Similar Posts
DoJ (CMMC) False Claims Lawsuit Against Georgia Tech
In 2021 the DoJ announced the Civil Cyber Fraud Initiative to go after companies that lie about their cybersecurity practices. Under the False Claims Act, the government can recover damages and more. The “damage” could be as simple as we would not have given you the contract if we knew that you were not complying…
NIST SP 800-171 Rev 3 Update for August 2023
NIST has released a draft version of the next update to the core standard behind CMMC. If you do work for the US, Canadian or Australian defense departments or are a vendor to one of these organizations or if you are a vendor to a large US corporation, this standard and these changes are important…
DoD CMMC Update for July 2023
CMMC or the Cybersecurity Maturity Model Certification passed a huge milestone this week when the Pentagon handed of the proposed rule to the Office of Management and Budget. After they approve the package, it gets published in the Federal Register for comment and implementation. Learn more about the remaining steps below.
Security News Update for April 7, 2024
This week’s news update includes:
Add 20-30 Points to Your SPRS Score
For those of you who are DoD contractors (and even if you are not), here is one thing that you can do that will improve your security program and, if you are a DoD contractor, will add 20 or more points to your NIST SP 800-171 SPRS Score. Audio Video
Which CMMC Controls Can Be PoAMed?
First, what is a PoAM? A PoAM is, basically, a plan to fix any issues that were found during an assessment. Under CMMC, currently, a company can miss some controls and still get a provisional check mark. But, the rules as to what can be in a PoAM – that is pretty restricted. As is…