Archive for the ‘CMMC’ Category
Wednesday, August 21st, 2024
The Defense Department recently proposed a new rule, published in the Federal Register on August 15, detailing how it plans to integrate the Cybersecurity Maturity Model Certification (CMMC) program into its contracting process. The CMMC program is designed to assess whether companies handling sensitive unclassified information comply with the department’s cybersecurity requirements. Since its announcement […]
Posted in CMMC, Compliance, Cybersecurity | Comments Off on Proposed Rule Establishes CMMC Guidelines for Defense Contract Compliance
Tuesday, August 20th, 2024
In recent years, cybersecurity has become a critical focus for the U.S. Department of Defense (DoD), particularly in safeguarding the defense industrial base (DIB) from increasing cyber threats. To address these concerns, the Cybersecurity Maturity Model Certification (CMMC) was introduced as a framework to enforce stronger cybersecurity practices among defense contractors. Recently, the DoD proposed […]
Posted in CMMC, Compliance, Cybersecurity | Comments Off on Understanding the New Proposed Final Rule for CMMC in CFR Title 48: What It Means for Contractors
Thursday, February 22nd, 2024
What To Know About Cybersecurity Insurance The cybersecurity insurance sector is in the midst of significant transformation. Escalating premiums, shifting prerequisites, and inconsistent standards within the industry present formidable hurdles for organizations seeking coverage. Now is a critical moment for these organizations to gain insight into the evolving landscape of cyber insurance and ascertain the […]
Posted in CMMC, Compliance, Cybersecurity, HIPAA | Comments Off on Cyber Insurance Explained
Wednesday, August 23rd, 2023
CMMC v2.0 Definitive Guide for 2023 The cyber landscape is becoming more intricate by the day, especially for companies working within the Department of Defense (DoD) supply chain. One pivotal evolution in this sphere is the introduction of the Cybersecurity Maturity Model Certification (CMMC). At its heart lies the crucial concept of security awareness training. […]
Posted in CMMC, Cybersecurity | Comments Off on CMMC Security Awareness Training
Monday, August 21st, 2023
A Comprehensive Guide to NIST Compliance In the dynamic world of government contracting, understanding and adhering to the National Institute of Standards and Technology (NIST) requirements is essential. These standards, particularly the NIST Special Publication 800-171, dictate how government contractors should manage and protect sensitive federal information. This guide provides an in-depth look at NIST […]
Posted in CMMC, Cybersecurity, NIST, NIST 800-171 | Comments Off on NIST Requirements for Government Contractors
Monday, August 21st, 2023
Securing Your Cloud Infrastructure Google Cloud Penetration Testing: In today’s rapidly digitizing world, cloud environments have become essential to businesses of all sizes. With a massive surge in cloud adoption, ensuring security in these virtual environments is paramount. Google Cloud Platform (GCP) is a leading provider of cloud services, and penetration testing or “pen testing” […]
Posted in CMMC, Compliance, Cybersecurity, NIST, NIST 800-171, Penetration Testing | Comments Off on Google Cloud Penetration Testing
Monday, August 21st, 2023
Fortifying the Frontline of Public-Private Collaboration Government Contractor Cybersecurity is imperative in today’s hyper-connected era. The collaboration between governments and private entities is an integral part of national infrastructure and defense. Government contractors, serving as a bridge between bureaucratic mechanisms and cutting-edge private sector solutions, are a crucial link in this chain. As with all […]
Posted in CMMC, NIST, NIST 800-171 | Comments Off on Government Contractor Cybersecurity
Monday, August 21st, 2023
Microsoft Azure Penetration Testing
Posted in CMMC, Cybersecurity, NIST 800-171, Penetration Testing | Comments Off on Microsoft Azure Penetration Testing
Thursday, August 17th, 2023
Why IT Managers Should Invest in 3rd Party Penetration Testing Penetration Testing and IT Managers should go hand in hand. In the rapidly evolving world of cybersecurity, one thing remains constant: the need for robust defense mechanisms against potential threats. IT managers, the gatekeepers of a company’s digital domain, are always on the lookout for […]
Posted in CMMC, Cybersecurity, NIST 800-171, Penetration Testing | Comments Off on Penetration Testing and IT Managers
Tuesday, August 15th, 2023
Elevating Cybersecurity Maturity for Defense Contractors The digital realm is a double-edged sword: while innovations have propelled industries to new heights, the accompanying cybersecurity threats have grown in tandem. Recognizing this, the Department of Defense (DoD) initiated the Cybersecurity Maturity Model Certification (CMMC). With the recent rollout of CMMC v2.1, defense contractors are required to […]
Posted in CMMC | Comments Off on CMMC v2.1
Friday, November 26th, 2021
What DoD Contractors Need To Do While Waiting for CMMC updates The Department of Defense’s (DoD’s) Office of the Under Secretary of Defense for Acquisition and Sustainment recently issued a long-awaited overhaul to its Cybersecurity Maturity Model Certification (CMMC) program. The DoD introduced CMMC 2.0, which streamlines the CMMC program via a significant set of […]
Posted in CMMC, Social | Comments Off on CMMC 2.0
Friday, December 18th, 2020
We have been reporting for quite a while now that the cyber security within the US government, in general, is just NOT up to par. The recent breach we have discussed over the last week or so really highlighted that fact. It was well-known even before this Russian cyberattack but not much has really been […]
Posted in CMMC, Cyber Security, Cybersecurity | Comments Off on US Government’s Cyber Security is a National Embarrassment
Thursday, December 17th, 2020
The DoD will begin including CMMC cyber security requirements in select solicitations beginning in 2021. Are you ready? It’s really not surprising that the DoD is concerned, especially if you have been following along with our last few blog posts about the massive breach that has compromised major US Governmental departments. As you probably know, […]
Posted in CMMC, Cyber Security, Cybersecurity | Comments Off on DoD Gets Ready for First CMMC Audits
Tuesday, December 15th, 2020
Every day, the information we learn about the FireEye hack just keeps getting increasingly worse. Last week we wrote about the hack occurring; yesterday we reported that not only was FireEye impacted, but the US government was, as well… Along with businesses and other governments across the globe; and today, we are starting to understand […]
Posted in Blog, CMMC, Cyber Security, Cybersecurity, NIST, Ransomware | Comments Off on The Hack that Keeps on Hacking
Wednesday, November 11th, 2020
Based on some confusing and potentially conflicting information we have found, we thought it was extremely important to clarify all expectations that the DoD has of its primes, subs and vendors. From listening to podcasts, watching and attending webinars, and reading any and every publication and white paper we can get our hands on, one […]
Posted in Blog, CMMC, Cyber Security, Cybersecurity, NIST | Comments Off on Must I Comply with the New DFARS Interim Rule?
Monday, November 9th, 2020
Penalties: Case Studies (An Excerpt from Craig’s newest book: “Ultimate Guide to CMMC: How to Access Millions in Government Contracts”) As we have established, it is clear that the “self-reporting” and “honor system” for government contractors who are required to abide by NIST 800-171 to gain government contracts is NOT working. But just because everyone […]
Posted in Blog, CMMC, Cyber Security, Cybersecurity, NIST | Comments Off on NIST Dishonesty: What Happens When Contractors Aren’t Truthful
Friday, November 6th, 2020
“CMMC certification is your Driver’s License on the Information Superhighway.” -Katie Arrington And if that’s the case (which it is), then the self-assessment required by the new DFARS Interim Rule is your permit… One that you must attain before December 1st, 2020 if you want to keep your car on the road- or your contract […]
Posted in Blog, CMMC, Cyber Security, NIST | Comments Off on URGENT DFARS UPDATE: Do Not Lose Your Contract!
Monday, April 6th, 2020
With the halt of HIPAA (Health Insurance Portability and Accountability Act of 1996) audits by the Department of Health and Human Services’ Office (HHS) for Civil Rights (OCR), the healthcare industry is seeing a decline of about 2% annually in compliance with HIPAA’s Security Rule (NIST 800-66). With that, however, has been a rise in […]
Posted in CMMC, Cyber Security, HIPAA, NIST | Comments Off on Is HIPAA’s Security Rule Adaptive Enough to Stay Relevant?
Friday, March 13th, 2020
It’s no coincidence that the maturity levels in the new Cybersecurity Maturity Model Certification (CMMC) are being referred to as levels of “cyber hygiene.” The World Health Organization (WHO) has been advising us that the most efficient way to protect against the Coronavirus (COVID-19) is to wash our hands regularly for at least 20 seconds […]
Posted in CMMC, Cyber Security, Ransomware, Tips & Tricks | Comments Off on How Avoiding Ransomware is like Avoiding the Coronavirus
Thursday, February 27th, 2020
By this point, you should hopefully understand that the purpose of the Cybersecurity Maturity Model Certification (CMMC) is to simplify cybersecurity for federal contractors and sub-contractors. Katie Arrington, the DOD’s Chief Information Security Officer for Acquisition and Sustainment, noticed (quite aptly) that “self-certifying” just wasn’t cutting the cake, so to speak. Hackers were targeting contractors, […]
Posted in CMMC | Comments Off on Understanding CMMC Maturity Levels (ML)