Similar Posts
CMMC Update- April 2022
Do you have to comply with CMMC? Here is an update with the current status of things – along with a little history – as of today. Audio Video
DoD Issues “Class Deviation” for NIST SP 800-171 Rev 3
We knew that DoD had to resolve the conflict between the current 7012 DFARS and the CMMC Part 32 rule that was released in December, but we did not know HOW they were going to resolve it. For defense contractors who are wrestling with getting ready for CMMC, their temporary workaround is the best we…
Defense Contractor Settles False Claims Act Suit
The feds sued MORSECorp under the False Claims Act alleging that they lied about their NIST 800-171/CMMC compliance, posted false SPRS scores and generally inflated their cybersecurity readiness. The DoJ is rumored to be working on anywhere from dozens to hundreds of these cases. They have an entire division called the Cyber Civil Fraud Initiative…
CUI and GPTs
Okay, that is a bit of alphabet soup. CUI stands for Controlled Unclassified Information. While technically, it only refers to government agencies and government contractors, think of it as information you might prefer that the Russians, Chinese and your competitors don’t have. GPT stands for generative pretrained transformers like ChatGPT, Bard and many others. It…
Will You be the Last to Know?
External attack surface management tools (EASM) allow anyone to get a sense of your security prep without your permission or even your knowledge. Who uses EASM tools? Your competitors against you, your customers to decide if they want to do business with you, members of the public, your insurance carrier to decide if they want…
Security News Update for February 9, 2025
This week’s news includes: