Can I Use a Plan of Action and, Milestones (POA&M) in CMMC?

POA&M featured

CMMC has become a strict, rigorous set of regulations for contractors working with the Defense Department. It is a clear map of maturity and capabilities; its implementation of NIST 800-171 controls; and its call for complete compliance before certification make CMMC audits challenging for many unprepared businesses. Unlike other frameworks, CMMC doesn’t allow documents like a Plan of Action and Milestones (POA&M) to stand in for actual compliance. 

CMMC 2.0 seems to change that. Here, we will discuss a POA&M and what it means within the CMMC framework. 

Read More

What is the NIST Cybersecurity Framework?

cybersecurity framework featured

In cybersecurity and compliance, terms like “framework” and “regulations” are often used interchangeably. As such, non-specialists might struggle to understand how different guidelines and regulatory bodies fit together to support cybersecurity. For example, the National Institute for Standards and Technology (NIST) provides several documents outlining guidelines and compliance requirements. However, in terms of larger frameworks, it provides two major examples: the Risk Management Framework (RMF) and the Cybersecurity Framework (CSF).

This article will cover the latter of these two, how they fit into government-sponsored cybersecurity concerns and what that means for your organization. 

 

Read More

What is Sarbanes-Oxley Act (SOX) Compliance?

SOX compliance featured

The U.S. faced several disheartening and frustrating scandals in the earliest part of the century. Without regulations guiding them to be transparent, corporations were regularly falsifying financial records or defrauding their investors. To curb this issue, Congress passed the Sarbanes-Oxley Act. This act, also known as SOX, codified a set of reporting and auditing standards into law to force corporations to provide truthful and accurate financial information and avoid further fraud issues. 

Here we discuss some of the implications of SOX and how you can approach compliance for your publicly traded company. 

 

Read More