Sum IT Up: CMMC News Roundup

We Mapped 130 Iranian Cyber Attacks to CMMC… Here's What We Found


Listen Later

Iranian cyber actors are targeting the Defense Industrial Base.

So does CMMC actually help?

In this episode, we mapped 130 real-world techniques used by five Iranian threat groups to the controls behind NIST SP 800-171 using the MITRE ATT&CK framework.

Here is what the data shows:

• 100% of techniques are detectable

• 68% are mitigated with preventative controls

• Just a handful of core controls drive most of the defensive impact

We also examine what that means for Cybersecurity Maturity Model Certification and why 800-171 remains a strong floor for protecting CUI.

But there is a gap. Only about half of the relevant NIST SP 800-53 that mitigate known Iranian techniques are represented in the 800-171 baseline.

If you are a defense contractor, this episode will show you what compliance actually buys you and where you may need to go further.

Register for Summit 7 Live: https://www.summit7.us/s7live

MITRE ATT&CK: https://attack.mitre.org/

Mappings Explorer: https://ctid.mitre.org/projects/mappings-explorer

CISA Alert: https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/iran

NIST SP 800-53: https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final

NIST SP 800-171: https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final

...more
View all episodesView all episodes
Download on the App Store

Sum IT Up: CMMC News RoundupBy Summit 7

  • 5
  • 5
  • 5
  • 5
  • 5

5

13 ratings


More shows like Sum IT Up: CMMC News Roundup

View all
Fantasy Footballers - Fantasy Football Podcast by Fantasy Football

Fantasy Footballers - Fantasy Football Podcast

29,453 Listeners

Jocko Podcast by Jocko DEFCOR Network

Jocko Podcast

30,840 Listeners

REAL AF with Andy Frisella by Andy Frisella

REAL AF with Andy Frisella

32,884 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,009 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

194 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

73 Listeners

My First Million by Hubspot Media

My First Million

2,662 Listeners

The Shawn Ryan Show by Shawn Ryan

The Shawn Ryan Show

46,469 Listeners

Cyberspin by Redspin

Cyberspin

2 Listeners

New Heights with Jason & Travis Kelce by Wondery

New Heights with Jason & Travis Kelce

17,718 Listeners

GRC Academy by Jacob Hill

GRC Academy

3 Listeners

Climbing Mount CMMC by Bobby Guerra

Climbing Mount CMMC

2 Listeners

CMMC Compliance Guide by CMMC Compliance Guide

CMMC Compliance Guide

0 Listeners

That CMMC Show by Summit 7

That CMMC Show

2 Listeners

CUI Hotline: Live CMMC Q&A by Summit 7

CUI Hotline: Live CMMC Q&A

0 Listeners