About

Compliance expertise built inside the agencies that write the rules.

ManageIT Security is an authorized CMMC Third-Party Assessment Organization specializing in Level 2 certification assessments, founded and led by Rosalyn Foltz.

Rosalyn Foltz, CISSP and Lead Certified CMMC Assessor at ManageIT Security

Rosalyn Foltz
CISSP, Lead Certified CMMC Assessor

Rosalyn Foltz founded ManageIT Security to give organizations something the compliance market makes surprisingly hard to find: an assessor with no stake in the outcome. The firm is an authorized C3PAO, one of roughly a hundred organizations cleared to conduct CMMC Level 2 certification assessments.

Rosalyn Foltz has spent 18 years in cybersecurity compliance — first inside the federal government, then advising the organizations regulated by it. She has led more than 40 CMMC Level 2 assessments.

Her career spans audit work at the Government Accountability Office, advisory engagements at KPMG, security program work at the U.S. Department of State, and enterprise compliance at E*TRADE. That combination — regulator, auditor, and practitioner — shapes how every ManageIT Security assessment is run.

She works with clients directly. Assessments are not delegated.

Depth beyond CMMC

CMMC assessments are the entire practice today, but the judgment behind them was built across a wider field. Rosalyn has worked through NIST 800-53, FedRAMP and FISMA environments, in defense, healthcare, finance and federal agencies, and spent years inside E*TRADE Financial, the U.S. Department of State, KPMG and the Government Accountability Office.

That range matters in an assessment. Controls rarely fail in isolation, and an assessor who has only ever seen one framework tends to read a finding narrowly. Knowing how the same control behaves under different regimes is what separates a checklist from an informed judgment.

We no longer offer advisory work in any of those frameworks. The experience stays; the conflict does not.

Credentials

  • C3PAOAuthorized CMMC Third-Party Assessment Organization (C3PAO)
  • Lead Certified CMMC Assessor (LCCA)
  • Certified Information Systems Security Professional (CISSP)
  • B.S. Management Information Systems, George Mason University
  • M.A. Global Affairs, IT Policy concentration, George Mason University

Background

  • GAO

    Federal audits of agency information security programs.

  • KPMG

    Advisory engagements across regulated industries.

  • U.S. Department of State

    Security program and control assessment work.

  • E*TRADE

    Enterprise security compliance in financial services.

We assess. We do not consult.

A certification assessment is only worth what the assessor's independence is worth. As an authorized C3PAO, that independence is not a preference, it is the basis on which we are allowed to do this work.

Ready to talk about your assessment?

Book an Intro Call