Assigned the Task of Getting Your Company Compliant: Burden or Blessing in Disguise?

Assigned the Task of Getting Your Company Compliant: Burden or Blessing in Disguise?

Hello, dear friends! Today, we’re going to discuss a situation that many of you may have experienced or might encounter in the future – being “burdened” with the task of getting your company compliant. At first glance, this might seem like a daunting and undesirable responsibility. But, what if I told you that this assignment…

Don’t Panic! NIST SP 800-171r3 and FutureFeed

Don’t Panic! NIST SP 800-171r3 and FutureFeed

NIST released an initial public draft of NIST SP 800-171 r3 (“r3”) on May 10, 2023. This blog post discusses that draft and our plans for incorporating r3 into FutureFeed. NIST 800-171 Discussion Draft Last year NIST announced that they would be updating 800-171, and asked for public feedback. They used that feedback, as well…

DoD Publishes new DFARS Rule Impacting SPRS

DoD Publishes new DFARS Rule Impacting SPRS

The United States Department of Defense recently published a notice that a new rule, DFARS 252.204-7024, will be published soon. In her recent article (available here for free), Sara Friedman publishes analysis of that new rule, including comments from Robert Metzger, Eric Crusius, and me. The biggest takeaway I see is that DoD is laying a foundation for…

Security Without Governance is not Secure

Security Without Governance is not Secure

Background The Internet has quickly revolutionized the way governments, companies, and other organizations conduct business. But in their haste to gain market share and meet client/constituent expectations, many organizations are pushing out products and services that are not, and using IT infrastructure that is not, secure. This has made it easy for criminals and other…

DoD Adds Scrutiny to Contractor Cybersecurity Programs

DoD Adds Scrutiny to Contractor Cybersecurity Programs

Background Over the past few years, the US federal government has been gradually trying to improve its cybersecurity program, and has been encouraging contractors to do the same. The US Department of Defense led the way in these efforts, including through a variety of initiatives like DFARS 252.204-7012 and the Cybersecurity Maturity Model Certification (“CMMC”) program. The CMMC program…

75/25 – We Need You

75/25 – We Need You

Regan Edens’ LinkedIn post is nothing short of a CMMC national call to action. To bottom line it, there are two facts. According to John Ellis at DIBCAC there have been just shy of 20,000 SPRS scores submitted out of a pool, we are told, of 80,000. Best government estimates are that the interim rule changes…

End of content

End of content