Sum IT Up: CMMC News Roundup

The DoD's "Basic" Cybersecurity Isn't Basic at All

24 min · 6. elo 2026
jakson The DoD's "Basic" Cybersecurity Isn't Basic at All kansikuva

Kuvaus

The DoD says it's reducing cybersecurity burden on the Defense Industrial Base. At the same time, the first recommendation in the new "Brilliant at the Basics" campaign calls for phishing-resistant multi-factor authentication, a capability that goes well beyond today's NIST SP 800-171 requirements. In this episode we break down replay resistance vs. phishing resistance, explain why they are different security properties, and explore where phishing-resistant authentication fits into the NIST standards lifecycle. We also ask a simple question: If this is now considered "basic," why isn't it in the NIST control catalog yet? 800-63: https://csrc.nist.gov/pubs/sp/800/63/b/4/final Brilliant at the Basics: https://dowcio.war.gov/BrilliantBasics/

Kommentit

0

Ole ensimmäinen kommentoija

Rekisteröidy nyt ja liity Sum IT Up: CMMC News Roundup-yhteisöön!

Aloita maksutta

30 vrk ilmainen kokeilu

Kokeilun jälkeen 7,99 € / kuukausi. · Peru milloin tahansa

  • Podimon podcastit
  • 20 kuunteluaikaa / kuukausi
  • Lataa offline-käyttöön

Kaikki jaksot

169 jaksot

jakson The DoD's "Basic" Cybersecurity Isn't Basic at All kansikuva

The DoD's "Basic" Cybersecurity Isn't Basic at All

The DoD says it's reducing cybersecurity burden on the Defense Industrial Base. At the same time, the first recommendation in the new "Brilliant at the Basics" campaign calls for phishing-resistant multi-factor authentication, a capability that goes well beyond today's NIST SP 800-171 requirements. In this episode we break down replay resistance vs. phishing resistance, explain why they are different security properties, and explore where phishing-resistant authentication fits into the NIST standards lifecycle. We also ask a simple question: If this is now considered "basic," why isn't it in the NIST control catalog yet? 800-63: https://csrc.nist.gov/pubs/sp/800/63/b/4/final Brilliant at the Basics: https://dowcio.war.gov/BrilliantBasics/

6. elo 202624 min
jakson CMMC Phase 2 Is Suspended... So Why Is the DoD Still Assessing Contractors? kansikuva

CMMC Phase 2 Is Suspended... So Why Is the DoD Still Assessing Contractors?

Everyone saw the headline that CMMC Phase 2 was suspended. Almost nobody read the part that says government-led assessments are still happening. In this episode we look at what the DoD actually said, how DIBCAC decides who gets assessed, why the LogZone False Claims Act case matters, and why today's approach looks surprisingly similar to the original CMMC 1.0 phased rollout. If you think the suspension means nobody is verifying cybersecurity anymore, you may want to read the Phase 2 suspension memo one more time. Phase 2 Suspension: https://youtu.be/TfdwAc5tdMA?si=H8Dtz6Z1UbG_aYpX LogZone FCA: https://youtu.be/T5wJYnQzWws?si=ME3p2C8Sx_jhXTGJ DFARS 7020: https://youtu.be/D4JLkfvB-Ws?si=rG-4enAdaj0InsfY DoD Critical Tech: https://www.cto.mil/osc/critical-technologies/ CIO Interview: https://defensescoop.com/2026/07/17/pentagon-task-force-to-review-cmmc-hits-the-ground-running/ Suspension Memo (PDF): https://dodcio.defense.gov/Portals/0/Documents/Library/CMMC-ReformMemo.pdf

23. heinä 202617 min
jakson CMMC Phase 2 Is Suspended... But Contractor Liability Just Went UP kansikuva

CMMC Phase 2 Is Suspended... But Contractor Liability Just Went UP

Miss the CUI Hotline Telethon? Watch it on-demand: https://summit7.us/event/secure-the-dib-telethon The DoD has suspended the November 2026 transition to Phase 2 of CMMC implementation, but that doesn't mean cybersecurity requirements have been relaxed. In this episode, we explain what actually changed, what didn't, why Level 2 self-assessments now matter more than ever, and how contractors could expose themselves to significant False Claims Act liability if they misunderstand the news. We also discuss the 60-day CMMC program review, the DoD's Request for Information, and what defense contractors should focus on moving forward. Phase 2 Announcement: https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/ Phase 2 Blog: https://summit7.us/blog/cmmc-phase-2-suspended-with-60-day-review-what-happens-next 32 CFR 170.16: https://www.ecfr.gov/current/title-32/section-170.16 32 CFR 170.22: https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170/subpart-D/section-170.22 False Claims Act: https://youtu.be/T5wJYnQzWws?si=pn8iwA7_8Ys_wvdq

16. heinä 202623 min
jakson Last Chance to Influence the FAR CUI Rule kansikuva

Last Chance to Influence the FAR CUI Rule

Register for Secure The DIB: https://summit7.us/event/secure-the-dib-telethon The public comment period for the proposed FAR CUI rule closes on July 23, making this your last opportunity to influence one of the biggest cybersecurity changes coming to federal contracting. Simply supporting or opposing the rule isn't enough. In this episode, we break down the Government's own guidance for writing effective public comments and explain the seven principles that make comments persuasive. You'll learn the common mistakes to avoid, how to build evidence-based arguments, and how to give regulators constructive recommendations they can actually use. Whether you're planning to comment on the FAR CUI rule or want to better understand how federal rulemaking works, this episode will help you make your comment count before the deadline. Register for Summit 7 Live: https://www.summit7.us/s7live FAR CUI Rule: https://www.federalregister.gov/documents/2026/06/23/2026-12559/federal-acquisition-regulation-revolutionary-federal-acquisition-regulation-overhaul-parts-1-2-4-33 GSA Comment Guidance: https://www.regulations.gov/commenting-guidance

9. heinä 202617 min