Sum IT Up: CMMC News Roundup

Estimating the Cost of NIST SP 800-171


Listen Later

The government recently released a new federal acquisition regulation that requires NIST SP 800-53 controls for federal information systems operated by contractors. Buried inside that rule are several cost estimates for implementing and maintaining SP 800-53. Meanwhile, the government has never published cost estimates for NIST SP 800-171 even though it is derived directly from SP 800-53. In this episode we use are knowledge of SP 800-53 to do the impossible and estimate SP 800-171 using the government's own numbers.

Episode Links:

LinkedIn Poll: https://www.linkedin.com/posts/jacob-evan-horne_information-hazards-are-one-of-my-favorite-activity-7116107489045004288-BfrM

FAR Rule: https://www.federalregister.gov/documents/2023/10/03/2023-21327/federal-acquisition-regulation-standardizing-cybersecurity-requirements-for-unclassified-federal

Fuzzy Math @ CS2 San Diego (2021): https://www.youtube.com/watch?v=843K3hkLquk

SolarWinds Hack: https://www.gao.gov/blog/solarwinds-cyberattack-demands-significant-federal-and-private-sector-response-infographic

EO 14028: https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/

DFARS 7012: https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.

DFARS 7010: https://www.acquisition.gov/dfars/252.239-7010-cloud-computing-services.

FIPS 199: https://csrc.nist.gov/pubs/fips/199/final

SP 800-53: https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final

SP 800-171: https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final

SP 800-171B cost estimate (2019): https://csrc.nist.gov/pubs/sp/800/171/b/ipd

...more
View all episodesView all episodes
Download on the App Store

Sum IT Up: CMMC News RoundupBy Summit 7

  • 5
  • 5
  • 5
  • 5
  • 5

5

13 ratings


More shows like Sum IT Up: CMMC News Roundup

View all
Fantasy Footballers - Fantasy Football Podcast by Fantasy Football

Fantasy Footballers - Fantasy Football Podcast

29,328 Listeners

Jocko Podcast by Jocko DEFCOR Network

Jocko Podcast

30,775 Listeners

REAL AF with Andy Frisella by Andy Frisella #100to0

REAL AF with Andy Frisella

32,747 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,002 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

188 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

73 Listeners

My First Million by Hubspot Media

My First Million

2,643 Listeners

Shawn Ryan Show by Shawn Ryan

Shawn Ryan Show

43,968 Listeners

Cyberspin by Redspin

Cyberspin

2 Listeners

New Heights with Jason & Travis Kelce by Wondery

New Heights with Jason & Travis Kelce

18,372 Listeners

GRC Academy by Jacob Hill

GRC Academy

4 Listeners

Climbing Mount CMMC by Bobby Guerra

Climbing Mount CMMC

2 Listeners

CMMC Compliance Guide by CMMC Compliance Guide

CMMC Compliance Guide

0 Listeners

That CMMC Show by Summit 7

That CMMC Show

2 Listeners

CUI Hotline: Live CMMC Q&A by Summit 7

CUI Hotline: Live CMMC Q&A

0 Listeners