Blog

Jan 22nd 2024

NIST 800-171 R3: What Is A SCRM Plan?

National Institute of Standards and Technology (NIST) publishes NIST 800-171 which is a set of guidelines designed to enhance the cybersecurity posture of organizations handling Controlled Unclassifie …
Understanding The CMMC Risk Management Ecosystem

May 31st 2022

Understanding The CMMC Risk Management Ecosystem

When it comes to recent CMMC discussions, it feels as though the trees are being missed due to the forest being in the way. Specifically, quite a few discussions on "necessary evidence" needed to sati …
CMMC Control Ownership Documentation (RACI/RASCI)

Feb 9th 2022

CMMC Control Ownership Documentation (RACI/RASCI)

This article covers the concept of building a RACI/RASCI matrix to demystify control ownership concerns, as well as reviewing any Customer Responsibility Matrix (CRM) that vendors may share with you.W …
Is Your MSP / MSSP A Dumpster Fire?

Jan 22nd 2022

Is Your MSP / MSSP A Dumpster Fire?

What is the soft underbelly of your CMMC program?For a lot of companies, it is not what they think it is and the reason is primarily based on misplaced assumptions. Too many people and companies view …
The most terrifying words in CMMC

Sep 2nd 2021

The most terrifying words in CMMC

This article looks at the most terrifying words in CMMC: "I’m from a RPO and I'm here to help!" This article focuses on a growing concern about Organizations Seeking Certification (OSC) being fleeced …