In terms of CMMC many organization feel overwhelmed by documentation and do not always understand the distinction between policy, plans, and procedure. Yet we often get lost in the effort to meet compliance requirements and forget that the “G” in GRC stands for …
J. Gregory McVerry
-
-
Building for the Future: Utilizing Rev 3 ODPs in your Rev 2 Assessment Scope
Do all NIST-SP-800-171 requirements need continuous monitoring? Which ones are annual? Which controls are monthly? Weekly? Right now an organization seeking CMMC certification can decide on which requirements get met by controls that need a defined cadence. As you make these …
-
-
MAM versus MDM: Data and Device Protections
A lot of organization who rely on Mobile Device Management are starting to understand the risks of Bring Your Own Device. Watching the Stryker Incident where Intune erased personal devices managed by employers has put the issue in stark contrast. Mobile Device Management is not …
-
Big Announcement
The DIB CS Program is OPEN for new companies. The outreach and onboarding functions have transitioned to DC3.
DIB Companies, with or without an FCL, working with CUI, can apply at DC3.DIB.CSRegistration@us.af.mil
-
CyberDI's Customizable CMMC and Export Control Curriculum
Proud to Announce CyberDI’s Awareness and Training Programs to meet your CMMC requirements and improving a culture of security CyberDI Awareness and Training Program
-
CMMC Tool Sets
-
CMMC, Backups, and FedRAMP
Why do back ups live in the Media Protection family? Ransomware threatens your business everyday, and backups help to inoculate your systems. Why do back ups get such a small mention in NIST.SP.800-171r2? NIST explains in NIST-SP-800-171r2 they pulled “CP-9, System Backup” into …
-
AI For Security S ecurity For AI
A good intro to the risks, challenges, and opportunities
-
Many people are confused by the Cross tenant collaboration and the new Microsoft UX:
gcch-m365-webinar-connect-collaborate-create-june-2025-complete.pdf
-
Adding sensitivity labels to SharePoint: learn.microsoft.com/en-us/pur…
unlabeled filed continue to be protected with current SharePoint permissions for the user, even though the files have left original SharePoint boundary
COOL!
-
Adding cross posting to Blue Sky
-
People keep asking, “What they can do?”
How can they help
If you are a small business owner one of the best things you can do is make sure you have a good backup and recovery plan
Good back ups are the Victory Gardens of the 21st Century
-
Many companies are now hearing more and more about Multi-Factor Authentication. In fact for most small businesses you can no longer get insurance, let alone cyber coverage, without ensuring MFA gets used for all sensitive data.
Really if you can turn on Multi-Factor Authentication. You should
-
-
Certified CMMC Assessor: Spinning the Wheels of Trust in Much Bigger Systems
Certified CMMC Assessors click into place as just another cog in a much larger system that already exists. Every objective that a CCA examines must already be legally met by Organization Seeking Certification. CMMC introduced no new requirements on Federal contractors. When …
-
Hanging at Converge Security and learning about Conway’s Law at the Keynote addresds
-
Developing a Rubric to Assess Policies and Procedures for CMMC Compliance
People panic when it comes to policy and procedures and CMMC. Rightfully so. Compliance with NIST-SP-800-171 at a miminum requires fourteen different policies and fourteen different procedures. Probably More. In fact NIST recommends 39 different plans, policies, and procedures …
-
Can you Engineer Culture in your Systems?
As we try to create online communities focused on open learning we have to recognize the troubled history open source has had with diversity, equity, and inclusion. Some bias is implicit due to systematic discrimination. You need to be well off to work for free. Often though we …
-
Guide to Microsoft's Security and Compliance Rebranding
Many people might stare with wide eye confusion at the naming conventions Microsoft has used in rebranding. Some of the services used in the government and by government contractors have a new moniker. Yet when you think about the changes the logic makes sense in terms of keeping …