How to respond to a customer NIST CSF compliance questionnaire
More and more of Totem’s clients have received cybersecurity compliance questionnaires from their customers, as part of due diligence activities in a supply chain risk
More and more of Totem’s clients have received cybersecurity compliance questionnaires from their customers, as part of due diligence activities in a supply chain risk
Those working in the US DoD Industrial Base (DIB) who also handle Controlled Unclassified Information (CUI) are required, via DFARS clause 252.204-7012, to implement the

Which DoD contractors require the medium assurance External Certification Authority (ECA) certificate? UPDATE APRIL 2024: As of 11 April 2024, DoD contractors are no longer
Over the past five years, we’ve helped over a thousand small business Defense Industrial Base (DIB) manufacturers meet their obligations to secure Federal Contract Information
For those small business DoD contractors managing non-domain connected workstations and who have been struggling with how to apply multifactor authentication to protect access —

We were delighted to learn recently about a free service offered by the National Security Agency (NSA) to DoD contractors: Protective Domain Name System (PDNS),
A month or so ago all of my multifactor authentication tokens for my administrator access to our Totem servers suddenly stopped working. All of them.

NIST 800-171 and Cybersecurity Maturity Model Certification require Department of Defense (DoD) contractors to “Mark media with necessary CUI markings and distribution limitations”. A basic
Department of Defense Industrial Base (DIB) supply chain members must implement cybersecurity programs to protect the Federal Contract Information (FCI) and Controlled Unclassified Information (CUI)