『The GIST of Govt IT』のカバーアート

The GIST of Govt IT

The GIST of Govt IT

著者: Swish
無料で聴く

The weekly show that breaks down ideas, innovations and decisions that cut through complexity and offer real insights from the intersection of technology and the mission.

© 2026 The GIST of Govt IT
マネジメント マネジメント・リーダーシップ 政治・政府 政治学 経済学
エピソード
  • A Pause, Not a Pass on CMMC
    2026/07/21
    On July 13, the Department of War hit pause on one of the most consequential compliance regimes in the defense industrial base. In Episode 14 of The GIST of Govt IT, Brian and Sean break down the suspension of CMMC Phase II — the third-party assessment requirement that was set to take effect November 10 — and what it actually means for the thousands of contractors caught in the middle. Sean's message is blunt: this is a pause, not a repeal. The requirement to protect controlled unclassified information isn't going anywhere, and the smart move is to keep marching toward NIST SP 800-171 compliance regardless of what the 60-day CMMC Reform Task Force recommends. The conversation digs into the real economics that triggered the review, the False Claims Act lawsuits already settling in the six-to-eight-figure range for contractors who attested to compliance they didn't have, why ISO 27001 is the closest on-ramp for commercial companies new to the space, and a clear Monday-morning playbook. Plus, CISA Director Nick Andersen's hacker name (hint: he's a Matrix fan).Resources Mentioned in This EpisodeThe Core StoryDepartment of War release: "Forging the Arsenal of Freedom: DoW Suspends CMMC Phase II Requirements" (July 13)Office of Industrial Base Growth version of the announcementFederal News Network coverageThe CMMC Reform Task Force RFI (responses due 12:00 PM ET, Friday, August 14) — posted on SAM.gov Legal & Advisory AnalysisMorgan Lewis — "Cybersecurity Obligations Remain"Crowell & Moring — DFARS obligations & contractor action stepsGreenberg Traurig — the July 13 memoranda explained Standards & Frameworks ReferencedNIST SP 800-171 Rev. 2 (protecting Controlled Unclassified Information) NIST SP 800-171 Rev. 3CMMC Program overview (DoD CIO)ISO/IEC 27001 (the commercial on-ramp Sean recommends)DFARS 252.204-7012 (safeguarding covered defense information)FIPS 140 validated encryptionCompliance & Assessment ConceptsSPRS (Supplier Performance Risk System) — where self-assessments are postedDIBCAC (Defense Industrial Base Cybersecurity Assessment Center)C3PAO (CMMC Third-Party Assessment Organizations) via the Cyber ABThe False Claims Act AngleDOJ Civil Cyber-Fraud InitiativeThe False Claims Act (DOJ overview)The Hosts & ShowSwishGIST 360CONNECT WITH USGot an idea for a future episode? Want to be a guest? Let us know.Brian Lake - blake@swishdata.comSean Applegate - sapplegate@swishdata.comSubscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.
    続きを読む 一部表示
    24 分
  • Fed Christmas in July? The OMB M-26-14 Holiday Rush Begins!
    2026/07/13
    Level One by Christmas. Level Two by Valentine's Day. Level Three by Independence Day. That's the OMB M-26-14 logging mandate clock federal agencies are now racing against — and if you don't want to spend your holidays at the office, it's time to start planning now! In Episode 13 of The GIST of Govt IT, Brian and Sean dig into OMB M-26-14 on the eve of Sean's fireside chat with CISA Director Nick Andersen. Sean breaks down what actually changed: the shift from long-term log hoarding (30 months of cold retention) to an outcomes-driven model focused on defending the cyberspace effectively, and the dramatic expansion of scope to include IoT and operational technology — the unmanaged, line-of-business-owned, often third-party-managed devices that CISOs have never had eyes on. The conversation walks through the mechanics: the Logging Reference Architecture (LRA) dropping mid-August, the 90-day plan requirement, and the three maturity levels with their rising inventory-and-logging thresholds (70/50, 80/80, 90/90). Brian and Sean unpack why asset inventory is the real "creeper" that will blindside teams, why OT discovery requires drop-in kits and passive network detection rather than active scanning that can break physical systems, why centralized logging matters for coordinated FSEB-wide defense, and how to think about "three-for-one" investments that solve this mandate and other capability gaps at once. ----------RESOURCES MENTIONED IN THIS EPISODEThe Core Policy- OMB M-26-14 (new logging mandate, issued May 22)- OMB M-21-31 (the rescinded SolarWinds-era predecessor)- OMB M-26-14 Signals a New Era for Cyber Visibility (BLOG)Background: The SolarWinds / Sunburst Hack- CISA on the SolarWinds supply chain compromise- GAO review of federal M-21-31 log management adoptionThe Maturity Milestones (per the memo)- Level 1 (Basic) — ~120 days after LRA: 70% of assets inventoried, 50% logged centrally- Level 2 (Intermediate) — ~Valentine's Day 2027: 80% inventoried, 80% logged- Level 3 (Advanced) — ~320 days / Independence Day 2027: 90% inventoried, 90% loggedOT/IoT Discovery & Network Detection Solutions Referenced- Zeek- Corelight (commercial Zeek / "Sericana" reference- Armis- Dragos- Nozomi Networks SIEM, SOAR & SOC Modernization- Continuous Threat Exposure Management (CTEM)- CISA SIEM-as-a-service with ElasticRelated Episodes- Episode 12: The Founding Father's Guide to Federal IT- Episode 7: Iran Came for the US Dams and We Got Lucky: Frontline Insight from the OT Fight- Episode 6: Cupcakes and OODA Loops: Inside(r)'s Insights Into the New Federal Cyber PlaybookUpcoming Events- July 14 Breakfast Briefing at the National Press Club — "When the Perimeter Disappears: Securing the Converged Federal Enterprise Across IT, IoT, and OT": - July 14 Mid-Year Federal IT Priority Setting Session with a fireside chat featuring CISA Director Nick AndersenThe Hosts & Show- Swish Data - GIST 360 ----------CONNECT WITH USGot an idea for a future episode? Want to be a guest? Let us know.Brian Lake - blake@swishdata.comSean Applegate - sapplegate@swishdata.comSubscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.
    続きを読む 一部表示
    36 分
  • The Founding Fathers' Guide to Federal IT
    2026/07/06

    Happy 250th birthday, America. In this special shortened Fourth of July episode of The GIST of Govt IT, Brian and Sean keep it snackable for the beach-and-boat crowd — kicking off with a debate over favorite founding fathers before turning to a rundown of the GIST 360 summer event lineup. Sean previews what's coming: a July 14 breakfast briefing at the National Press Club on securing the converged IT/OT/IoT enterprise; a mid-year federal IT priority-setting session featuring a fireside chat with CISA Director Nick Andersen, an ATARC roundtable on operationalizing continuous threat exposure management, as well as several webinars on deck. If you want to know where federal IT leaders are placing their bets for the last stretch of the fiscal year, this is your map to the conversations that matter. Plus a kite-surfing Ben Franklin!

    ----------

    RESOURCES MENTIONED IN THIS EPISODE

    Upcoming GIST 360 Events

    - July 14 — Breakfast Briefing, National Press Club - "When the Perimeter Disappears: Securing the Converged Federal Enterprise Across IT, IoT, and OT"

    - July 14 — Mid-Year Federal IT Priority Setting & Listening Session, The Riggs Rooftop (9th & E, Washington DC, 5:30–7:30 PM)

    - August 13 — Webinar: "From the Edge to the Enterprise: The Future of Mission-Critical Infrastructure"

    - August 25 — Webinar: "Rethinking Command and Control Resiliency at the Tactical Edge"

    The Hosts & Show
    - Swish
    - GIST 360
    ----------

    CONNECT WITH US

    Got an idea for a future episode? Want to be a guest? Let us know.

    Brian Lake - blake@swishdata.com

    Sean Applegate - sapplegate@swishdata.com

    Subscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.


    続きを読む 一部表示
    19 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません