The trend I've been noticing lately is the rise of 1-man or 1-woman consulting firms. Now at the monthly security group meetings one loses count of how many people are working as independent consultants. Yet, when they present their services to you it's a very long list like that below. So how is this possible for one person to do? Are they just reselling services from bigger firms, or is their really a workable system to providing all these services as a InfoSec Consultant
[The below services I've noticed most consultants provide]CYBERSECURITY ASSESSMENTS
Vulnerability Assessment Services
Penetration Testing Services
Social Engineering Assessments
Security Architecture Review & Design
FEDERAL SERVICES
Risk Management Framework (RMF) Support
Security Assessment and Authorization
FISMA Certification
FedRAMP Compliance
NIST 800-53 Assessment Services
Continuous Monitoring
Vulnerability Analysis and Penetration Testing
Security Policy and Procedures Documentation
Security Staff Augmentation
HEALTHCARE ASSESSMENTS
HIPAA / HITECH Readiness Assessment
PRIVACY ASSESSMENTS
Domestic and Cross-border
CLOUD SECURITY ASSESSMENTS
Cloud Security Services; FedRAMP Compliance
SOC EXAMINATIONS
THIRD PARTY RISK