Remove blog cybersecurity-risk-assessment-framework
article thumbnail

[ANSWERED] Who is Responsible for Protecting CUI?

Etactics

While working with CUI, you must have the proper cybersecurity safeguards and measures in place. A good example of this is through the Cybersecurity Maturity Model Certification (CMMC) program. Did you know that the DoD is migrating to using only the CMMC framework? So who exactly needs to abide by these regulations?

article thumbnail

CMMC Data Flow Diagrams: An Ultimate Guide

Etactics

The Cybersecurity Maturity Model Certification (CMMC) program protects federal information from unauthorized disclosure. Organizations will either self-assess or undergo a third party assessment of security requirements. This blog focuses on how organizations define those boundaries. What is an authorization boundary?

59
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

NIST SP 800-171 vs 800-53: Everything You Need to Know

Etactics

The National Institute for Standards and Technology (NIST) publishes pioneering cybersecurity standards. NIST SP 800-53 is a catalog of security controls used in the risk management framework (RMF). Image Source: NIST SP 800-53 Assessment NIST SP 800-53A facilitates control assessments.

article thumbnail

All CMMC Version 2.0 Changes and Their Impact

Etactics

On November 4, 2021, the Acquisition and Sustainment Office of the Under Secretary of Defense (OUSD A&S) announced a new strategic direction for the Cybersecurity Maturity Model Certification (CMMC) framework. This blog will assess these changes and discuss their impacts. Like the title of this blog post says, CMMC 2.0

52
article thumbnail

CMMC-AB May Town Hall: Key Takeaways

Etactics

Since our Town Hall blogs summarize the latest news from the leading CMMC authorities, here were our key takeaways from this presentation: Only controls with a value of 1 point are allowable on a POA&M during certification. Consider voluntary assessments high assurance today and valid for 3-4 years.

article thumbnail

CMMC-AB November 30 Town Hall: Key Takeaways and Unanswered Questions

Etactics

Table of Contents Town Hall Overview Credits for Exam Vouchers C3PAO Assessment Vouchers Renewals On Proposed Changes in CMMC 2.0 It leads up to the news of the Department of Defense (DoD) releasing the guidance and documentation on the CMMC assessment scoping. the CMMC-AB planned to charge C3PAOs for each assessment.

article thumbnail

CMMC GRC Toolset Essentials: A Closer Look

Etactics

The Cybersecurity Maturity Model Certification (CMMC) will introduce third-party verification of cybersecurity requirements. Organizations may turn to governance, risk, and compliance (GRC) applications to organize artifacts. A few years ago, a blog summarized the requirements for CMMC-focused GRC applications.