• Sum IT Up: CMMC News Roundup

  • 著者: Summit 7
  • ポッドキャスト

Sum IT Up: CMMC News Roundup

著者: Summit 7
  • サマリー

  • It's difficult to keep up with all of the moving parts that make up the Department of Defense's Cybersecurity Maturity Model Certification Program. It's even more difficult to keep up with the relevant bits and bites that influence CMMC. This weekly podcast sums up the news and developments relevant to CMMC; DFARS and other regulations; and NIST standards such as SP 800-171, SP 800-53, the NIST Cybersecurity Framework, and others.

    Copyright 2025 by Summit 7
    続きを読む 一部表示

あらすじ・解説

It's difficult to keep up with all of the moving parts that make up the Department of Defense's Cybersecurity Maturity Model Certification Program. It's even more difficult to keep up with the relevant bits and bites that influence CMMC. This weekly podcast sums up the news and developments relevant to CMMC; DFARS and other regulations; and NIST standards such as SP 800-171, SP 800-53, the NIST Cybersecurity Framework, and others.

Copyright 2025 by Summit 7
エピソード
  • DoD’s Parameters for SP 800-171r3
    2025/04/24

    DoD has officially released their parameters for NIST SP 800-171 revision 3 requirements. Defense contractors now have a clear picture of their future compliance requirements and what assessors will ask for under “CMMC 3.0”. But if SP 800-171r3 won't be required for some time, why did the DoD publish their organizationally defined values? In this episode we dive into the basics of “ODPs”, why they matter, and how contractors can leverage them now to future-proof their systems against regulatory updates.

    Register for CS2 Reston: https://cs2.cloud/reston

    Pathfinder 101: https://www.summit7.us/pathfinder

    Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

    Memo: https://dodcio.defense.gov/cmmc/Resources-Documentation/

    ODP Deep Dive: https://www.youtube.com/watch?v=QXfzSo4_F54

    Deep Dive w/ Ron Ross: https://www.youtube.com/watch?v=x37V6fE-ies

    171r3: https://www.youtube.com/watch?v=TAzYQjLfPY0

    7012 Class Deviation: https://www.youtube.com/watch?v=voziZRAMvv4

    続きを読む 一部表示
    29 分
  • What is DFARS 7012?
    2025/04/17

    Most people mistaken believe that their cybersecurity requirements stem from the Cybersecurity Maturity Model Certification Program (CMMC). CMMC is simply a verification program that proves if you have implemented the requirements imposed by DFARS clause 252.204-7012. Ultimately, DFARS clause 252.204-7012 is the center of gravity for all the cybersecurity stuff that comes with being a defense contractor. This week is an important primer on DFARS 7012 because even though it's only 13 paragraphs long, few people take the time to read it closely.

    Register for CS2 Reston: https://cs2.cloud/reston

    Pathfinder 101: https://www.summit7.us/pathfinder

    Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

    DFARS 7008: https://youtu.be/vgrRGIWboKc?si=TFuX_wYBgfDhNQ8X

    DFARS 7012: https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.

    The History of CMMC: https://youtu.be/jbY2irZ1ePg?si=Khw6kLH5JnXfiTs6

    7012 Class Deviation: https://youtu.be/voziZRAMvv4?si=2TczM85cISzpd63V

    FedRAMP equivalency memo: https://youtu.be/torWNL3U7ZY?si=_tAubFpxJxtqrS6L

    続きを読む 一部表示
    39 分
  • What is DFARS 252.204-7008?
    2025/04/10

    After 100 episodes diving into every possible rabbit hole to help illuminate the bigger picture around CMMC we're starting over at square zero: the “DFARS Cyber Series” of contract clauses. First up: the solicitation provision 252.204-7008. Although 7008 doesn't have the notoriety of it's big brother DFARS 252.204-7012, it is the first domino that triggers the cascade of cybersecurity compliance obligations that ultimately culminate in CMMC assessment.

    Register for CS2 Reston: https://cs2.cloud/reston

    Pathfinder 101: https://www.summit7.us/pathfinder

    Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

    DFARS 252.204-7008: https://www.acquisition.gov/dfars/252.204-7008-compliance-safeguarding-covered-defense-information-controls.

    The 2016 final rule: https://www.federalregister.gov/documents/2016/10/21/2016-25315/defense-federal-acquisition-regulation-supplement-network-penetration-reporting-and-contracting-for

    続きを読む 一部表示
    36 分

Sum IT Up: CMMC News Roundupに寄せられたリスナーの声

カスタマーレビュー:以下のタブを選択することで、他のサイトのレビューをご覧になれます。