『A Pause, Not a Pass on CMMC』のカバーアート

A Pause, Not a Pass on CMMC

A Pause, Not a Pass on CMMC

無料で聴く

ポッドキャストの詳細を見る
On July 13, the Department of War hit pause on one of the most consequential compliance regimes in the defense industrial base. In Episode 14 of The GIST of Govt IT, Brian and Sean break down the suspension of CMMC Phase II — the third-party assessment requirement that was set to take effect November 10 — and what it actually means for the thousands of contractors caught in the middle. Sean's message is blunt: this is a pause, not a repeal. The requirement to protect controlled unclassified information isn't going anywhere, and the smart move is to keep marching toward NIST SP 800-171 compliance regardless of what the 60-day CMMC Reform Task Force recommends. The conversation digs into the real economics that triggered the review, the False Claims Act lawsuits already settling in the six-to-eight-figure range for contractors who attested to compliance they didn't have, why ISO 27001 is the closest on-ramp for commercial companies new to the space, and a clear Monday-morning playbook. Plus, CISA Director Nick Andersen's hacker name (hint: he's a Matrix fan).Resources Mentioned in This EpisodeThe Core StoryDepartment of War release: "Forging the Arsenal of Freedom: DoW Suspends CMMC Phase II Requirements" (July 13)Office of Industrial Base Growth version of the announcementFederal News Network coverageThe CMMC Reform Task Force RFI (responses due 12:00 PM ET, Friday, August 14) — posted on SAM.gov Legal & Advisory AnalysisMorgan Lewis — "Cybersecurity Obligations Remain"Crowell & Moring — DFARS obligations & contractor action stepsGreenberg Traurig — the July 13 memoranda explained Standards & Frameworks ReferencedNIST SP 800-171 Rev. 2 (protecting Controlled Unclassified Information) NIST SP 800-171 Rev. 3CMMC Program overview (DoD CIO)ISO/IEC 27001 (the commercial on-ramp Sean recommends)DFARS 252.204-7012 (safeguarding covered defense information)FIPS 140 validated encryptionCompliance & Assessment ConceptsSPRS (Supplier Performance Risk System) — where self-assessments are postedDIBCAC (Defense Industrial Base Cybersecurity Assessment Center)C3PAO (CMMC Third-Party Assessment Organizations) via the Cyber ABThe False Claims Act AngleDOJ Civil Cyber-Fraud InitiativeThe False Claims Act (DOJ overview)The Hosts & ShowSwishGIST 360CONNECT WITH USGot an idea for a future episode? Want to be a guest? Let us know.Brian Lake - blake@swishdata.comSean Applegate - sapplegate@swishdata.comSubscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません