Matt Titcombe on the Compliance Trap from the Department of Defense.
J. Gregory McVerry
-
-
Amira Armond on how inheritance and CMMC works.
-
Excited for Kyle Lai’s talk on ISO 2700. This is why I came.
-
Cole French a C3PAO on preparing for CMMC.
-
Victoria Pillitteri of NIST on future of 171
-
Leopold Wildenauer Datacentric approaches to Protecting CUI: CMMC and Zero Trust
-
Karen Evans, Why CMMC matters for SMBs.
-
Stacy Bostjanick, CMMC Director, at CMMC Day
-
-
CCMC: Asset Categorization and Systems Security Engineering
Systems security engineering, establishing security by considering the problem, solution, and trustworthiness of all key components in a business, begins with stakeholder interest and the business outcomes. A business that cannot turn a profit cannot remain a business for long. …
-
In reply to
I just RSVPd
-
CMMC: Systems Security Engineering and the Cloud
In systems security engineering requirements and constraints drive the design choices we make. They will send signals in a CMMC assessment. The constraints and requirements of an environment determines the type of evidence an assessor needs to verify. Organizations Seeking …
-
CMMC Assessment: In Systems Security Engineering the Environment Drives Evidence
From A Systems Security Engineering perspective, the environment will drive the evidence collected to ensure an organization seeking certification meets security requirements. For both the assessor and the contractor considering the impact of scope on how their systems gets …
-
CMMC, Asset Inventory, and Systems Security Engineering
table, th, td { border: 1px solid; } You cannot protect what you do not know you have. Systems security engineering, as a method to meet the security requirements of CMMC requires an Organization Seeking Certification (OSC) to provide the means to locate, identify, and log the …
-
System Security Engineering and CMMC
Every organization has a philosophy behind their system security plan. These may range from an idea that, “Compliance is not security,” to “DFARS is an unfunded mandate, “ or ” “CMMC did this to me.” Other organizations may have their SSP reviewed on a quarterly timeline, and …
-
Evaluating Organizations Seeking Certifcation: Document Based Requirements to Start a Conversation
You do not jump out of a plane without first making sure a parachute works. Yet many Organization Seeking Certification (OSC) want to make a leap of bling faith about their compliance to the practices in the Cybersecurity Maturity Model Certification. When an Organization Seeking …
-
CMMC and Asset Inventory
Asset Inventory will drive your compliance. Whether you rely on the shared responsibility of zero trust models or protect information at your boundaries, asset inventory drives your security. When determining the cost of both compliance and security asset inventory drives your …
-
-
Any great conference should close with Amira Armond.
-
5 – A Vision for Software Bill of Materials (SBOM) in the DoD
Jason Weiss
DoD Chief Software Officer, Office of the Secretary of Defense