Services
Services
- Details
- Written by: Robin Basham
- Parent Category: Services
- Category: Training & Professional Development
People are seeing the words DFARS and CMMC thrown into webinar topics. Our board wants to assure that our membership gets qualified and accurate training. Since Robin is recently engaged on this topic…
Topic: NIST 171 Compliance: The NIST Special Publication 171 series, Defense Federal Acquisition Regulation Supplement (DFARS) 7012, and Cybersecurity Maturity Model Certification – Regulating Protected Controlled Unclassified Information
Suppose you are a nonfederal service provider whose offering might involve handling Controlled Unclassified Information (CUI). Up till now, it might not have been an issue. Still, suddenly either your Government Contract Management Officer or an upstream distributor for one of your products has informed you that your contracts and work orders won’t move forward till your offering is listed in the DoD Supplier Performance Review System as having passed NIST 171. Now what? This paper explains what you need to know about the NIST SP 800-171 Assessment Methodology and its use in demonstrating adequate security as detailed in the recently updated DFARS clause 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting
- Hits: 369
Read more: ISC2 East Bay NIST 171 CMMC Training Jan 13, 2022
- Details
- Written by: Robin Basham
- Parent Category: Services
- Category: Training & Professional Development
Denial-of-Service Attacks
- Prevents systems from processing or responding to legitimate traffic
- Transmits data packets
- Exploits a known fault in an OS, service or application
- Results in system crash or CPU at 100%
- Distributed reflective denial of service DRDoS
- Reflected approach, rather than direct to victim, manipulates traffic so that attack is reflected back to victim from other sources
- Example: DNS Poisoning and SMURF
- Hits: 934
- Details
- Written by: SANS / ISC2
- Parent Category: Services
- Category: Training & Professional Development
Here's the vocabulary you need to navigate any security publication. Sitting on the train? Do a low stress brain refresh.
- Hits: 4588
- Details
- Written by: Robin Basham
- Parent Category: Services
- Category: Training & Professional Development
Me Tarzan, You Jane is my way of reminding everyone that we can't get far without some common language. This month, GDPR and NIST 171 are top of mind around our office. Here's what we found helpful.
- Hits: 607
- Laws - most frequently asked in CISSP exam
- PAT meet NAT - know this stuff for your CISSP Exam (Firewall)
- Security Programs Overview
- Cloud and Virtualization Audit
- Cryptographic Lifecycle
- ISC2 East Bay August 13, 2020 Life Sciences & Health Care, Medical Device Manufacturing and Cybersecurity, A Strategy
- Data Centric Security for GDPR NIST SOC 2 PCI Use Cases
- Virtual Vocab
