GRC Academy

GRC Academy

por Jacob Hill
Temporada 1

Cloud Security & DFARS 7012 Compliance with Michael Greenman from Deltek

In this episode Jacob speaks with Michael Greenman from Deltek. Michael has worked in government and cloud-based technology for over 20 years, and currently works at Deltek in the Product Strategy group and is the evangelist for cybersecurity compliance and cloud services! Michael shares Deltek's perspective on security and compliance as a cloud service provider. Here are some highlights from the episode: How Michael got into cybersecurity Deltek's government clouds DFARS 252.204-7012's C - G incident reporting requirements How cloud providers can demonstrate FedRAMP moderate equivalency What is a shared responsibility matrix The need for a defense focused CSP / ESP / MSP marketplace Follow Michael on LinkedIn: https://www.linkedin.com/in/michael-greenman-94952a3/ Deltek website: https://www.deltek.com/ ----------- Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform! Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e15&utm_campaign=courses Need a FedRAMP authorized Password Manager? Start a free 14-day trial of Keeper: https://grcacademy.io/ref/keeper/b2b-trial/ See the CMMC controls that Keeper meets: https://grcacademy.io/ref/keeper/cmmc-controls-sheet/

CMMC Insights with Redspin Assessor Thomas Graham

In this episode Jacob speaks with Dr. Thomas Graham who is a CMMC assessor. Thomas is the Vice President and CISO at Redspin, and Redspin is the first CMMC Third Party Assessor Organization (C3PAO)! This episode has a lot of great information for the defense industrial base!Here are some highlights from the episode: Redspins' experience becoming the first C3PAO Notable changes in NIST 800-171 r3 CMMC challenges and misconceptions Tips for selecting the right CMMC consultant and assessor Other countries interested in CMMC Each phase of the CMMC assessment process What CMMC practices can be POA&M'd according to current guidance And more! Follow Thomas on LinkedIn: https://www.linkedin.com/in/tgrahamphd/ Redspin website: https://www.redspin.com ----------- Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform! Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e14&utm_campaign=courses Need a FedRAMP authorized Password Manager? Start a free 14-day trial of Keeper: https://grcacademy.io/ref/keeper/b2b-trial/ See the CMMC controls that Keeper meets: https://grcacademy.io/ref/keeper/cmmc-controls-sheet/

CMMC Rulemaking with Jacob Horne

In this episode Jacob Hill talks with Jacob Horne from Summit 7! Jacob Horne is Summit 7's Chief Security Evangelist, and has a unique genetic superpower that allows him to delve into NIST publications & government regulations without experiencing even a hint of boredom! In the episode Jacob Horne explains the history leading up to the CMMC program, when CMMC may be required, and the significance of the FAR CUI rule! Here are some key topics we discussed: How he started in cybersecurity The history leading up to CMMC What is rulemaking The two CMMC rules we are waiting on When CMMC may appear in contracts The FAR CUI rule and its importance Why DHS and VA regulations were silent on NIST 800-171 When will the FAR CUI rule drop? Follow Jacob on LinkedIn: https://www.linkedin.com/in/jacob-evan-horne/ Summit 7 website: https://www.summit7.us/ Jacob Horne's Deep dive on CMMC rulemaking timeline: https://www.youtube.com/watch?v=qyLDQxo-YPg Federal Rulemaking book: https://www.amazon.com/Rulemaking-Government-Agencies-Write-Policy/dp/1483352811/ ----------- Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform! Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e13&utm_campaign=courses Need a FedRAMP authorized Password Manager? Start a free 14-day trial of Keeper: https://grcacademy.io/ref/keeper/b2b-trial/ See the CMMC controls that Keeper meets: https://grcacademy.io/ref/keeper/cmmc-controls-sheet/

Talking Cybersecurity with Dr Ron Ross of NIST

In this episode Jacob talks with Dr. Ron Ross from NIST! This is the final of a three-part series with Dr. Ross. In the episode Dr. Ross shares his thoughts on topics like ChatGPT, zero trust, his top 5 security controls, advice to folks new to cybersecurity, and much more! Here are some key topics we discussed: Top challenges in federal cybersecurity compliance How to enable positive cybersecurity culture The missing strategic view in cybersecurity Zero Trust LLMs like ChatGPT The importance of managing complexity Dr. Ross's top 5 critical security controls Career advice to folks new to cybersecurity Dr. Ross is the author of multiple publications including Risk Management Framework (RMF), NIST 800-53, NIST 800-171, and many more! Dr. Ross leads the FISMA Implementation Project which includes the development of security standards and guidelines for the federal government, contractors, and the United States critical infrastructure. He also leads the Joint Task Force, an interagency group that includes the DoD, U.S. Intelligence Community, and the Committee on National Security Systems, with responsibility for developing a unified information security framework for the federal government and its contractors. Follow Ron on LinkedIn: https://www.linkedin.com/in/ronrossecure/ NIST CSRC Website: https://csrc.nist.gov/ ----------- Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform! Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e12&utm_campaign=courses Need a FedRAMP authorized Password Manager? Start a free 14-day trial of Keeper: https://grcacademy.io/ref/keeper/b2b-trial/ See the CMMC controls that Keeper meets: https://grcacademy.io/ref/keeper/cmmc-controls-sheet/

NIST 800-171 r3 August 2023 Status Update with Dr Ron Ross

In this episode Jacob talks with Dr. Ron Ross from NIST! This is the 2nd of a three-part series with Dr. Ross. In the episode Dr. Ross shares a status update on NIST 800-171 revision 3. At the time of this recording, NIST has released the 1st initial draft, and the 1st public comment period has closed. Here are some key topics we discussed: Notable changes in NIST 800-171 r3 Thoughts on public comments Strategy on the ODPs Encryption (FIPS 140) control ODP Independent Assessment control Security Protection Assets Implementation examples Dr. Ross is the author of multiple publications including Risk Management Framework (RMF), NIST 800-53, NIST 800-171, and many more! Dr. Ross leads the FISMA Implementation Project which includes the development of security standards and guidelines for the federal government, contractors, and the United States critical infrastructure. He also leads the Joint Task Force, an interagency group that includes the DoD, U.S. Intelligence Community, and the Committee on National Security Systems, with responsibility for developing a unified information security framework for the federal government and its contractors. Follow Ron on LinkedIn: https://www.linkedin.com/in/ronrossecure/ NIST CSRC Website: https://csrc.nist.gov/ ----------- Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform! Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e11&utm_campaign=courses Need a FedRAMP authorized Password Manager? Start a free 14-day trial of Keeper: https://grcacademy.io/ref/keeper/b2b-trial/ See the CMMC controls that Keeper meets: https://grcacademy.io/ref/keeper/cmmc-controls-sheet/

NIST Cybersecurity History with Dr Ron Ross

In this episode Jacob talks with Dr. Ron Ross from NIST! This is the 1st of a three-part series with Dr. Ross. In the episode Dr. Ross shares the fascinating history of NISTs involvement in cyber security! Here are some key topics we discussed: How he started at NIST and the projects he has worked on NIST's and the Joint Task Force's Mission How he convinced the DoD to transition from DIACAP to RMF The history of continuous monitoring program The origins of NIST 800-171 Why NIST did not adopt ISO 27001 The goal of NIST 800-160 Dr. Ross is the author of multiple publications including Risk Management Framework (RMF), NIST 800-53, NIST 800-171, and many more! Dr. Ross leads the FISMA Implementation Project which includes the development of security standards and guidelines for the federal government, contractors, and the United States critical infrastructure. He also leads the Joint Task Force, an interagency group that includes the DoD, U.S. Intelligence Community, and the Committee on National Security Systems, with responsibility for developing a unified information security framework for the federal government and its contractors. Follow Ron on LinkedIn: https://www.linkedin.com/in/ronrossecure/ NIST CSRC Website: https://csrc.nist.gov/ ----------- Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform! Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e10&utm_campaign=courses Need a FedRAMP authorized Password Manager? Start a free 14-day trial of Keeper: https://grcacademy.io/ref/keeper/b2b-trial/ See the CMMC controls that Keeper meets: https://grcacademy.io/ref/keeper/cmmc-controls-sheet/

Securing the Oil and Gas Industry with Industrial OT Cybersecurity Expert Joseph Loomis

In this episode Jacob talks with operational technology (OT) cybersecurity expert Joseph Loomis! Joseph is the President of Secrabus Inc where he performs cybersecurity assessments on Oil & Gas companies to help elevate their security posture and protect their critical assets. Joseph shares his experiences after more than 15 years in the Oil & Gas industrial control system (ICS) and OT cybersecurity space. Here are some key topics we discussed: How he started in cybersecurity The just in time deliverability aspect of Oil & Gas IT and OT convergence Defense in depth architecture GRC Standards that apply to the Oil & Gas industry Purdue Model for ICS Security His risk assessment methodology Interesting stories And more! Follow Joseph on LinkedIn: https://www.linkedin.com/in/josephloomis/ Secrabus Inc's Website: https://secrabus.com/ ----------- Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform! Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e9&utm_campaign=courses Need a FedRAMP authorized Password Manager? Start a free 14-day trial of Keeper: https://grcacademy.io/ref/keeper/b2b-trial/ See the CMMC controls that Keeper meets: https://grcacademy.io/ref/keeper/cmmc-controls-sheet/

From Aircraft Maintenance to GRC and Cybersecurity with Jonathan Fisher

In this episode Jacob talks with GRC professional Jonathan Fisher. Jonathan shifted into the GRC field after 20 years in the military supporting aircraft maintenance, and explains how others can do the same! Here are some key topics we discussed: What GRC is How he transitioned into GRC and cybersecurity How nontechnical folks can transition into cybersecurity by starting in a GRC role How most folks already have transferrable experience What GRC frameworks to focus on How to use LinkedIn to boost your career Follow Jonathan on LinkedIn: https://www.linkedin.com/in/jonfisher11/ ----------- Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform! Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e8&utm_campaign=courses Need a FedRAMP authorized Password Manager? Start a free 14-day trial of Keeper: https://grcacademy.io/ref/keeper/b2b-trial/ See the CMMC controls that Keeper meets: https://grcacademy.io/ref/keeper/cmmc-controls-sheet/

Privacy Laws and GRC with Attorney Donata Stroink-Skillrud

In this episode Jacob speaks with privacy attorney Donata Stroink-Skillrud. Donata is the chair of the American Bar Association’s ePrivacy committee, and has an excellent understanding of privacy laws in the US and the EU. She shares the impact of US and EU privacy laws on businesses, how they can plan to comply, and much more! Here are some key topics we discussed: The importance of privacy laws Differences between EU and US approaches to privacy The impact of GDPR and why many consider it to be the gold standard in privacy laws Current and emerging state-level privacy laws in the US Implications of privacy laws for small businesses The importance of only collecting the information you need The status of the US's federal privacy law and how it compares to the GDPR How GRC compliance frameworks like NIST’s Privacy Framework and ISO 27001 can help comply Donata's website: https://termageddon.com Follow Donata on LinkedIn: https://www.linkedin.com/in/donata-stroink-skillrud/ ----------- Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform! Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e7&utm_campaign=courses Need a FedRAMP authorized Password Manager? Start a free 14-day trial of Keeper: https://grcacademy.io/ref/keeper/b2b-trial/ See the CMMC controls that Keeper meets: https://grcacademy.io/ref/keeper/cmmc-controls-sheet/

Insights from CMMC Consultant and Assessor Koren Wise

In this episode Jacob speaks with Koren Wise who is a highly experienced CMMC consultant, assessor, and instructor. Koren offers insights from her experience helping companies prepare for CMMC, and gives advice on hiring the right CMMC consultant and assessor for your business - and much more!. Here are some of the topics we discussed: How she got to where she is today Common misconceptions businesses have about CMMC Who should take the CMMC Certified Professional (CCP) course Real world problems and solutions What is a CUI enclave? Addressing CUI data sprawl in a business Joint Surveillance Assessments Managing CMMC compliance like a project Hiring the right CMMC consultant Hiring the right CMMC assessor Follow Koren on LinkedIn: https://www.linkedin.com/in/koren-wise/ Koren's website: https://www.wtinetworks.com ----------- Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform! Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e6&utm_campaign=courses Need a FedRAMP authorized Password Manager? Start a free 14-day trial of Keeper: https://grcacademy.io/ref/keeper/b2b-trial/ See the CMMC controls that Keeper meets: https://grcacademy.io/ref/keeper/cmmc-controls-sheet/
5 de 6