Make NIST SP 800-171 A Framework Again

  Рет қаралды 4,517

Summit 7

Summit 7

Күн бұрын

Пікірлер: 7
@rickrandall3174
@rickrandall3174 2 жыл бұрын
Excellent video! This is probably the best video on YT on the "real truth" of CMMC in 2022. One of the biggest sources of confusion in the DIB community is that NIST publications historically were written for, and applicable to, *federal* agency IT networks and not private sector contractor IT. The concept of maintaining a 200 page "security plan" document is arguably accepted as reality in many federal agencies, but is often perceived of as gibberish and useless bureaucracy inside of a private for-profit company (large or small). DFARS 7012 and then later CMMC 2.0 pushed the idea that private companies had to implement the government's documentation bureaucracy INTERNALLY on company networks. Documentation for its own sake is fairly useless, costs a lot of money to develop and maintain, and does NOT improve actual IT security. That is why CMMC is getting so much pushback from the DIB contractor community.
@ansizfark
@ansizfark 2 жыл бұрын
Thank you for posting this! Jacob always does a fantastic job with NIST history lessons. I will definitely watch this a few times. By chance are the slides publicly available?
@enterprisegrc
@enterprisegrc 2 жыл бұрын
I really enjoy hearing you say out loud much of what I have squirreling around in my head. Thanks for giving voice to the frustration b/c that's how we move forward. I especially liked the idea of adding back classification, implementation priority, and Keywords. I did not throw the meta content out and I want rev 5 to do a release that assigns them back in. (Robin Basham)
@Summit7
@Summit7 2 жыл бұрын
Awesome! Thanks for watching.
@turegoodoverlooked
@turegoodoverlooked 2 жыл бұрын
31:38 Okay I’m pretty new to IT and Cybersecurity in general. I have a clarifying question: did he basically imply in this talk that the whole NIST standard, which I have seen EVERYWHERE is intended more for information privacy than information security? (I’m not saying he’s wrong it is a genuine question)
@turegoodoverlooked
@turegoodoverlooked 2 жыл бұрын
Also I’m sure this talk is out of my depth, but I like to understand the frameworks I’m going to be expected to work with, before I work with them, so I can understand their strengths and weaknesses.
@infusor1243
@infusor1243 2 жыл бұрын
Yes, because privacy and security are intrinsically linked. It's impossible to keep things private without keeping them secure.
CS2 Tampa Recap
1:01
Summit 7
Рет қаралды 1,2 М.
NIST 800-171 assessment, from an auditor's perspective
25:09
DIB Tech Talk
Рет қаралды 11 М.
When you have a very capricious child 😂😘👍
00:16
Like Asiya
Рет қаралды 18 МЛН
Quando eu quero Sushi (sem desperdiçar) 🍣
00:26
Los Wagners
Рет қаралды 15 МЛН
IL'HAN - Qalqam | Official Music Video
03:17
Ilhan Ihsanov
Рет қаралды 700 М.
We Attempted The Impossible 😱
00:54
Topper Guild
Рет қаралды 56 МЛН
Cyber Insurance, NIST SP 800-171, and CMMC 2.0
51:53
Summit 7
Рет қаралды 2,7 М.
NIST SP 800-171 revision 3 with Dr. Ron Ross
2:05:04
Summit 7
Рет қаралды 2,1 М.
What are AI Agents?
12:29
IBM Technology
Рет қаралды 1,1 МЛН
NIST 800-171 Overview
14:51
AuditorSense
Рет қаралды 8 М.
NIST 800-53 Revision 5, Security and Privacy Controls
9:19
Fuzzy Math: The Gap Between SPRS Scores and CMMC Readiness
1:03:05
Achieving CMMC & NIST 800-171 Compliance
58:51
PreVeil
Рет қаралды 1,6 М.
Exploring the NIST Cybersecurity Framework 2.0: What You Need to Know
53:49
Winslow Technology Group
Рет қаралды 23 М.
When you have a very capricious child 😂😘👍
00:16
Like Asiya
Рет қаралды 18 МЛН