Information Security Resources

As the CMMC Churns | Apple MacOS and CMMC

February 2nd, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , , , , , , , |

Does your business use Apple MacOS devices? Do you also have to implement NIST SP 800-171 and be CMMC accredited? Good news!!! Apple MacOS devices can be setup to fulfill NIST SP 800-171 and pass a CMMC [...]

As the CMMC Churns | Documenting Your Scope

January 26th, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , , , , , , , |

Are looking to understand how to document your SSP? How does the NIST SP 800-171 Scope of Applicability and CMMC Assessment Scope fit in the SSP? In this "At the CMMC Churns," we take the Scope of [...]

As the CMMC Churns | Security Tactics for NIST SP 800-171 & CMMC “Specialized Assets”

January 19th, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , , , , , , |

Does your business have CMMC-defined "Specialized Assets"? Are you struggling to determine how to apply NIST SP 800-171 requirements to them? In this "As the CMMC Churns," we take a look at "Specialized Assets," or when broken [...]

As the CMMC Churns | Acquisition 101 and the CMMC Rule… [Update #1]

January 12th, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , |

How will the changes to the CMMC Rule going final affect your business? This special edition of As the CMMC Churns will help to clarify. Matt Titcombe, the CEO of Peak InfoSec will put on his old [...]

As the CMMC Churns | To Enclave or not to Enclave, that is the question

January 5th, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , |

"To Enclave or not to Enclave, that is the question…" In this "As the CMMC Churns," we look into "enclaving." We also look into the most common pitfalls businesses do when making an enclaving decision--falling back into [...]

NIST SP 800-171 and CMMC Level 2 Assessment Scoping Process Diagram

January 4th, 2023|Categories: CMMC, Compliance, DFARS & NIST SP 800-171, Information Security, whItepaper|Tags: , , , , , , , , , , , |

The process diagram is used to: Classify components per the NIST SP 800-171 Scope of Applicability Then categorize those components per the CMMC Level 2 Assessment Scoping Guide A separate diagram for classifying and categorizing roles will [...]

As the CMMC Churns | ‘Twas The Night Before the Final Rule Drop

December 22nd, 2022|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , |

A special fireside reading of “’Twas the Night Before Final Rule Drop.” Upcoming "As the CMMC Churns" Episodes: 5 Jan Enterprise or enclave 12 Jan OT & IIOT Security for CMMC 19 Jan Documenting your Scope 26 [...]

NIST SP 800-171 & CMMC Implementation in Three “Easy” Steps Infographic

December 15th, 2022|Categories: CMMC, Compliance, DFARS & NIST SP 800-171, Infographic, Information Security|Tags: , , , , , , , , , , , |

Yes, you too can implement NIST SP 800-171 in preparation for CMMC  in just three "Easy" Steps. Yeah, there is a LOT of sarcasm in the "Easy." However, many people and organizations are losing sight of [...]

As the CMMC Churns | Implementing CMMC Myth Busted!

December 15th, 2022|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , |

Time to do some more debunking. There is a belief that Defense Industrial Base contractors need to implement the Cybersecurity Maturity Model Certification (CMMC). Au contraire. Aside from being the name of a wine, it is also [...]

As the CMMC Churns | The Three Descoping Methods

December 8th, 2022|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , |

Three. Three. Yes, Three Descoping methods to take components out of your NIST SP 800-171 Scope of Applicability. “But Matt, there are only two isolation techniques listed in NIST SP 800-171 para 1.1” Muh-huh. There are three. [...]

As the CMMC Churns | How to apply the NIST SP 800-171 Scope of Applicability

December 1st, 2022|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , |

Struggling to figure out what is in scope for NIST SP 800-171 and CMMC? Building on the Scope Confusion episodes and our “NIST SP 800-171 and CMMC Level 2 Assessment Scoping Infographic Whitepaper,” this As the CMMC [...]

As the CMMC Churns | CMMC Training on the Cheap for SMBs

November 17th, 2022|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , |

As the CMMC Churns goes live!! This episode is "SMB Ways to meet CMMC Training Requirements" Are you a small business leader who needs to meet CMMC training requirements and your budget is limited? Perfect! In this [...]

NIST SP 800-171 and CMMC Level 2 Assessment Scoping Infographic Whitepaper

November 6th, 2022|Categories: CMMC, Compliance, DFARS & NIST SP 800-171, Information Security, whItepaper|Tags: , , , , , , , , , , , |

Commentary This document was created on 6 November 2022 and has not been revised, yet. This document and the infographic will be revised when the CMMC Interim Rule is published. Foundational Premises of the Infographic The foundational premises [...]

As the CMMC Churns – The CMMC Seven Stages of Grief

November 3rd, 2022|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , |

Is your organization stuck in the CMMC Seven Stages of Grief? Sadly, the malady is not sarcasm to get you to watch this video.   Just as individuals grieve during a personal loss, organizations and their staff [...]

As the CMMC Churns | Managed Service Provider Ghost Stories

October 25th, 2022|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , |

Welcome to the Halloween edition of As the CMMC Churns. In this edition we will regale the watched with real world ghost stories that drove their client, an Organization Seeking Certification, into non-compliance and scared their compliance [...]

White Paper | Debunking CMMC Assessment Scope Myths

October 24th, 2022|Categories: CMMC, Compliance, DFARS & NIST SP 800-171, Information Security, VLOG, whItepaper|Tags: , , , , , , , , , , , |

The Problem The Cybersecurity Maturity Model Certification (CMMC) Assessment Scope – Level 2 Guide is misleading cybersecurity professionals into underapplying National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal [...]

How much is a CMMC Conformity Assessment going to cost???

October 12th, 2022|Categories: As the CMMC Churns, CMMC, Compliance, DFARS & NIST SP 800-171, Information Security, VLOG|Tags: , , , , , , , , |

"How much is a CMMC Conformity Assessment going to cost???" The foremost favorite question every Organization Seeking Compliance (OSC) is asking CMMC 3rd Party Assessor Organizations (C3PAO) right now. While this episode won't answer that question for [...]

As the CMMC Churns: Procedure Myths Busted & Quarter Pounders???

October 4th, 2022|Categories: As the CMMC Churns, CMMC, Compliance, DFARS & NIST SP 800-171, Information Security, VLOG|Tags: , , , , , , , , |

Is your business struggling to implement procedures for Cybersecurity Maturity Model Certification (CMMC)? Is your business chasing procedures for everything because of perceived compliance requirements coming from CMMC, NIST SP 800-171, and NIST SP 800-171A? Well, this [...]

As the CMMC Churns: The Little CMMC Engine that Could

September 14th, 2022|Categories: As the CMMC Churns, CMMC, Compliance, DFARS & NIST SP 800-171, Information Security, VLOG|Tags: , , , , , , , , |

Are you struggling to get through Remediation Pass and over Conformity Hill? Well, today's story from As the CMMC Churns is all about "the Little CMMC Engine that Could." It is a classic story of the little [...]

As the CMMC Churns: Finger Pointing and the Customer Responsibility Matrix (CRM)

August 24th, 2022|Categories: As the CMMC Churns, CMMC, Compliance, DFARS & NIST SP 800-171, Information Security, VLOG|Tags: , , , , , , , , |

Did you know your need a CRM for your CMMC Conformity Assessment? No, not a Customer Responsibility Management application--you need a Customer Responsibility Matrix (CRM). If you don't know: What a CRM is? Why it is needed? [...]

As the CMMC Churns and the Quest for the Lost Families of NIST

August 17th, 2022|Categories: As the CMMC Churns, CMMC, Compliance, DFARS & NIST SP 800-171, Information Security, VLOG|Tags: , , , , , , , , |

Are you ready to go on a CMMC Quest? We will be looking for the lost Families of NIST. A whirlwind tour through NIST SP 800-171 Appendix E, Tailoring. While not as exciting as being thrown into [...]

As the CMMC Churns: Good, Fast, or Cheap. Pick one, Punk!

August 3rd, 2022|Categories: As the CMMC Churns, CMMC, Compliance, DFARS & NIST SP 800-171, Information Security, VLOG|Tags: , , , , , , , , |

So many Defense Industry organizations are making critical and costly errors. Are you? They fail to recognize the fundamental acquisition relationship between Good, Fast, or Cheap when it comes to implementing NISR SP 800-171 requirements to satisfy [...]

As the CMMC Churns: Moving the Pentagon

July 26th, 2022|Categories: As the CMMC Churns, CMMC, Compliance, DFARS & NIST SP 800-171, Information Security, VLOG|Tags: , , , , , , , , |

Did you know you have enough leverage to move the Pentagon? Is your Program Office and Contracting Officer not providing your organization guidance on CUI? While you may not have enough leverage to move the whole Pentagon, [...]

As the CMMC Churns: Scope Confusion (Part 2)

July 20th, 2022|Categories: As the CMMC Churns, CMMC, Compliance, DFARS & NIST SP 800-171, Information Security, VLOG|Tags: , , , , , , , , |

Are you confused about the CMMC Assessment Scope and how to apply it to your business? Do you think you don’t have to apply NIST SP 800-171 requirements to Contractor Risk Managed or Specialized Assets? Well for [...]

Information Security Turnaround Specialists