Similar Posts
Will You be the Last to Know?
External attack surface management tools (EASM) allow anyone to get a sense of your security prep without your permission or even your knowledge. Who uses EASM tools? Your competitors against you, your customers to decide if they want to do business with you, members of the public, your insurance carrier to decide if they want…
DoJ (CMMC) False Claims Lawsuit Against Georgia Tech
In 2021 the DoJ announced the Civil Cyber Fraud Initiative to go after companies that lie about their cybersecurity practices. Under the False Claims Act, the government can recover damages and more. The “damage” could be as simple as we would not have given you the contract if we knew that you were not complying…
CUI and GPTs
Okay, that is a bit of alphabet soup. CUI stands for Controlled Unclassified Information. While technically, it only refers to government agencies and government contractors, think of it as information you might prefer that the Russians, Chinese and your competitors don’t have. GPT stands for generative pretrained transformers like ChatGPT, Bard and many others. It…
Which CMMC Controls Can Be PoAMed?
First, what is a PoAM? A PoAM is, basically, a plan to fix any issues that were found during an assessment. Under CMMC, currently, a company can miss some controls and still get a provisional check mark. But, the rules as to what can be in a PoAM – that is pretty restricted. As is…
CMMC News Update for October 2023
CMMC is definitely a work in progress. However, like all works in progress, there is progress being made. Here is the update for October.
What is Required for CMMC Level 1 Compliance?
Over the last couple of years we have talked a lot about what is required for CMMC Level 2 certification, but a lot more companies will need to be CMMC Level 1 certified. What is required for this?