ICT Compliance Pod

Cnxtd Event Media

The ICT Compliance Pod is a monthly podcast serving the cybersecurity compliance ecosystem across commercial, federal, and defense markets. The podcast addresses the ICT compliance needs of the entire industry value chain, including ICT product developers, component suppliers, commercial testing laboratories, trusted integrators, standards organizations, and government agencies.

エピソード

  1. 10時間前

    Episode 2 - From Paperwork to Proof: Automating Cyber Compliance

    Cyber compliance has long been defined by documents, manual reviews, and one-off assessments—but that model is buckling under the speed and complexity of modern technology. In “From Paperwork to Proof,” host Josh Brickman explores how automation, machine-readable standards, and AI could transform compliance into a continuous, evidence-driven practice. Pirooz Javan, CTO and co-founder of Easy Dynamics, explains the promise of OSCAL, intelligent automation, and a common language for communicating cybersecurity posture—while emphasizing why organizations cannot permanently outsource ownership of compliance. Members of the Common Criteria Users Forum Management Group preview their upcoming work in Rome and discuss how vendors, laboratories, and governments can improve international product assurance. Eric Crusius, Partner at Hunton Andrews Kurth brings us up to date on CMMC. Former NSA NIAP director Jonathan Rolf reflects on four decades of cybersecurity change and examines the tensions surrounding EUCC, mutual recognition, protection profiles, software supply chains, and post-quantum cryptography. Plus, Josh and producer Bill Rutledge unpack recent developments involving AI-assisted cryptanalysis, the CMVP backlog, AI and PQ, ENISA’s PQ plans, and critical-infrastructure threats. Sponsors Common Criteria Users Forum (www.ccusersforum.org) Biometric Update (biometricupdate.com) OpenSSL Foundation (openssl.foundation) The Cybersecurity Certification and Assessment Tools (CCAT) Project (ccat.fi.muni.cz) Guests Pirooz Javan, Chief Technology Officer, Easy Dynamics Corp The CCUF Management Group Jonathan Rolf, Cybersecurity Consultant, Independent, Retired NSA NIAP Director, United States Eric Crusius, Partner, Hunton Andrews Kurth LLP Links AI-Assisted Cryptanalysis Leads to withdrawal of HAWK from NIST's ongoing additional signature scheme standardisation process. https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/2r2u6SbHun4/m/TdylDSNgCQAJ?utm_medium=email&utm_source=footer CMVP Reaches “Zero” Queue https://crypto-v.org/cmvp-reaches-zero-queue-a-milestone-worth-celebrating/ ENISA opens a call to participate in the public review of “Agreed Cryptographic Mechanisms” until end of July https://certification.enisa.europa.eu/news/participate-public-review-new-draft-agreed-cryptographic-mechanisms-2026-06-02_en Cyber Attacks of Water Systems https://www.nytimes.com/2026/08/01/us/politics/iran-cyberattack-water-systems.html?smid=nytcore-android-share Trust and Turbulence Podcast https://www.joshuabrickmanpmp.com/listen

  2. 8月4日

    Episode 1 - From CRA Deadlines to Q-Day: The New Era of Cybersecurity Compliance

    Cybersecurity compliance is moving from policy discussions to urgent implementation. In the premiere episode of the ICT Compliance Pod, host Joshua Brickman speaks with four leading experts about the regulatory and cryptographic changes reshaping the ICT industry. Roland Atoui, founder of Red Alert Labs, explains how manufacturers can prepare for the EU Cyber Resilience Act and turn compliance into a competitive advantage. ABI Research’s Michela Menting shares key lessons from the International Cryptographic Module Conference, including the challenges of deploying post-quantum cryptography in embedded systems. AWS cryptographer Matthew Campagna explains the “harvest now, decrypt later” threat and the practical steps organizations should take to begin migration. NIST Fellow Lily Chen discusses the post-quantum transition, cryptographic inventories, and why crypto agility must become a long-term organizational capability. Guests focus on a common theme: Deadlines are approaching and technical challenges are significant. Sponsors: Common Criteria Users Forum (www.ccusersforum.org)Biometric Update (biometricupdate.com)OpenSSL Foundation (openssl.foundation)The Cybersecurity Certification and Assessment Tools (CCAT) Project (ccat.fi.muni.cz) Guests: Roland Atoui, Managing Director and Founder, Red Alert LabsMichela Menting, Vice President, ABI ResearchMatt Campagna, Chairman of ETSI Quantum-safe Cryptography Technical Committee, Sr Principal Engineer, Amazon Web Services (AWS)Lily Chen, Mathematician and NIST Fellow, National Institute of Standards and Technology (NIST) Links: Panel Discussion: PQC Readiness by 2030? – Trust but Verify in a Diverse Technology Ecosystem (Q03a) Leader: Blair Canavan, Director Alliances, PKI and PQC Portfolio, Thales Group, Canada Panelists: Jaime Gomez, Global Head of the Santander Quantum Threat Program, Santander Digital Services, Spain; Bill Newhouse, Cybersecurity Engineer, National Cybersecurity Center of Excellence, National Institute of Standards and Technology (NIST), United States; Michele Mosca, Co-founder and CEO, evolutionQ, and Co-founder, Institute for Quantum Computing, Canada; Ted Shorter, Chief Technology Officer, Keyfactor, United States https://youtu.be/8N_6uZtiKX0  Recognizing Excellence: The CMUF Community Awards & ICMC Closing Plenary (P32a) Including Lifetime Achievement Award: Lily Chen, Mathematician and NIST Fellow, National Institute of Standards and Technology (NIST) https://www.youtube.com/watch?v=GMj62M0nyB8  CRA Standards Unlocked – EU Tour 2 (Lisboa) https://www.etsi.org/events/cra-standards-unlocked-eu-tour-2-170926/ Trust and Turbulence Podcast: https://www.joshuabrickmanpmp.com/podcast

番組について

The ICT Compliance Pod is a monthly podcast serving the cybersecurity compliance ecosystem across commercial, federal, and defense markets. The podcast addresses the ICT compliance needs of the entire industry value chain, including ICT product developers, component suppliers, commercial testing laboratories, trusted integrators, standards organizations, and government agencies.