Information Security Resources
As the CMMC Churns | CUI Litmus Test: How to identify CUI in your environment
Is your organization struggling to identify CUI in your environment? Does your organization know the key tenets to identify CUI? If so, this As the CMMC Churns will help your organization. This video will explain the three [...]
As the CMMC Churns | Assessors and Toddlers
Is your organization getting ready to undergo a formal Conformity Assessment for NIST SP 800-171? If so, you need to watch this video!!! With the uptick in non-voluntary and Joint Surveillance Voluntary Assessments (JSVA) done by the [...]
As the CMMC Churns | NIST SP 800-171 3.13.7, “Split Tunneling,” Security Requirement
Are you trying got understand the 3.13.7, “Split Tunneling” Security Requirement in NIST SP 800-171 Rev 2 (and draft Rev 3?? Like all of the requirements, there are nuances in the actual Security Requirement, “Prevent remote devices [...]
As the CMMC Churns | NIST SP 800-171 Rev 3 Draft and Federal Math
DO NOT watch this if you are a Defense Industrial Base (DIB) Contractor. You have real work to do by implementing NIST SP 800-171 Revision 2. Here is what you need to do: Ignore all of the [...]
As the CMMC Churns | 4 Ways to Demonstrate NIST SP 800-171 Compliance
BREAKING NEWS from "As the CMMC Churns".... The Cyber-AB, with DoD's implicit blessing, is now allowing Authorized C3PAOs to conduct formal NIST SP 800-171 Assessments for organizations both inside and outside of the Defense Industrial Base. This [...]
As the CMMC Churns | Overengineering for CMMC
Has your business made the implementation of NIST SP 800-171 harder than it needs to be? Are your employees using one device for CUI work and another for normal work? If so, there is a good chance [...]
As the CMMC Churns | Vulnerability Management for Remote Workers
COVID-19 was a massive catalyst to change how the United States and the world operate. Businesses and the Federal Government had to shift to work from home on an unprecedented schedule. It forced businesses to transform all [...]
As the CMMC Churns | CMMC FUD
There is a lot of CMMC-related Fear, Uncertainty, and Doubt (FUD) being used to goad Defense Industrial Base (DIB) companies into implementing NIST SP 800-171 and get ready for CMMC. While we are 1000% for the DIB [...]
As the CMMC Churns | Tips about FIPS Part 2
Has 3.13.11, the use of FIPS-validated encryption, sent your organization through the Seven Stages of CMMC Grief? Does the use of FIPS-validated encryption have you befuddled? FIPS is confusing and complicated. In this episode of "As the [...]
As the CMMC Churns | Tips about FIPS Part 1
Has 3.13.11, the use of FIPS validated encryption, sent your organization through the Seven Stages of CMMC Grief? Does the use of FIPS validated encryption have you befuddled? FIPS is confusion and complicated. In this episode of [...]
DIBCAC Gaps
Did you know the Defense Industrial Based Cybersecurity Assessment Center (DIBCAC) posted slides about what NIST SP 800-171 requirements were "Other Than Satisfied"? In this episode of As the CMMC Churns we will take a look at [...]
As the CMMC Churns | Apple MacOS and CMMC
Does your business use Apple MacOS devices? Do you also have to implement NIST SP 800-171 and be CMMC accredited? Good news!!! Apple MacOS devices can be setup to fulfill NIST SP 800-171 and pass a CMMC [...]
As the CMMC Churns | Documenting Your Scope
Are looking to understand how to document your SSP? How does the NIST SP 800-171 Scope of Applicability and CMMC Assessment Scope fit in the SSP? In this "At the CMMC Churns," we take the Scope of [...]
As the CMMC Churns | Security Tactics for NIST SP 800-171 & CMMC “Specialized Assets”
Does your business have CMMC-defined "Specialized Assets"? Are you struggling to determine how to apply NIST SP 800-171 requirements to them? In this "As the CMMC Churns," we take a look at "Specialized Assets," or when broken [...]
As the CMMC Churns | Acquisition 101 and the CMMC Rule…[Update #1]
How will the changes to the CMMC Rule going final affect your business? This special edition of As the CMMC Churns will help to clarify. Matt Titcombe, the CEO of Peak InfoSec will put on his old [...]
As the CMMC Churns | To Enclave or not to Enclave, that is the question
"To Enclave or not to Enclave, that is the question…" In this "As the CMMC Churns," we look into "enclaving." We also look into the most common pitfalls businesses do when making an enclaving decision--falling back into [...]
NIST SP 800-171 and CMMC Level 2 Assessment Scoping Process Diagram
The process diagram is used to: Classify components per the NIST SP 800-171 Scope of Applicability Then categorize those components per the CMMC Level 2 Assessment Scoping Guide A separate diagram for classifying and categorizing roles will [...]
As the CMMC Churns | ‘Twas The Night Before the Final Rule Drop
A special fireside reading of “’Twas the Night Before Final Rule Drop.” Upcoming "As the CMMC Churns" Episodes: 5 Jan Enterprise or enclave 12 Jan OT & IIOT Security for CMMC 19 Jan Documenting your Scope 26 [...]
NIST SP 800-171 & CMMC Implementation in Three “Easy” Steps Infographic
Yes, you too can implement NIST SP 800-171 in preparation for CMMC in just three "Easy" Steps. Yeah, there is a LOT of sarcasm in the "Easy." However, many people and organizations are losing sight of [...]
As the CMMC Churns | Implementing CMMC Myth Busted!
Time to do some more debunking. There is a belief that Defense Industrial Base contractors need to implement the Cybersecurity Maturity Model Certification (CMMC). Au contraire. Aside from being the name of a wine, it is also [...]
As the CMMC Churns | The Three Descoping Methods
Three. Three. Yes, Three Descoping methods to take components out of your NIST SP 800-171 Scope of Applicability. “But Matt, there are only two isolation techniques listed in NIST SP 800-171 para 1.1” Muh-huh. There are three. [...]
As the CMMC Churns | How to apply the NIST SP 800-171 Scope of Applicability
Struggling to figure out what is in scope for NIST SP 800-171 and CMMC? Building on the Scope Confusion episodes and our “NIST SP 800-171 and CMMC Level 2 Assessment Scoping Infographic Whitepaper,” this As the CMMC [...]
As the CMMC Churns | CMMC Training on the Cheap for SMBs
As the CMMC Churns goes live!! This episode is "SMB Ways to meet CMMC Training Requirements" Are you a small business leader who needs to meet CMMC training requirements and your budget is limited? Perfect! In this [...]
NIST SP 800-171 and CMMC Level 2 Assessment Scoping Infographic Whitepaper
Commentary This document was created on 6 November 2022 and has not been revised, yet. This document and the infographic will be revised when the CMMC Interim Rule is published. Foundational Premises of the Infographic The foundational premises [...]
As the CMMC Churns – The CMMC Seven Stages of Grief
Is your organization stuck in the CMMC Seven Stages of Grief? Sadly, the malady is not sarcasm to get you to watch this video. Just as individuals grieve during a personal loss, organizations and their staff [...]
Social Contact