What the heck is device authentication in CMMC?
All federal government contractors handle Federal Contract Information (FCI) in some form or another. We cover the definition of FCI in a previous post, but
All federal government contractors handle Federal Contract Information (FCI) in some form or another. We cover the definition of FCI in a previous post, but
Government contractors that handle –store, process, or transmit– Controlled Unclassified Information (CUI) must implement the National Institutes of Standards and Technology (NIST) 800-171 standard to
As we’ve stated previously, all federal government contractors, even subcontractors, suppliers, and vendors, handle Federal Contract Information (FCI) and must implement the FAR 52.204-21 clause
Federal government contractors that handle Controlled Unclassified Information (CUI) must implement the National Institutes of Standards and Technology (NIST) cybersecurity standard 800-171. In May 2024,
Between the DoD’s publication of the FedRAMP equivalency memo, the subsequent discussion amongst the CMMC community, and more small businesses providing cloud-based services to the
In this post, we will take a look at a Microsoft 365 feature known as Conditional Access. This curious bit of security access control and
UPDATE 20 December 2024: This post is about the proposed CMMC rule, which has now been finalized. Therefore, this post has been superseded by our
Those working in the US DoD Industrial Base (DIB) who also handle Controlled Unclassified Information (CUI) are required, via DFARS clause 252.204-7012, to implement the
The ever-increasing number of breaches and hacks of small and medium-sized businesses (SMBs) make cybersecurity a top concern in today’s IT world. As organizations evolve