures; and;
- Coordinate the submission of security clearance requests for AFRRCS staff.
- Act as the primary Point of Contact for access to AFFRCS infrastructure and sites.
Physical Security Activities:
- Review, perform, and update the Threat Risk Assessments on AFRRCS physical assets, (up to 400 individual AFRRCS sites and installations);
- Evaluate and prioritize risks to physical structures, equipment, and assets based on design and location;
- Implement policies, procedures, and measures to mitigate or minimize the prioritized risks,
- Determine and apply differential mitigation measures that are specific to the various different physical configuration of AFRRCS assets;
- Review site documents including site construction documents, legal land surveys, inside cable plant designs and make recommendations regarding physical security of the design;
- Perform physical security audits, analyze the results and make recommendations for improvements; and;
- Liaise with radio site land owners to identify the various access requirements and coordinate the adoptions of such requirements within AFRRCS support groups; and;
- Review, enhance and recommend improvements to the AFRRCS radio site safety program.
Technology Security Activities:
- Coordinate and analyze threat risk assessments within the AFRRCS technology environment;
- Liaise with the OMS engineering team to evaluate and prioritize risks within the technological environment, and existing equipment;
- Implement mitigation policies, procedures, and measures to mitigate the prioritized risks within the AFRRCS technology environment,
- Determine and apply differential mitigation measures that are specific to the various technology configurations of AFRRCS assets,
- Perform and/or analyse security audits, analyze the results and make recommendations for improvements,
- Perform system verification testing for security features and functions, and
Establish parameters and audit same for Inter-Agency Data connections.