This interview with Regan Edens (CMMC-AB Chairman of the Standards Management Committee) clarifies clouds and CMMC, FedRAMP, and DFARS questions for Organizations Seeking Certification (OSCs)
Author: Amira Armond
CMMC Level 3 Assessment Guide Webinar and Review
The CMMC Level 3 Assessment Guide is published! Video about how to read and use it. Critical review of the guide by Amira Armond.
CMMC-AB Jeff Dalton Interview #2 – C3PAOs, CAs, Instructors, Ethics
Second interview with Jeff Dalton (CMMC-AB) and Amira Armond (CMMCAudit.org) on the topics of C3PAOs, CAs, Instructors, and Ethics
Registered Practitioner Home
CMMC Registered Practitioner is abbreviated “CMMC RP” The CMMC RP is a person who pays $500 a year to the Cyber-AB to be advertised as someone who can help companies prepare for the CMMC. Here are the benefits of working with a CMMC Registered Practitioner That is it. Notice I didn’t say anything about cybersecurity Read More
CMMC Level 1 Assessment Guide and Review
Video explanation from the authors of the CMMC Level 1 Assessment Guide (CMU-SE), and review by CMMCaudit.org
CMMC RM.2.142 Scan for vulnerabilities in organizational systems
This article is an in-depth review of the CMMC Level 2 Requirement RM.2.142 on the topic of vulnerability scanning. I break out frequently asked questions and reference other requirements that are related to vulnerability scanning. This requirement also applies to current DFARS 252.204-7012 and NIST SP 800-171 organizations that hold CUI
Answers about C3PAOs, Assessors, and other CMMC Professional questions
Jeff Dalton from the CMMC Accreditation Body Board of Directors was kind enough to provide answers to my burning questions about…
Webinar on CMMC Level 1 by the Software Engineering Institute (CMU)
This webinar is a great resource for organizations no matter what CMMC level you expect to need. It is released by Carnegie Mellon University’s Software Engineering Institute. This is the organization that helped the DoD develop the original CMMC model. Their recommendations are very authoritative. Here are the resources that SEI recommends: DIB Cybersecurity program: Read More
CMMC News Rollup November 19 2020
Hello all, Lots of different topics in this news article. I hope they help you! – Amira Armond Registered Practitioners and RPOs are official! The CMMC-AB started releasing badges to Registered Practitioners on November 17th. If you are a Registered Practitioner candidate that has 1) finished the background check. 2) finished the training. 3) signed Read More
Where is the Easy Button for CMMC? Why MSPs may be the solution.
CMMC and DFARS compliance is too expensive for small businesses. This article describes “easy button” solutions such as a CMMC MSP, using …
CMMC News Rollup – October 25, 2020
Hello all, Here are the latest third party articles and topics regarding CMMC, DFARS, and NIST 800-171 compliance. Best of luck in your compliance journey! – Amira DFARS 7012 , 7019, 7020 DoD Self Assessments Due This list has some ‘dumb’ questions and some ‘smart’ questions, based on my conversations with contractors in the last Read More
CMMC Basics – the Full Details
In-depth article about CMMC basics such as where it came from, what purpose it is trying to achieve, timeframe for rollout, and…
Address 19 CMMC Practices with Cybersecurity Training
This article gives advice on how a quality cyber-awareness training program helps your organization meet 19+ CMMC practice requirements
CMMC ML.2.999 Developing an effective CMMC Policy
This webinar is published by Carnegie Mellon University’s Software Engineering Institute (SEI) – the co-authors of the CMMC Model. Their guidance about the CMMC should be considered authoritative. At CMMC level 2 and above, organizations are expected to have policies supporting their security program. Here are my notes from the webinar. Policies are a way Read More
Introducing the CMMC Kill Chain – Zero to full compliance
Author: Tom Cornelius| Senior Partner at ComplianceForge | Founder & Contributor at Secure Controls Framework (SCF) Originally published on LinkedIn on October 19, 2020 The concept of creating a “CMMC Kill Chain” started off as a bit of a dare… kind of a “Here! Hold my coffee!” moment among a small group of CMMC practitioners to Read More
CMMC Level 4 – Discussion on Process Maturity – ML.4.996
This video from Carnegie Mellon Software Engineering Institute (co-authors of the CMMC Model) discusses CMMC Level 4 Maturity. The specific topic is CMMC requirement ML.4.996 “Review and measure [DOMAIN NAME] activities for effectiveness” SEI Blog: https://insights.sei.cmu.edu/sei_blog/cybersecurity-maturity-model-certification-cmmc/
NIST SP 800-171 Discussion for CMMC
Why is there a page for NIST SP 800-171 on a CMMC website? The NIST standard, as described in a document named “NIST Special Publication 800-171” is a set of 110 security best practices that are CURRENTLY required for all DoD contractors that deal with Controlled Unclalssified Information. You can tell if your contract requires Read More