Similar Posts
DoD CMMC Update – February 1, 2023
For those of you who are covered by DoD’s cybersecurity regulations such as 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting, you probably know that it is a bit of a moving target. We expect a flurry of updates later this spring, but in the mean time, you should be working on compliance. Here…
Which CMMC Controls Can Be PoAMed?
First, what is a PoAM? A PoAM is, basically, a plan to fix any issues that were found during an assessment. Under CMMC, currently, a company can miss some controls and still get a provisional check mark. But, the rules as to what can be in a PoAM – that is pretty restricted. As is…
CUI and GPTs
Okay, that is a bit of alphabet soup. CUI stands for Controlled Unclassified Information. While technically, it only refers to government agencies and government contractors, think of it as information you might prefer that the Russians, Chinese and your competitors don’t have. GPT stands for generative pretrained transformers like ChatGPT, Bard and many others. It…
NIST SP 800-171 Rev 3 Update for August 2023
NIST has released a draft version of the next update to the core standard behind CMMC. If you do work for the US, Canadian or Australian defense departments or are a vendor to one of these organizations or if you are a vendor to a large US corporation, this standard and these changes are important…
NIST SP 800-171 Update for July 2023
800-171 is the government’s chosen cybersecurity standard for protecting controlled unclassified information (CUI) and is the standard is required by a number of government departments and by private industry as a matter of contract for protecting sensitive unclassified information. Learn more about this new version of the standard here.
CMMC Update for October 2024 – Part 2
The Final rule for Title 32 is out. Here is a more detailed explanation of some of the requirements. This is a very complex rule at about 475 pages. Most of that is explanation, but still there is a lot to this part of the rule. Please contact us if – excuse me – when…