Sum IT Up: CMMC News Roundup

Estimating the Cost of NIST SP 800-171


Listen Later

The government recently released a new federal acquisition regulation that requires NIST SP 800-53 controls for federal information systems operated by contractors. Buried inside that rule are several cost estimates for implementing and maintaining SP 800-53. Meanwhile, the government has never published cost estimates for NIST SP 800-171 even though it is derived directly from SP 800-53. In this episode we use are knowledge of SP 800-53 to do the impossible and estimate SP 800-171 using the government's own numbers.

Episode Links:

LinkedIn Poll: https://www.linkedin.com/posts/jacob-evan-horne_information-hazards-are-one-of-my-favorite-activity-7116107489045004288-BfrM

FAR Rule: https://www.federalregister.gov/documents/2023/10/03/2023-21327/federal-acquisition-regulation-standardizing-cybersecurity-requirements-for-unclassified-federal

Fuzzy Math @ CS2 San Diego (2021): https://www.youtube.com/watch?v=843K3hkLquk

SolarWinds Hack: https://www.gao.gov/blog/solarwinds-cyberattack-demands-significant-federal-and-private-sector-response-infographic

EO 14028: https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/

DFARS 7012: https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.

DFARS 7010: https://www.acquisition.gov/dfars/252.239-7010-cloud-computing-services.

FIPS 199: https://csrc.nist.gov/pubs/fips/199/final

SP 800-53: https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final

SP 800-171: https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final

SP 800-171B cost estimate (2019): https://csrc.nist.gov/pubs/sp/800/171/b/ipd

...more
View all episodesView all episodes
Download on the App Store

Sum IT Up: CMMC News RoundupBy Summit 7

  • 5
  • 5
  • 5
  • 5
  • 5

5

13 ratings


More shows like Sum IT Up: CMMC News Roundup

View all
Fantasy Footballers - Fantasy Football Podcast by Fantasy Football

Fantasy Footballers - Fantasy Football Podcast

29,761 Listeners

Jocko Podcast by Jocko DEFCOR Network

Jocko Podcast

30,809 Listeners

REAL AF with Andy Frisella by Andy Frisella

REAL AF with Andy Frisella

397 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

189 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

My First Million by Hubspot Media

My First Million

2,653 Listeners

The Shawn Ryan Show by Shawn Ryan

The Shawn Ryan Show

45,636 Listeners

Cyberspin by Redspin

Cyberspin

2 Listeners

New Heights with Jason & Travis Kelce by Wondery

New Heights with Jason & Travis Kelce

18,020 Listeners

GRC Academy by Jacob Hill

GRC Academy

3 Listeners

Climbing Mount CMMC by Bobby Guerra

Climbing Mount CMMC

2 Listeners

CMMC Compliance Guide by CMMC Compliance Guide

CMMC Compliance Guide

0 Listeners

That CMMC Show by Summit 7

That CMMC Show

2 Listeners

CUI Hotline: Live CMMC Q&A by Summit 7

CUI Hotline: Live CMMC Q&A

0 Listeners