Powered by RND
PodcastsTechnologySum IT Up: CMMC News Roundup

Sum IT Up: CMMC News Roundup

Summit 7
Sum IT Up: CMMC News Roundup
Latest episode

Available Episodes

5 of 100
  • What is DFARS 252.204-7008?
    After 100 episodes diving into every possible rabbit hole to help illuminate the bigger picture around CMMC we're starting over at square zero: the “DFARS Cyber Series” of contract clauses. First up: the solicitation provision 252.204-7008. Although 7008 doesn't have the notoriety of it's big brother DFARS 252.204-7012, it is the first domino that triggers the cascade of cybersecurity compliance obligations that ultimately culminate in CMMC assessment. Register for CS2 Reston: https://cs2.cloud/reston Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo DFARS 252.204-7008: https://www.acquisition.gov/dfars/252.204-7008-compliance-safeguarding-covered-defense-information-controls. The 2016 final rule: https://www.federalregister.gov/documents/2016/10/21/2016-25315/defense-federal-acquisition-regulation-supplement-network-penetration-reporting-and-contracting-for
    --------  
    36:10
  • DOJ vs Small Defense Contractors
    The Department of Justice finally did it: they went after a small defense contractor for failure to comply with their contractually obligated cybersecurity requirements. This case has it all from fake SPRS scores to whistleblowers getting paid hundreds of thousands of dollars to contractors paying millions in fines. All thanks to the same set of contract clauses in every DoD contract and the same errors committed by the vast majority of defense contractors. Register for CS2 Reston: https://cs2.cloud/reston Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo DOJ press release: https://www.justice.gov/opa/pr/defense-contractor-morsecorp-inc-agrees-pay-46-million-settle-cybersecurity-fraud Law firm press release: https://www.prnewswire.com/news-releases/morsecorp-agrees-to-pay-4-6-million-to-settle-landmark-cybersecurity-false-claims-act-case-brought-by-whistleblower-law-collaborative-client-302412118.html?tc=eml_cleartime FCA w/ Stephanie Siegmann: https://youtu.be/d1yweDy2wV4?si=_CgQ3WTV2ynVbEyL FCA w/ Alex Canizares: https://youtu.be/Tga0krfIrEk?si=oOXG-zvYcV_mGTL2
    --------  
    23:03
  • March AB Townhall Recap
    The Cyber AB is back with their monthly Town Hall meeting which can only mean one thing; Joy is here to co-host the show, and we are gonna break down the information distributed during the meeting. The ecosystem is growing, CMMC is going international, and so much more! Tune in to see what we have to say! Register for CS2 Reston: https://cs2.cloud/reston Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo Sum IT Up ‘Canada's CMMC': https://youtu.be/AFe8CeIosYk?si=3Um3sXa1IEoTvAbD AB Town Halls: https://cyberab.org/News-Events/Town-Halls/Details/march-town-hall
    --------  
    23:22
  • Canada’s CMMC
    The Canadian Program for Cyber Security Certification (CPCSC) requires defense contractors to undergo assessment against NIST SP 800-171 revision 3. That's a big problem for contractors who also do work for the U.S. Department of Defense because CMMC currently evaluates NIST SP 800-171 revision 2 and will for quite some time. In this episode we dive into what we know about Canada's version of CMMC and how close (or far) we are from reciprocity between the programs and what might be done to close the gap. Register for CS2 Reston: https://cs2.cloud/reston Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo CPCSC Info: https://www.canada.ca/en/public-services-procurement/services/industrial-security/security-requirements-contracting/cyber-security-certification-defence-suppliers-canada.html
    --------  
    39:59
  • C3PAO Authorization Audit Pt. 4 of 4
    At long last we've come to the fourth and final episode covering every finding and allegation in the DoD Inspector General Report on the CMMC process for authorizing 3rd-party assessment organizations. So far none of the 10 findings come anywhere close spelling doom for the CMMC program. Perhaps the juiciest scandals were saved for last? Register for CS2 Reston: https://cs2.cloud/reston Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo DoD IG report: https://www.dodig.mil/reports.html/Article/4028189/audit-of-the-dods-process-for-authorizing-third-party-organizations-to-perform/ IG Report Part 1: https://youtu.be/RNafaUlgBGo?si=4prcpAp3GUAhk8nN IG Report Part 2: https://youtu.be/_kU7N2uI3xU?si=li1PwnG-FRSBjzyb IG Report Part 3: https://youtu.be/3ND8RG2cKEc?si=ap5N5jasjYSztUVn
    --------  
    22:12

More Technology podcasts

About Sum IT Up: CMMC News Roundup

It's difficult to keep up with all of the moving parts that make up the Department of Defense's Cybersecurity Maturity Model Certification Program. It's even more difficult to keep up with the relevant bits and bites that influence CMMC. This weekly podcast sums up the news and developments relevant to CMMC; DFARS and other regulations; and NIST standards such as SP 800-171, SP 800-53, the NIST Cybersecurity Framework, and others.
Podcast website

Listen to Sum IT Up: CMMC News Roundup, The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features

Sum IT Up: CMMC News Roundup: Podcasts in Family

Social
v7.15.0 | © 2007-2025 radio.de GmbH
Generated: 4/15/2025 - 6:14:14 AM