Information Security Resources

As the CMMC Churns | CUI Litmus Test: How to identify CUI in your environment

July 6th, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , , , , , , , , |

Is your organization struggling to identify CUI in your environment? Does your organization know the key tenets to identify CUI? If so, this As the CMMC Churns will help your organization. This video will explain the three [...]

As the CMMC Churns | Assessors and Toddlers

June 28th, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , , , , , , , , |

Is your organization getting ready to undergo a formal Conformity Assessment for NIST SP 800-171? If so, you need to watch this video!!! With the uptick in non-voluntary and Joint Surveillance Voluntary Assessments (JSVA) done by the [...]

As the CMMC Churns | NIST SP 800-171 3.13.7, “Split Tunneling,” Security Requirement

June 22nd, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , , , , , , , , |

Are you trying got understand the 3.13.7, “Split Tunneling” Security Requirement in NIST SP 800-171 Rev 2 (and draft Rev 3?? Like all of the requirements, there are nuances in the actual Security Requirement, “Prevent remote devices [...]

As the CMMC Churns | NIST SP 800-171 Rev 3 Draft and Federal Math

May 19th, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , , , , , , , , |

DO NOT watch this if you are a Defense Industrial Base (DIB) Contractor. You have real work to do by implementing NIST SP 800-171 Revision 2. Here is what you need to do: Ignore all of the [...]

As the CMMC Churns | 4 Ways to Demonstrate NIST SP 800-171 Compliance

May 5th, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , , , , , , , |

BREAKING NEWS from "As the CMMC Churns".... The Cyber-AB, with DoD's implicit blessing, is now allowing Authorized C3PAOs to conduct formal NIST SP 800-171 Assessments for organizations both inside and outside of the Defense Industrial Base. This [...]

As the CMMC Churns | Overengineering for CMMC

April 27th, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , , , , , , , |

Has your business made the implementation of NIST SP 800-171 harder than it needs to be? Are your employees using one device for CUI work and another for normal work? If so, there is a good chance [...]

As the CMMC Churns | Vulnerability Management for Remote Workers

April 23rd, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , , , , , , , |

COVID-19 was a massive catalyst to change how the United States and the world operate. Businesses and the Federal Government had to shift to work from home on an unprecedented schedule. It forced businesses to transform all [...]

As the CMMC Churns | CMMC FUD

April 5th, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , , , , , , , |

There is a lot of CMMC-related Fear, Uncertainty, and Doubt (FUD) being used to goad Defense Industrial Base (DIB) companies into implementing NIST SP 800-171 and get ready for CMMC. While we are 1000% for the DIB [...]

As the CMMC Churns | Tips about FIPS Part 2

March 31st, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , , , , , , , |

Has 3.13.11, the use of FIPS-validated encryption, sent your organization through the Seven Stages of CMMC Grief? Does the use of FIPS-validated encryption have you befuddled? FIPS is confusing and complicated. In this episode of "As the [...]

As the CMMC Churns | Tips about FIPS Part 1

February 16th, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , , , , , , , |

Has 3.13.11, the use of FIPS validated encryption, sent your organization through the Seven Stages of CMMC Grief? Does the use of FIPS validated encryption have you befuddled? FIPS is confusion and complicated. In this episode of [...]

DIBCAC Gaps

February 9th, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , , , , , , , |

Did you know the Defense Industrial Based Cybersecurity Assessment Center (DIBCAC) posted slides about what NIST SP 800-171 requirements were "Other Than Satisfied"? In this episode of As the CMMC Churns we will take a look at [...]

As the CMMC Churns | Apple MacOS and CMMC

February 2nd, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , , , , , , , |

Does your business use Apple MacOS devices? Do you also have to implement NIST SP 800-171 and be CMMC accredited? Good news!!! Apple MacOS devices can be setup to fulfill NIST SP 800-171 and pass a CMMC [...]

As the CMMC Churns | Documenting Your Scope

January 26th, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , , , , , , , |

Are looking to understand how to document your SSP? How does the NIST SP 800-171 Scope of Applicability and CMMC Assessment Scope fit in the SSP? In this "At the CMMC Churns," we take the Scope of [...]

As the CMMC Churns | Security Tactics for NIST SP 800-171 & CMMC “Specialized Assets”

January 19th, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , , , , , , |

Does your business have CMMC-defined "Specialized Assets"? Are you struggling to determine how to apply NIST SP 800-171 requirements to them? In this "As the CMMC Churns," we take a look at "Specialized Assets," or when broken [...]

As the CMMC Churns | Acquisition 101 and the CMMC Rule… [Update #1]

January 12th, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , |

How will the changes to the CMMC Rule going final affect your business? This special edition of As the CMMC Churns will help to clarify. Matt Titcombe, the CEO of Peak InfoSec will put on his old [...]

As the CMMC Churns | To Enclave or not to Enclave, that is the question

January 5th, 2023|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , |

"To Enclave or not to Enclave, that is the question…" In this "As the CMMC Churns," we look into "enclaving." We also look into the most common pitfalls businesses do when making an enclaving decision--falling back into [...]

NIST SP 800-171 and CMMC Level 2 Assessment Scoping Process Diagram

January 4th, 2023|Categories: CMMC, Compliance, DFARS & NIST SP 800-171, Information Security, whItepaper|Tags: , , , , , , , , , , , |

The process diagram is used to: Classify components per the NIST SP 800-171 Scope of Applicability Then categorize those components per the CMMC Level 2 Assessment Scoping Guide A separate diagram for classifying and categorizing roles will [...]

As the CMMC Churns | ‘Twas The Night Before the Final Rule Drop

December 22nd, 2022|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , |

A special fireside reading of “’Twas the Night Before Final Rule Drop.” Upcoming "As the CMMC Churns" Episodes: 5 Jan Enterprise or enclave 12 Jan OT & IIOT Security for CMMC 19 Jan Documenting your Scope 26 [...]

NIST SP 800-171 & CMMC Implementation in Three “Easy” Steps Infographic

December 15th, 2022|Categories: CMMC, Compliance, DFARS & NIST SP 800-171, Infographic, Information Security|Tags: , , , , , , , , , , , |

Yes, you too can implement NIST SP 800-171 in preparation for CMMC  in just three "Easy" Steps. Yeah, there is a LOT of sarcasm in the "Easy." However, many people and organizations are losing sight of [...]

As the CMMC Churns | Implementing CMMC Myth Busted!

December 15th, 2022|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , |

Time to do some more debunking. There is a belief that Defense Industrial Base contractors need to implement the Cybersecurity Maturity Model Certification (CMMC). Au contraire. Aside from being the name of a wine, it is also [...]

As the CMMC Churns | The Three Descoping Methods

December 8th, 2022|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , |

Three. Three. Yes, Three Descoping methods to take components out of your NIST SP 800-171 Scope of Applicability. “But Matt, there are only two isolation techniques listed in NIST SP 800-171 para 1.1” Muh-huh. There are three. [...]

As the CMMC Churns | How to apply the NIST SP 800-171 Scope of Applicability

December 1st, 2022|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , |

Struggling to figure out what is in scope for NIST SP 800-171 and CMMC? Building on the Scope Confusion episodes and our “NIST SP 800-171 and CMMC Level 2 Assessment Scoping Infographic Whitepaper,” this As the CMMC [...]

As the CMMC Churns | CMMC Training on the Cheap for SMBs

November 17th, 2022|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , |

As the CMMC Churns goes live!! This episode is "SMB Ways to meet CMMC Training Requirements" Are you a small business leader who needs to meet CMMC training requirements and your budget is limited? Perfect! In this [...]

NIST SP 800-171 and CMMC Level 2 Assessment Scoping Infographic Whitepaper

November 6th, 2022|Categories: CMMC, Compliance, DFARS & NIST SP 800-171, Information Security, whItepaper|Tags: , , , , , , , , , , , |

Commentary This document was created on 6 November 2022 and has not been revised, yet. This document and the infographic will be revised when the CMMC Interim Rule is published. Foundational Premises of the Infographic The foundational premises [...]

As the CMMC Churns – The CMMC Seven Stages of Grief

November 3rd, 2022|Categories: As the CMMC Churns, Compliance, DFARS & NIST SP 800-171, Information Security|Tags: , , , , , , , , , , , |

Is your organization stuck in the CMMC Seven Stages of Grief? Sadly, the malady is not sarcasm to get you to watch this video.   Just as individuals grieve during a personal loss, organizations and their staff [...]

Information Security Turnaround Specialists