720-891-1663

DoD Just “Upped” The Cybersecurity Game for Defense Contractors

If you are a defense contractor – prime, sub or vendor to one of these and you were hoping that CMMC was going to go away, I don’t think that is going to happen – at least not on this president’s watch. Even if the party in power changes in January, I don’t much will […]

Continue reading → [DISPLAY_ACURAX_ICONS]

DoD Contractors: Will You Have to Replace Your MSP?

If you are a defense contractor, then over the next few years you will likely have to be compliant and maybe certified for CMMC, either at level one or level two. Level one has about 17 controls and 59 assessment objectives; level two has 110 controls and about 315 assessment objectives. Assessment objectives are the […]

Continue reading → [DISPLAY_ACURAX_ICONS]

NIST Releases Draft 800-171 Rev 3

NIST Special Publication 800-171 is the guide that all defense contractors must follow for protecting controlled unclassified information. It has been around since 2015 and has gone over several revisions. Revision 3 is the most recent and NIST has released the “initial public draft”. Expect a final draft this fall and a released version in […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Federal Civilian Agencies May Have to Comply with CMMC-Like Security Requirements

If you sell to the federal government – any agency – you need to pay attention to this. Until now only DoD contractors were going to have to comply with CMMC or NIST SP 800-171. The standard requires 100% compliance with 110 controls; some of them pretty straight forward like having each user having their […]

Continue reading → [DISPLAY_ACURAX_ICONS]

So You Think You Are Ready for Your CMMC Assessment

At some point in the “relatively near future”, if are a DoD contractor, subcontractor, vendor, managed service provider or a host of other folks, you will be staring a CMMC certification in the face. Here are some thoughts from a provisional assessor on what it will take to get the job done. Hopefully this is […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Is Your IT Provider a Security Dumpster Fire

Many small businesses and a lot of large ones use third party IT service providers called MSPs or Managed Service Providers. In almost all cases, these MSPs have the keys to your IT universe. They have access to your data. They also have access to all of your access rules. If they also help you […]

Continue reading → [DISPLAY_ACURAX_ICONS]