26 episodes

Addressing cybersecurity’s latest trends, tactics, tools and best practices.

CyberSpin Redspin

    • Technology

Addressing cybersecurity’s latest trends, tactics, tools and best practices.

    25: CMMC - NFOs, Don’t Ignore Your Appendix E

    25: CMMC - NFOs, Don’t Ignore Your Appendix E

    This episode addresses one topic taken from our top ten list of most common failed practices from the CMMC & DIBCAC High assessments. 
    Today we discuss Non-Federal Organization (NFO) controls, where Appendix E comes into play, updates on the NIST 800-171 rev.3 announcement, and dig a little into cybersecurity strategy. 
    Subscribe to CyberSpin: Apple iTunes, Spotify, Stitcher, or your preferred podcast platform. New episodes are released every other week and a transcript of each episode can be found at redspin.com.
    Do you have a question, topic, or idea you’d like us to address on this podcast? Send us an email podcast@redspin.com and we will do our best to cover it in our upcoming episodes!

    • 15 min
    24: CMMC, Your Incident Response Requirements, What Makes a Good Communications Plan, and More!

    24: CMMC, Your Incident Response Requirements, What Makes a Good Communications Plan, and More!

    This episode addresses one topic taken from our top ten list of most common failed practices from the CMMC & DIBCAC High assessments. 
    Today we discuss your CMMC (and DFARS) requirements around Incident response, how to address the problem of limited resources for small and medium-sized businesses, and cover what actually makes a good communications/response plan.
    Subscribe to CyberSpin: Apple iTunes, Spotify, Stitcher, or your preferred podcast platform. New episodes are released every other week and a transcript of each episode can be found at redspin.com.
    Do you have a question, topic, or idea you’d like us to address on this podcast? Send us an email podcast@redspin.com and we will do our best to cover it in our upcoming episodes!

    • 13 min
    23: CMMC and Logging Capabilities, The Why and How

    23: CMMC and Logging Capabilities, The Why and How

    This episode addresses one topic taken from our top ten list of most common failed practices from the CMMC & DIBCAC High assessments. 
    Logging plays a major role in protecting an organization's CUI and FCI because it detects malicious activity. This episode highlights logging best practices, learned by Redspin, the first Authorized CMMC C3PAO. Rob and Thomas talk through your logging options (to perform them manually, or use a new/existing SIEM?), what your program needs to include to meet requirements, and what evidence you need to be prepared to provide during an assessment. 
    Subscribe to CyberSpin: Apple iTunes, Spotify, Stitcher, or your preferred podcast platform. New episodes are released every other week and a transcript of each episode can be found at redspin.com.
    Do you have a question, topic, or idea you’d like us to address on this podcast? Send us an email podcast@redspin.com and we will do our best to cover it in our upcoming episodes!

    • 9 min
    22: CMMC - Understanding Documentation

    22: CMMC - Understanding Documentation

    This episode addresses one topic taken from our top ten list of most common failed practices from the CMMC & DIBCAC High assessments. 
    The documentation episode, where we address some of Redspin's most common questions like: Do I need documentation for every domain? How long should your SSP be? Why do we need documentation, and do we still need it with CMMC 2.0? Listen in as Rob and Thomas walk through the documentation requirement, what to expect during an assessment, important documentation aspects you can't afford to miss, and where to turn when you don't know where to begin (we have templates!).
    Subscribe to CyberSpin: Apple iTunes, Spotify, Stitcher, or your preferred podcast platform. New episodes are released every other week and a transcript of each episode can be found at redspin.com.
    Do you have a question, topic, or idea you’d like us to address on this podcast? Send us an email podcast@redspin.com and we will do our best to cover it in our upcoming episodes!

    • 10 min
    21: CMMC AB Updates: Joint Assessments Are Starting & More!

    21: CMMC AB Updates: Joint Assessments Are Starting & More!

    Redspin's CMMC experts are back to highlight the recent news announcing the start of joint C3PAO and DIBCAC assessments! During the CMMC AB Townhall on July 26th, 2022 it was announced that the first set of certifications will kick off as a joint surveillance program with C3PAOs and DIBCAC. 
    Representing one of the first C3PAOs conducting a joint DIBCAC HIGH assessment, Redspin's Thomas Graham walks us through what the first four  assessments will look like, what the relationship between the OSC and C3PAO will look like during these assessments, and will discuss the goal of DIBCAC High. Our experts will also discuss what happens to DIBCAC Joint assessments once CMMC is live and active. Rob Teague reviews what a joint assessment is, what the current projected course is for CMMC finalization, and last Ross Piper covers the release of the CAP. 
    Do you have a question you’d like us to address on this podcast, or would you like to connect with us at an upcoming conference? Send us an email at podcast@redspin.com.
    Subscribe to CyberSpin: Apple iTunes, Spotify, Stitcher, or your preferred podcast platform. 

    • 8 min
    20: Rumor Control: DIBCAC HIGH

    20: Rumor Control: DIBCAC HIGH

    The Cyber AB and the PMO office recently announced that CMMC 2.0 certifications can be conducted, just not under the “CMMC 2.0” title. The certifications will temporarily be called “DIBCAC High certifications” until the rule-making phase is complete. So, what does that mean for organizations seeking certification?
    Today Redspin’s CMMC Experts, Dr. Thomas Graham, Rob Teague, and Ross Piper will clarify this process so OSCs understand the way forward. 
    Do you have a question, topic, or idea you’d like us to address on this podcast? Send us an email podcast@redspin.com and we will do our best to cover it in our upcoming episodes!
    Subscribe to CyberSpin: Apple iTunes, Spotify, Stitcher, or your preferred podcast platform. New episodes are released every other week and a transcript of each episode can be found at redspin.com.

    • 24 min

Top Podcasts In Technology

Lex Fridman
The Cut & The Verge
Jason Calacanis
The New York Times
The Wall Street Journal
NPR