Global Information
Assurance Metrics.
A Service-Disabled Veteran-Owned Small Business providing governance, risk, and compliance consulting to DoD contractors, federal agencies, and the Defense Industrial Base. The practice traces back to 1988, before governance, risk, and compliance existed as a named discipline.
The Firm
What GiaMetrics Does
GiaMetrics® helps organizations establish the governance foundation needed to manage risk, meet regulatory and contractual requirements, and make trustworthy decisions. We apply that foundation across cybersecurity, CMMC, RMF, FedRAMP, data governance, AI, and broader business operations.
The name is an abbreviation of Global Information Assurance Metrics, and the emphasis on metrics is deliberate. Governance that cannot be measured cannot be assured, and assurance is what a contracting officer, an assessor, or an authorizing official is actually asking for.
We work with organizations at every stage of maturity: first-time contractors facing a CMMC requirement they did not anticipate, program offices navigating an authorization, and established organizations whose governance was built for a different era and no longer holds up.
As an SDVOSB verified through the Small Business Administration, work performed by GiaMetrics can be applied toward federal and prime contractor small business subcontracting goals under FAR Part 19.
At a Glance
- SDVOSB, SBA verified
- Certified FutureFeed partner
- Cyber AB RP and CCP practitioners
- DoD, federal, and DIB focus
- Founded on practice dating to 1988
Founder Credentials
- CISSP · CGRC (ISC2)
- CISM · CISA · CCSA (ISACA)
- CCISO (EC-Council)
- RP · CCP (Cyber AB)
- IcAgile ICP
Leadership
Lawrence M. Coclough
Founder and Principal. Nearly four decades across military communications, federal program management, and cloud authorization, applied to the question of how organizations establish governance they can actually defend.
Lawrence Coclough founded GiaMetrics® to apply a governance methodology developed over decades of federal and defense practice. He served 23 years in the U.S. Army Signal Corps, then thirteen years at the Program Executive Office, Enterprise Information Systems as Information Assurance Program Manager and Senior Cybersecurity Manager, where roughly 70 percent of the organization’s Authorizations to Operate carried his signature before reaching the Approving Authority.
In 2016 he led the effort that obtained the first IL5 FedRAMP authorization issued by DISA. He holds CISSP, CISM, CISA, CGRC, CCISO, and CCSA, and is a Cyber AB Registered Practitioner and Certified CMMC Professional.
Experience & Credentials
The Full Record
U.S. Army Signal Corps · 23 Years
Enlisted February 1975, retired honorably February 1998. Assignments included the 1st Battalion, 80th Field Artillery in Germany across two tours, the 3rd Armored Cavalry Regiment at Fort Bliss, The Old Guard at Arlington, the 513th Military Intelligence Group at Fort Monmouth, and PM TACMIS at Fort Belvoir.
Project Officer · PM TACMIS, Fort Belvoir
Fielded and integrated Army computer systems worldwide, coordinating delivery, receipt, inspection, acceptance, handoff, and training setup at each site. Roughly six months a year on temporary duty travel. This was the introduction to what systems accountability actually requires at scale.
Where the Practice Begins
Structured systems analysis, Computer-Aided Software Engineering tools, and business process reengineering. The vocabulary of governance, risk, and compliance did not exist yet. The underlying discipline of establishing what a system does, who is accountable for it, and how you prove it works, did.
Information Assurance Program Manager · PEO EIS, Fort Belvoir
Returned to the same organization, by then the Program Executive Office, Enterprise Information Systems, serving as Information Assurance Program Manager, Senior Cybersecurity Manager, and Senior Managing Consultant across thirteen years. Roughly 70 percent of the organization’s Authorizations to Operate carried his signature before reaching the Approving Authority. Implemented DITSCAP, then DIACAP, then the transition to RMF. At its peak PEO EIS managed approximately $3.5 billion annually, supporting Army-wide operations globally with roughly 3,000 personnel, 37 product offices, and 71 acquisition programs.
First IL5 FedRAMP Authorization Issued by DISA
Joined IBM and led the effort that obtained the first Impact Level 5 FedRAMP authorization issued by the Defense Information Systems Agency. At the time this made IBM only the second cloud service provider, after AWS, authorized to handle all levels of unclassified DoD data. This was the introduction to cloud governance at scale.
Founder & Principal · GiaMetrics®
Applying nearly four decades of accumulated practice to organizations that need a governance foundation they can defend. Credentials include CISSP, CISM, CISA, CGRC, CCISO, and CCSA, along with Cyber AB Registered Practitioner and Certified CMMC Professional designations, from the Cyber AB.
Purpose to Promise
Leadership Philosophy
“My success is measured by the success I help create in others.”
Lawrence M. CocloughBuilt to Be Handed Over
The throughline across military service, federal program management, governance practice, and coaching has not been technical depth. It has been building systems and organizations that allow other people to succeed after the person who built them has moved on.
Independent of Any One Person
A governance program that depends on one person’s memory is not a program. The work is finished when someone else can trace an ownership decision, produce evidence, and explain a risk acceptance without asking the person who made it.
Capability, Not Dependency
Engagements are structured so the client organization finishes more capable than it started. The measure of the work is whether your team can run the program without us, not whether you need us to keep running it.
GiaMetrics helps organizations establish the governance necessary to make trustworthy mission decisions, ensuring that data is authoritative, understood, and fit for the decisions that depend on it.
Experience & Capability
From Requirements to Results
GiaMetrics® combines extensive federal and defense experience with industry-recognized professional certifications and established governance practices. We translate complex requirements into practical action: reviewing, identifying, planning, implementing, validating, and sustaining the capabilities organizations need to manage risk and meet customer, contractual, regulatory, and mission requirements.
Whether the objective is CMMC certification, RMF or FedRAMP authorization, cybersecurity maturity, data governance, or responsible AI adoption, GiaMetrics leadership and practitioners hold the industry-recognized professional certifications and bring the governance expertise required to assess organizational requirements, identify gaps, develop practical plans, and support implementation through measurable outcomes and continuous assurance.
Credentials held include CISSP and CGRC from ISC2; CISM, CISA, and CCSA from ISACA; CCISO from EC-Council; Registered Practitioner and Certified CMMC Professional from the Cyber AB; and IcAgile Certified Professional. Also held are Defense Acquisition University certifications and INFOSEC IAM designation.
Where We Work
Six Domains, One Foundation
The same governance foundation supports each of these. None of them is the destination.
Cybersecurity
Security programs built on ownership and accountability.
CMMC
Certification readiness and assessment support for the DIB.
RMF
The federal risk management lifecycle, from categorize to monitor.
FedRAMP
Cloud service authorization and continuous monitoring.
Data Governance
Ownership, lineage, provenance, stewardship, and intended use.
AI Governance
NIST AI RMF implementation and trustworthy AI oversight.
And broader business operations, wherever an organization needs to manage risk, satisfy a requirement, and make a decision it can defend.
Service-Disabled Veteran-Owned Small Business
GiaMetrics® is an SDVOSB verified through the U.S. Small Business Administration. Federal agencies and prime contractors can apply GiaMetrics work toward SDVOSB subcontracting goals under FAR Part 19.
Get Started
Have a Project? Let’s Talk.
We work with organizations at every stage, from those addressing governance for the first time to those with mature programs facing a new requirement. Tell us about your situation and we will outline a clear path forward.
Send Us a Message
Whether you are exploring your options or ready to start, we are here to help. All inquiries are confidential.