
Sign up to save your podcasts
Or


Defense contractors aren't the only ones who need to implement NIST cybersecurity requirements for CUI. The big question has always been whether other agencies would require proof of implementation via the CMMC program. The GSA just revised their process for assessing nonfederal systems handling controlled unclassified information and it's way closer to NIST's Risk Management Framework than CMMC.
CIO-IT Security-21-112r1 (PDF): https://www.gsa.gov/system/files/Protecting-Controlled-Unclassified-Information-%28CUI%29-in-Nonfederal-Systems-and-Organizations-Process-%5BCIO-IT-Security-21-112-Rev-1%5D.pdf
Summit 7 Live San Diego: https://www.summit7.us/s7live
By Summit 75
1313 ratings
Defense contractors aren't the only ones who need to implement NIST cybersecurity requirements for CUI. The big question has always been whether other agencies would require proof of implementation via the CMMC program. The GSA just revised their process for assessing nonfederal systems handling controlled unclassified information and it's way closer to NIST's Risk Management Framework than CMMC.
CIO-IT Security-21-112r1 (PDF): https://www.gsa.gov/system/files/Protecting-Controlled-Unclassified-Information-%28CUI%29-in-Nonfederal-Systems-and-Organizations-Process-%5BCIO-IT-Security-21-112-Rev-1%5D.pdf
Summit 7 Live San Diego: https://www.summit7.us/s7live

29,464 Listeners

30,838 Listeners

32,869 Listeners

2,007 Listeners

192 Listeners

74 Listeners

2,663 Listeners

46,285 Listeners

2 Listeners

17,911 Listeners

3 Listeners

2 Listeners

0 Listeners

2 Listeners

0 Listeners