Powered by RND
Lyt til GRC Academy i appen
Lyt til GRC Academy i appen
(2.537)(250.190)
Gem station
Vækkeur
Sleeptimer

GRC Academy

Podcast GRC Academy
Jacob Hill
Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform for GRC professionals, executives, and anyone else who wants to incre...

Tilgængelige episoder

5 af 43
  • CMMC 2.0 Is FINALLY Here - What Happens Next (with Stacy Bostjanick)
    It’s been a long and wild ride on this #cmmc ship! ⛵In this episode, I speak with Stacy Bostjanick who is the Director of the CMMC program at DoD CIO!Here are some highlights from the episode:Expectations for the initial phase in of CMMCWho determines CMMC levels for contracts?How will CMMC waivers work?Criteria for CMMC level 2 self-assessments and CMMC level 3Early use of NIST 800-171 r3And so much more!First mentioned in 2019, CMMC 1.0 was released in 2020 under the Trump administration.CMMC 1.0 was reviewed during the Biden administration, they released CMMC 2.0 in late 2021, and then… There was a great silence.If you threw a small rock, you’d hit ten people who thought CMMC was going away.All this time though, the DoD was quietly marching on.They released the proposed CMMC program rule in December 2023 and released the final CMMC program rule in October 2024 - which is now EFFECTIVE.After all of that, CMMC will FINALLY begin to phase into DoD solicitations and contracts by this summer.CMMC has been a LONG time coming, and it was an honor to hear the back story and why certain decisions were made!What were your biggest takeaways? Let me know in the comments!Follow Stacy on LinkedIn: https://www.linkedin.com/in/stacy-bostjanick-a3b67173/DoD CIO CMMC website: https://dodcio.defense.gov/CMMC/-----------Thanks to our sponsor Vanta!Want to save time filling out security questionnaires?Experience questionnaire automation here: https://vanta.com/grcacademy-----------Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e43&utm_campaign=courses#cmmc #nist #cybersecurity
    --------  
    1:07:48
  • CMMC Disaster: What MSPs Aren't Telling You
    Your MSP could be a CMMC disaster. 💥💣💥I wish I was joking.In this episode I speak with Joy Beland about the critical role IT Managed Service Providers (MSPs) play in the CMMC space and why so many of them will cause their clients to fail their CMMC assessments.Here are some of the highlights:The NEW critical CMMC requirement for MSPsWhy so many MSPs will cause their clients to fail CMMC assessmentsWhy MSPs SHOULD still get CMMC certifiedQuestions to ask your MSP to gauge their CMMC readinessJoy is the Vice President of Cybersecurity Compliance at Summit 7 and brings over 20 years of experience as a former MSP owner. Summit 7 is a specialized MSP exclusively supporting defense contractors.If you use an MSP, don't just assume that everything is OK and your MSP has it all covered.It's highly likely that they do NOT and you'll FAIL your CMMC assessment because of them.There are some great CMMC-focused MSPs out there, but the majority of MSPs have NO BUSINESS supporting defense contractors.Choose wisely!What stood out most to you? Whatever your thoughts are, feel free to let me know in the comments!Follow Joy on LinkedIn: https://www.linkedin.com/in/joy-belinda-beland/Summit 7 website: https://www.summit7.us/-----------Thanks to our sponsor Vanta!Want to save time filling out security questionnaires?Experience questionnaire automation here: https://vanta.com/grcacademy-----------Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e42&utm_campaign=courses
    --------  
    47:28
  • Healthcare Cybersecurity: Lives are at Stake
    Should you NEVER pay after a ransomware attack?In this episode I speak with Frank Riccardi about cybersecurity in healthcare and the event that triggered much more cyber accountability for the C-suite.Here are some of the highlights:Why healthcare workers are prone to social engineering attacksReasons you SHOULD and should NOT pay after ransomware attacksManaging shadow IT after acquisitions/mergersWhy every member of the C-suite must understand cyberThe importance of a culture of reportingFrank is a former C-level executive with 25 years of experience developing compliance and privacy programs for large healthcare systems comprised of hospitals, physician practice groups, urgent care centers, and other healthcare organizations.I really enjoyed Frank's description of shadow IT! I always thought of an employee who is using an unauthorized application, but I never thought of it from the standpoint of an acquisition/merger.What stood out most to you? Whatever your thoughts are, feel free to let me know in the comments!Follow Frank on LinkedIn: https://www.linkedin.com/in/frank-riccardi-261831b1/Frank's Book (Mobilizing the C-Suite: Waging War Against Cyberattacks): https://www.amazon.com/Mobilizing-C-Suite-Waging-Against-Cyberattacks/dp/1637424248/-----------Thanks to our sponsor Vanta!Want to save time filling out security questionnaires?Experience questionnaire automation here: https://vanta.com/grcacademy-----------Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e41&utm_campaign=courses#cybersecurity #healthcare #hospital #informationtechnology
    --------  
    34:48
  • My MSP Was Hacked - Should I Fire Them?
    Should you fire your MSP?!? 🔥🔥🔥In this episode, I speak with cybersecurity attorney Sarah Anderson about how to evaluate IT Managed Service Providers and how businesses can protect themselves when relying on them.Here are some of the highlights:How you should evaluate MSPsWhat to do after your MSP is hackedManaging the cyber incidentCyber insurance pitfallsShould you fire your hacked MSP?Sarah is the owner of SWA Law LLC and also serves in U.S. Army Reserves as a Lieutenant Colonel.She has been involved in more than 100 cyber incident responses throughout her career and also represents public and private entities in regulatory compliance, cybersecurity practices, and technology contract negotiations.If you are relying on an MSP to manage your IT and security, you won’t want to miss this!As Sarah said, not all MSPs are created equally. Many MSPs have such poor security practices they WILL get you hacked.Encourage your MSP to join MSPCyberX! It's a nonprofit focused on elevating the security of MSPs: https://www.mspcyberx.com/Follow Sarah on LinkedIn: https://www.linkedin.com/in/sarah-anderson-lacyberlawblog123/Legally Cyber website: https://www.legallycyber.com/Sarah's cybersecurity course for lawyers: https://courses.sprouteducation.com/item/cybersecurity-basics-lawyers-653403-----------Thanks to our sponsor Vanta!Want to save time filling out security questionnaires?Experience questionnaire automation here: https://vanta.com/grcacademy-----------Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e40&utm_campaign=courses#msp #informationtechnology #cybersecurity #cmmc
    --------  
    52:47
  • SOC 2 Compliance: ALL The Essentials Simplified
    SOC 2 isn't the only SOC out there! 🧦In this episode Cera Adams breaks down these SOC reports and what to expect in a SOC audit!Here are a few highlights from this episode:Why CPAs are involvedWhat SOC 1 / SOC 2 / SOC 3 reports mean to providers and consumersDifference between SOC 2 Type 1 and Type 2 reportsHow SOC scoping and audits workSOC consulting/audit independence requirementsCera is the Director of IT Assurance Services and leads OCD Tech's SOC 2 and IT Audit Practices. She has more than 20 years of experience in information security!I've spent most of my career working in the NIST cybersecurity space, so this was very interesting to me!I thought that the SOC 3 report was interesting, especially since many other frameworks don't have an equivalent.What were your takeaways? What is your best SOC pun? Let me know in the comments!Follow Cera on LinkedIn: https://www.linkedin.com/in/ceraadams/OCD Tech Website: https://ocd-tech.com/-----------Thanks to our sponsor Vanta!Want to save time filling out security questionnaires?Experience questionnaire automation here: https://vanta.com/grcacademy-----------Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e39&utm_campaign=courses#soc2 #cybersecurity #informationsecurity
    --------  
    22:16

Flere Teknologi podcasts

Om GRC Academy

Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform for GRC professionals, executives, and anyone else who wants to increase their knowledge in the GRC space!
Podcast-websted

Lyt til GRC Academy, Vildt Naturligt og mange andre podcasts fra hele verden med radio.dk-appen

Hent den gratis radio.dk-app

  • Bogmærke stationer og podcasts
  • Stream via Wi-Fi eller Bluetooth
  • Understøtter Carplay & Android Auto
  • Mange andre app-funktioner

GRC Academy: Podcasts i samme familie

Juridiske forhold
Social
v7.3.0 | © 2007-2025 radio.de GmbH
Generated: 1/20/2025 - 7:09:40 PM