The SimpliCompliance Podcast

Craig Willard

The SimpliCompliance podcast provides direct discussion from experts to simplify compliance for IT and business leaders. If you feel compliance is too complicated and need someone to lay it out clearly, this podcast will help. We also discuss technology and security strategies, tips, and trends, all focused on making life easier for busy business leaders. Our moderator, Craig Willard, is a CMMC-AB Registered Practitioner with 15+ years of senior leadership experience in a Fortune 100 company. Join in as we SIMPLIFY the compliance conversation! Everything from HIPAA and NIST 800-1717 to CMMC.

Episodes

  1. 06/02/2021

    CMMC - Interview with Retired Navy Cryptologist Vincent Scott

    Craig Willard, CMMC-AB Registered Practitioner, and Vincent Scott, retired Navy Cryptologist and serial entrepreneur talk a few things within the CMMC Space. Vincent Scott currently serves as the CEO of Defense Cybersecurity Group, a cyber consulting company focused on the new DoD Cyber requirements for the Defense Industrial Base where he brings the cyber offensive mindset of his Navy career to cyber defense for US companies Questions Discussed: What is a CYBER OFFENSE mindset? If I Meet All Of The 800-171 Requirements... Is My Company Safe? Should DoD Contractors Use the MEP Guide For 800-171 Self Assessments? How Powerful Is The SPRS Score From The 800-171 Self Assessment? What Challenges are DIB's Currently Experiencing? How Can DIB's Handle The Expense Perspective of Compliance? What DIB's Should DIB's Not Do While Implementing Their Security Requirements? You can find our Podcast here: Radio Public https://radiopublic.com/the-simplicompliance-podcast-WR122e PocketCasts https://pca.st/ox4pn15m Spotify https://open.spotify.com/show/5fo9zaA4X12cWPxe2GzU6F Apple Podcast https://podcasts.apple.com/us/podcast/the-simplicompliance-podcast/id1562908018 Anchor FM https://anchor.fm/simplicompliancepodcast Google Podcast https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy80ZWVmZWJiYy9wb2RjYXN0L3Jzcw== Vincent Scott Contact Info: Vincent.Scott@cybersecgru.com www.cybersecgru.com https://www.linkedin.com/in/vincent-scott-cybersecurity/ https://www.linkedin.com/pulse/cmmc-challenge-documentation-vincent-scott https://www.linkedin.com/pulse/when-encryption-enough-vincent-scott/ https://www.linkedin.com/pulse/1-problem-cybersecurity-truth-you-dont-want-know-vincent-scott/ If you need help with your CMMC Compliance, reach out to us: www.WeSimplifIT.com 502-783-6630

    34 min
  2. 04/19/2021

    CMMC - Interview with FedRAMP Author and Architect, Dave Fairburn

    In this episode, Craig Willard, CMMC-AB Registered Practitioner, and Dave Fairburn, nationally known as the architect and author of the Federal Risk Authorization and Management Program (FedRAMP) talk about many enlightening topics regarding CMMC.   Questions: • How did you become the Author and Architect of FedRAMP. • With an increasing level of vendors offering CUI cloud storage that meets CMMC requirements, how can a contractor quiet the noise and pick a vendor that will be able to truly meet 800-171/CMMC requirements for storing CUI? • If an OSC is seeking ML-1, even though documentation is not required, what are you, as a provisional Assessor, expecting to see documented in order to certify the OSC as ML-1? • I’ve heard that the CMMC-AB is designating assessor data as CUI.  Along that same vein, If an OSC is seeking ML-3 and they store validating documentation needed for the assessor in DropBox or any other non 7012 compliant solutions, would that also need to be considered CUI and stored within an environment meeting 7012 requirements? • For ML-3, is data such as system vulnerability scans, user names, and associated privileged levels considered CUI? • System vulnerabilities are noted in the archives as CUI, however, I’m hearing others say a contractor's system vulnerabilities on their CUI infrastructure is not CUI.   Dave Fairburn Contact Info:   Dave.Fairburn@CyberPros.us https://www.CyberPros.us https://www.linkedin.com/in/dave-fairburn-cissp-pmp-cmmc-pa-cmmc-rp-93b87717/ If you need help with your CMMC Compliance, reach out to us: www.WeSimplifIT.com 502-783-6630

    51 min

About

The SimpliCompliance podcast provides direct discussion from experts to simplify compliance for IT and business leaders. If you feel compliance is too complicated and need someone to lay it out clearly, this podcast will help. We also discuss technology and security strategies, tips, and trends, all focused on making life easier for busy business leaders. Our moderator, Craig Willard, is a CMMC-AB Registered Practitioner with 15+ years of senior leadership experience in a Fortune 100 company. Join in as we SIMPLIFY the compliance conversation! Everything from HIPAA and NIST 800-1717 to CMMC.