Episodios

  • The DoD is Mad as Hell About Cyber Noncompliance
    May 15 2025

    Katie Arrington is the architect of the CMMC program, currently performing the duties of the DoD CIO, and she is ultra pissed that defense contractors haven't improved their cybersecurity posture while she was gone for 3 short years. This week we dive into Katie's keynote at AFCEA TechNet Cyber 2025 where she didn't mince words about CMMC, the DIB, and the coming storm.

    Register for CEIC West: https://ceicwest.com/

    Pathfinder 101: https://www.summit7.us/pathfinder

    Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

    Katie's Keynote: https://www.youtube.com/watch?v=n4dNFn_HX20

    DFARS 7012: https://youtu.be/cy4e28YAkXU?si=F8FSzFqaWMXQ2h8e

    Más Menos
    15 m
  • You can’t do that with your ESP!
    May 8 2025

    The Cyber AB has once again convened the CMMC ecosystem to deliver the monthly Town Hall covering the latest news and information about the CMMC Program; and Joy has once again joined the show so we can talk about the latest ecosystem happening for the month of April. A change in CAICO leadership, stats on completed assessments, another audit, a “ESP, not a CSP” MythBusters/Ecosystem ethics fusion, and so much more...

    Pathfinder 101: https://www.summit7.us/pathfinder

    Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

    AB Town Halls: https://cyberab.org/News-Events/Town-Halls/Details/march-town-hall

    Más Menos
    33 m
  • CS2 Reston Preview
    May 1 2025

    It's that time of year again and this time CS2 is coming to Reston, VA. This week we walk through the agenda adn talk about the sessions we're most excited for. Whistleblower attorneys? C3PAO lessons learned? Real world defense contractors who have completed CMMC Level 2? Prime contractor perspectives on upcoming requirements? CS2 has it all.

    Register for CS2 Reston: https://cs2.cloud/reston

    Pathfinder 101: https://www.summit7.us/pathfinder

    Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

    Más Menos
    27 m
  • DoD’s Parameters for SP 800-171r3
    Apr 24 2025

    DoD has officially released their parameters for NIST SP 800-171 revision 3 requirements. Defense contractors now have a clear picture of their future compliance requirements and what assessors will ask for under “CMMC 3.0”. But if SP 800-171r3 won't be required for some time, why did the DoD publish their organizationally defined values? In this episode we dive into the basics of “ODPs”, why they matter, and how contractors can leverage them now to future-proof their systems against regulatory updates.

    Register for CS2 Reston: https://cs2.cloud/reston

    Pathfinder 101: https://www.summit7.us/pathfinder

    Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

    Memo: https://dodcio.defense.gov/cmmc/Resources-Documentation/

    ODP Deep Dive: https://www.youtube.com/watch?v=QXfzSo4_F54

    Deep Dive w/ Ron Ross: https://www.youtube.com/watch?v=x37V6fE-ies

    171r3: https://www.youtube.com/watch?v=TAzYQjLfPY0

    7012 Class Deviation: https://www.youtube.com/watch?v=voziZRAMvv4

    Más Menos
    29 m
  • What is DFARS 7012?
    Apr 17 2025

    Most people mistaken believe that their cybersecurity requirements stem from the Cybersecurity Maturity Model Certification Program (CMMC). CMMC is simply a verification program that proves if you have implemented the requirements imposed by DFARS clause 252.204-7012. Ultimately, DFARS clause 252.204-7012 is the center of gravity for all the cybersecurity stuff that comes with being a defense contractor. This week is an important primer on DFARS 7012 because even though it's only 13 paragraphs long, few people take the time to read it closely.

    Register for CS2 Reston: https://cs2.cloud/reston

    Pathfinder 101: https://www.summit7.us/pathfinder

    Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

    DFARS 7008: https://youtu.be/vgrRGIWboKc?si=TFuX_wYBgfDhNQ8X

    DFARS 7012: https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.

    The History of CMMC: https://youtu.be/jbY2irZ1ePg?si=Khw6kLH5JnXfiTs6

    7012 Class Deviation: https://youtu.be/voziZRAMvv4?si=2TczM85cISzpd63V

    FedRAMP equivalency memo: https://youtu.be/torWNL3U7ZY?si=_tAubFpxJxtqrS6L

    Más Menos
    39 m
  • What is DFARS 252.204-7008?
    Apr 10 2025

    After 100 episodes diving into every possible rabbit hole to help illuminate the bigger picture around CMMC we're starting over at square zero: the “DFARS Cyber Series” of contract clauses. First up: the solicitation provision 252.204-7008. Although 7008 doesn't have the notoriety of it's big brother DFARS 252.204-7012, it is the first domino that triggers the cascade of cybersecurity compliance obligations that ultimately culminate in CMMC assessment.

    Register for CS2 Reston: https://cs2.cloud/reston

    Pathfinder 101: https://www.summit7.us/pathfinder

    Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

    DFARS 252.204-7008: https://www.acquisition.gov/dfars/252.204-7008-compliance-safeguarding-covered-defense-information-controls.

    The 2016 final rule: https://www.federalregister.gov/documents/2016/10/21/2016-25315/defense-federal-acquisition-regulation-supplement-network-penetration-reporting-and-contracting-for

    Más Menos
    36 m
  • DOJ vs Small Defense Contractors
    Apr 3 2025

    The Department of Justice finally did it: they went after a small defense contractor for failure to comply with their contractually obligated cybersecurity requirements. This case has it all from fake SPRS scores to whistleblowers getting paid hundreds of thousands of dollars to contractors paying millions in fines. All thanks to the same set of contract clauses in every DoD contract and the same errors committed by the vast majority of defense contractors.

    Register for CS2 Reston: https://cs2.cloud/reston

    Pathfinder 101: https://www.summit7.us/pathfinder

    Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

    DOJ press release: https://www.justice.gov/opa/pr/defense-contractor-morsecorp-inc-agrees-pay-46-million-settle-cybersecurity-fraud

    Law firm press release: https://www.prnewswire.com/news-releases/morsecorp-agrees-to-pay-4-6-million-to-settle-landmark-cybersecurity-false-claims-act-case-brought-by-whistleblower-law-collaborative-client-302412118.html?tc=eml_cleartime

    FCA w/ Stephanie Siegmann: https://youtu.be/d1yweDy2wV4?si=_CgQ3WTV2ynVbEyL

    FCA w/ Alex Canizares: https://youtu.be/Tga0krfIrEk?si=oOXG-zvYcV_mGTL2

    Más Menos
    23 m
  • March AB Townhall Recap
    Mar 27 2025

    The Cyber AB is back with their monthly Town Hall meeting which can only mean one thing; Joy is here to co-host the show, and we are gonna break down the information distributed during the meeting. The ecosystem is growing, CMMC is going international, and so much more! Tune in to see what we have to say!

    Register for CS2 Reston: https://cs2.cloud/reston

    Pathfinder 101: https://www.summit7.us/pathfinder

    Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

    Sum IT Up ‘Canada's CMMC': https://youtu.be/AFe8CeIosYk?si=3Um3sXa1IEoTvAbD

    AB Town Halls: https://cyberab.org/News-Events/Town-Halls/Details/march-town-hall

    Más Menos
    23 m
adbl_web_global_use_to_activate_T1_webcro805_stickypopup