GRC Academy

GRC Academy

por Jacob Hill
Temporada 1

The Business Case for Information Security with Mark Nicholls

In this episode, Jacob speaks with Mr. Mark Nicholls! Mark is the CEO of Information Professionals Group and has over 30 years of experience! In the episode they discuss the business case for information security, and how cybersecurity professionals can effectively communicate with the C-suite and other business leaders! Here are some highlights from the episode: The Importance of information security in business The Importance of securing data How cyber professionals should engage with business leaders Roleplaying exercise - bad/good examples of a cyber pro trying to convince a CEO How active listening can help you make a difference Follow Mark on LinkedIn: https://www.linkedin.com/in/markdnicholls/ Information Professionals Group Website: https://www.informpros.com.au/ ----------- Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform! Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e25&utm_campaign=courses Need a FedRAMP authorized Password Manager? Start a free 14-day trial of Keeper: https://grcacademy.io/ref/keeper/b2b-trial/ See the CMMC controls that Keeper meets: https://grcacademy.io/ref/keeper/cmmc-controls-sheet/

How To Stop Social Engineering in Its Tracks with Chris Silvers

In this episode, Jacob speaks with Penetration Tester & Social Engineer Chris Silvers! Chris Silvers is the founder of CG Silvers Consulting! Chris has a vast amount of experience ranging from CMMC assessments to penetration testing. He even won the prestigious DEF CON black badge during the DEF CON 24 Social Engineering Capture the Flag (SECTF)! In this episode they focus on how organizations can defend against social engineering attacks! Here are some highlights from the episode: Winning the DEF CON SECTF black badge Social engineering tactics and tools CEO impersonation / fraud attacks How can GRC help defend against social engineering? Why businesses shouldn't start with a penetration test Follow Chris on LinkedIn: https://www.linkedin.com/in/cgsilvers/ Chris's Website: https://www.cgsilvers.com/ ----------- Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform! Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e24&utm_campaign=courses Need a FedRAMP authorized Password Manager? Start a free 14-day trial of Keeper: https://grcacademy.io/ref/keeper/b2b-trial/ See the CMMC controls that Keeper meets: https://grcacademy.io/ref/keeper/cmmc-controls-sheet/

ISO 27001 Essentials with Aron Lange

In this episode, Jacob speaks with ISO 27001 expert Aron Lange! Aron is the founder of the GRC Lab, and a Udemy instructor with more than 11,000 students! He is an experienced auditor for management systems based on ISO 27001, ISO 9001, ISO 27018 and ISO 22301. In this episode they discuss the essentials of ISO 27001 including the history of the standard and the changes in the latest revision, but also the significance of the organizations involved and the danger of ISO “certification paper mills.” Here are some highlights from the episode: The history of ISO 27001 Changes in ISO 27001:2022 Who are the IAF, accreditation bodies, and certification bodies? The importance of hiring an IAF affiliated certification body ISO scoping Maintaining an ISO certification Best practices for internal audits Follow Aron on LinkedIn: https://www.linkedin.com/in/aronlange/ Aron’s Udemy courses: https://www.udemy.com/user/aron-lange/ Aron’s Website: https://www.aronlange.com/ ----------- Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform! Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e23&utm_campaign=courses Need a FedRAMP authorized Password Manager? Start a free 14-day trial of Keeper: https://grcacademy.io/ref/keeper/b2b-trial/ See the CMMC controls that Keeper meets: https://grcacademy.io/ref/keeper/cmmc-controls-sheet/

Why Threat Intel is Essential for Vulnerability Management with Patrick Garrity

In this episode, Jacob speaks with cybersecurity researcher Patrick Garrity! Patrick Garrity is a seasoned security researcher at VulnCheck where he focuses on vulnerabilities, vulnerability exploitation and threat actors. In this episode they discuss the importance of integrating threat intelligence into vulnerability management using the Exploit Prediction Scoring System (EPSS), CISA Known Exploited Vulnerabilities Catalog, and the changes in CVSS 4.0! Here are some highlights from the episode: How Exploit Prediction Scoring System (EPSS) can predict exploitation How vulnerability scanners integrate EPSS CISA's Known Exploited Vulnerabilities (KEV) Catalog The national security implications of vulnerability management Follow Patrick on LinkedIn: https://www.linkedin.com/in/patrickmgarrity/ VulnCheck Website: https://vulncheck.com/ Thanks to our sponsor Keeper Security! Need a FedRAMP authorized Password Manager? See how Keeper can help you comply with CMMC: https://www.keepersecurity.com/cmmc/?utm_source=grcacademy&utm_medium=display&utm_campaign=cmmc_video Start a free 14-day trial of Keeper: https://grcacademy.io/ref/keeper/b2b-trial/ ----------- Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform! Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e22&utm_campaign=courses

The False Claims Act and The DOJ's Civil Cyber Fraud Initiative with Julie Bracker

In this episode, Jacob speaks with attorney Julie Bracker! Julie is the whistleblower attorney for both the Penn State University and Georgia Tech University FCA complaints. These complaints essentially allege the defendants misrepresented their compliance with NIST 800-171! They discuss the False Claims Act and the DOJ's Civil Cyber Fraud Initiative, and what federal contractors can do to avoid being the subject of a whistleblower complaint! Here are some highlights from the episode: What is the False Claims Act? What is the DoJ's Civil Cyber Fraud Initiative? What are the risks and rewards for whistleblowers? Who are the targets of the initiative? Can companies blindly rely on their MSP and be safe? How to quantify damages of cyber noncompliance fraud DoJ Civil Cyber Fraud settled lawsuits so far Georgia Tech and Penn State FCA cases Follow Julie on LinkedIn: https://www.linkedin.com/in/juliekeetonbracker/ Bracker & Marcus LLP Website: https://www.fcacounsel.com/ Penn State FCA Complaint: https://cdn.grcacademy.io/web/20240325204912/penn-state-university-false-claims-act-complaint.pdf Georgia Tech FCA Complaint: https://cdn.grcacademy.io/web/20240325204909/georgia-tech-university-false-claims-act-complaint.pdf 2023 DoJ Report of FCA settlements (more than $2.68 billion): https://www.justice.gov/opa/pr/false-claims-act-settlements-and-judgments-exceed-268-billion-fiscal-year-2023 ----------- Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform! Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e21&utm_campaign=courses Need a FedRAMP authorized Password Manager? Start a free 14-day trial of Keeper: https://grcacademy.io/ref/keeper/b2b-trial/ See the CMMC controls that Keeper meets: https://grcacademy.io/ref/keeper/cmmc-controls-sheet/

CMMC and Security Compliance in Higher Education

In this episode, Jacob speaks with a panel of information security experts from universities about CMMC and their experience preparing for it! They discuss security and compliance challenges at universities, the Penn State NIST 800-171 False Claims Act lawsuit, and much more! Here are some highlights from the episode: How universities are different from other types of organizations Different compliance requirements for universities Who is involved in the execution of a government contract? The drivers of cybersecurity compliance at universities Thoughts on the Penn State False Claims Act lawsuit How to drive positive cybersecurity change at a university CUI enclaves at universities Areas of CMMC that need clarification Here are the panelists: Jay Gallman - Duke University (https://www.linkedin.com/in/jay-gallman/) Kolin Hodgson - Notre Dame (https://www.linkedin.com/in/kolin-hodgson-cisa-cissp-4bbb9a/) Melissa Kimble - University of Maine (https://www.linkedin.com/in/melissa-kimble/) Wendy Epley - University of Arizona (https://www.linkedin.com/in/wendyepley/) Thanks to our sponsor Keeper Security! Need a secure file sharing solution? Register for a webinar showing how Defense Contractors can share sensitive information using Keeper: https://grcacademy.io/ref/keeper/webinar-cmmc-file-sharing-april-2024/ ----------- Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform! Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e20&utm_campaign=courses Need a FedRAMP authorized Password Manager? Start a free 14-day trial of Keeper: https://grcacademy.io/ref/keeper/b2b-trial/ See the CMMC controls that Keeper meets: https://grcacademy.io/ref/keeper/cmmc-controls-sheet/

AI's Impact on Cybersecurity Risk with Dr. Raghuram Srinivas of MetricStream

In this episode, Jacob talks to Dr. Raghuram Srinivas from MetricStream! They discuss the beginnings of AI, how it has evolved over time, and the risks and opportunities it presents to companies around the world! Raghuram is the Senior Vice President of Product Management at MetricStream. He is an AI expert and has worked in AI-focused roles at JPM Chase, KPMG, as well as the Watson Group at IBM. Here are some highlights from the episode: The history of AI How do large language models (LLMs) work? AI for GRC & GRC for AI Using AI in cyber operations The future of cyber risk Follow Ragu on LinkedIn: https://www.linkedin.com/in/raghuramsrinivas/ MetricStream website: https://www.metricstream.com/ ----------- Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform! Online cyber GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e19&utm_campaign=courses Need a FedRAMP authorized Password Manager? Start a free 14-day trial of Keeper: https://grcacademy.io/ref/keeper/b2b-trial/ See the CMMC controls that Keeper meets: https://grcacademy.io/ref/keeper/cmmc-controls-sheet/

Zscaler on FedRAMP and Zero Trust with Patrick Perry

In this episode, Jacob talks to Patrick Perry from Zscaler. They discuss Zscaler's experiences navigating the FedRAMP and DoD Impact Level processes as well as Zero Trust! Pat is a cybersecurity expert with over 20 years of experience. He currently works at Zscaler as Field CTO and is responsible for the alignment of Zscaler capabilities to the DoD and IC mission sets in order to provide dynamic, mission-focused, innovative approaches to enable transformation and zero trust to warfighter organizations. Zscaler U.S. Government Solutions enables the U.S government and their strategic partners to securely transform their networks and applications for a mobile and cloud-first world. Zscaler's FedRAMP Moderate/High/DoD IL5-authorized solutions ensure fast, secure connections between users and applications, regardless of device, location, or network. Here are some highlights from the episode: Zscaler's Approach to FedRAMP, DoD Impact Levels, and CMMC Shared Responsibility Between Cloud Service Providers and Users What Zero Trust is and how it relates to CMMC Zero Trust Pillars Thoughts on Federal Approach to Zero Trust Follow Patrick on LinkedIn: https://www.linkedin.com/in/perrypn2019/ Zscaler website: https://www.zscaler.com/ ----------- Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform! Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e18&utm_campaign=courses Need a FedRAMP authorized Password Manager? Start a free 14-day trial of Keeper: https://grcacademy.io/ref/keeper/b2b-trial/ See the CMMC controls that Keeper meets: https://grcacademy.io/ref/keeper/cmmc-controls-sheet/

Cyber Security Questionnaire Essentials with Derrich Phillips of Aspire Cyber

In this episode Jacob speaks with Derrich Phillips from Aspire Cyber about best practices and tips when filling out cybersecurity questionnaires. Derrich Phillips is a cybersecurity expert with over 20 years of experience in the field. He started his career in the Army's security operations center, defending networks against cyber attacks. As the founder of Aspire Cyber, he focuses on helping small companies prove their cybersecurity readiness to handle information for enterprise customers. Here are some highlights from the episode: How Derrich get into cybersecurity The what and why of security questionnaires How to save time and money while filling out a security questionnaires When to push back on overly burdensome requirements Check out this video where Derrich and I discuss how ChatGPT can be used in information security compliance: https://youtu.be/IAAJPJLBeaY Follow Derrich on LinkedIn: https://www.linkedin.com/in/derrichphillips/ Aspire Cyber website: https://www.aspirecyber.com/ ----------- Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform! Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e17&utm_campaign=courses Need a FedRAMP authorized Password Manager? Start a free 14-day trial of Keeper: https://grcacademy.io/ref/keeper/b2b-trial/ See the CMMC controls that Keeper meets: https://grcacademy.io/ref/keeper/cmmc-controls-sheet/

Behind the Curtain of Federal Rulemaking with Shauna Weatherly of FedSubK.com

In this episode Jacob speaks with Shauna Weatherly from FedSubK.com. Shauna recently retired from the federal government after serving more than 35 years in the federal acquisition / contracting space! During her career she served as chief of contracting, contracting officer representative, and as an advisor to the Civilian Agency Acquisition Council (CAAC). She even has direct experience in the federal rulemaking process, and contributed to FAR case 2017-016, also known as the FAR CUI rule, which will contractually require the implementation of NIST SP 800-171 on federal contracts. Join us as we pull back the curtain on the federal rulemaking process and more! Here are some highlights from the episode: Shauna’s background Steps and roles involved in the federal rulemaking process What is a FAR case? What is OIRA’s role? The relationship between the FAR and DFARS How to provide effective public comments on regulations Impacts of FAR case 2017-16 - CUI rule Impacts of FAR case 2021-17 - Cyber Threat and Incident Reporting and Information Sharing regulation Impacts of FAR case 2021-019 - Standardizing Cybersecurity Requirements for Unclassified Information Systems Follow Shauna on LinkedIn: https://www.linkedin.com/in/shauna-weatherly/ FedSubK website: https://www.fedsubk.com/ ----------- Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform! Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e16&utm_campaign=courses Need a FedRAMP authorized Password Manager? Start a free 14-day trial of Keeper: https://grcacademy.io/ref/keeper/b2b-trial/ See the CMMC controls that Keeper meets: https://grcacademy.io/ref/keeper/cmmc-controls-sheet/
4 de 6