show episodes
 
Join us as we discuss news and current events, trends, and controversies in the world of cybersecurity. We have strong feelings and they're not limited to FedRAMP, CMMC, FISMA, IRAP, security engineering, or documentation. Anything goes -- some of the things we say are probably even helpful! Interested in having words? Email us at 38northsocial@gmail.com.
  continue reading
 
Artwork

1
Compliance Therapy™, hosted by Igor Volovich

Risk. Security. Compliance. Get It Together.

Unsubscribe
Unsubscribe
Weekly+
 
Welcome to Compliance Therapy™, hosted by industry expert Igor Volovich. This informative podcast bridges the gap between regulatory compliance, risk assessment, and cybersecurity best practices, making complex topics accessible for technology, business, and legal leaders. Join Igor and renowned guests as they offer valuable insights and actionable strategies to strengthen your organization’s security posture and maintain compliance with key regulations such as NIST, FedRAMP, CMMC, and FISMA ...
  continue reading
 
Artwork

1
Cybersecurity Sense

LBMC Information Security

Unsubscribe
Unsubscribe
Monthly
 
CyberSecurity Sense is LBMC Information Security's podcast that provides insight and updates on such information security topics as: IPS Monitoring and Managed IDS Services, Security Information Event Management, Digital Forensic Analysis, Electronic Discovery and Litigation Support, Computer Security Incident Response, Penetration Testing, Risk Assessments, Security Program Planning, Web Application Security Assessments, ACAB LADMF Certification Assessments, CMS Information Security, FedRAM ...
  continue reading
 
Emagine the Future is a cybersecurity and technology podcast aimed to offer ambitious technology and national security professionals with actionable insights and unique stories from proven industry leaders. Each week, we release conversations with experts from the intelligence, defense, civilian, and private sectors where we discuss current events, career and skill development, technology and national security, and the future. Obtain the edge you need to stay current, to accelerate your deve ...
  continue reading
 
A Federal Security & Compliance career is a very rewarding career - we get the honor and privilege of protecting some of the most guarded assets of our great country. However, it doesn’t come without a cost. We often take the brunt of the beating when it comes to the regulations that are impeding innovation. Join federal security professional Max Aulakh as he distills the challenges facing our career field, pulling back the curtain on culture, emerging technical knowledge, ATOs, CMMC and var ...
  continue reading
 
Resilient Cyber brings listeners discussions from a variety of Cybersecurity and Information Technology (IT) Subject Matter Experts (SME) across the Public and Private domains from a variety of industries. As we watch the increased digitalization of our society, striving for a secure and resilient ecosystem is paramount.
  continue reading
 
Artwork
 
Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform for GRC professionals, executives, and anyone else who wants to increase their knowledge in the GRC space!
  continue reading
 
Artwork

1
The Daily Scoop Podcast

The Daily Scoop Podcast

Unsubscribe
Unsubscribe
Weekly+
 
A podcast covering the latest news & trends facing top government leaders on topics such as technology, management & workforce. Hosted by Billy Mitchell on FedScoop and released every Tuesday and Thursday afternoons.
  continue reading
 
Step into the fascinating world of risk and achievement with The Paramify Podcast. Join us as we engage with inspiring individuals who have accomplished extraordinary feats in various fields. From daring entrepreneurs, innovative scientists, extreme sports athletes to pioneering artists, we delve into their incredible journeys and explore the structures and strategies that guided them. We dissect the frameworks, methodologies, and mindsets they’ve employed to conquer challenges, manage risks ...
  continue reading
 
Welcome to “Cyber Compliance and Beyond,” a Kratos podcast that will bring clarity to compliance, helping put you in control of cybersecurity compliance in your organization. Kratos is a leading cybersecurity compliance advisory and assessment organization, providing services to both government and commercial clients across varying sectors including defense, space, satellite, financial services, and health care. Through "Cyber Compliance and Beyond," our cyber team of experts will share thei ...
  continue reading
 
Disruptive SmackTalk is from Hassan River. Hassan River is an excellent source for United States discourse. For entrepreneurs, technologists, and the culturally conscious. The content spans very relevant topics whether it’s election season or not. Also, we have great recommendations for apps and books. We’re based in the United States, but I invite you to join our growing global community wherever you are. I can best describe the Hassan River digital publication as ‘Thoughtful citizens for f ...
  continue reading
 
Loading …
show series
 
As federal agencies patiently await final modernization guidance from the Office of Management and Budget (OMB), the Federal Risk and Authorization Management Program (FedRAMP) finds itself navigating through a transitional period. Congressman Gerry Connolly (D-Va.), a staunch advocate for federal IT modernization and the author of the FedRAMP Auth…
  continue reading
 
Senators John Cornyn (R-Texas) and Gary Peters (D-Michigan) have introduced the Securing America's Federal Equipment (SAFE) in Supply Chains Act. This bipartisan legislation aims to safeguard federal cybersecurity by mandating that electronic purchases be limited to original manufacturers or authorized resellers, addressing the increased risks of c…
  continue reading
 
Today we're honored to have Eric Evans on the show! Eric is the Founder and CTO of HanaByte, he is a cloud security and compliance expert. He has led security initiatives for startups to Fortune 10 companies and is a renowned public speaker on cloud security and compliance automation. Learn more about Hanabyte: https://www.hanabyte.com/ https://www…
  continue reading
 
The IRS has successfully piloted its free Direct File online tax-filing system in 12 select states, despite facing numerous technical challenges. At a President’s Management Agenda event, IRS officials Merici Vinton and Chris Given discussed how over 1,000 fixes were made after the launch. Commissioner Danny Werfel's cautious approach was crucial t…
  continue reading
 
In today's episode of The Daily Scoop Podcast, host Billy Mitchell examines the implications of the Supreme Court's recent decision to overturn Chevron deference and its impact on federal AI regulation. The 6-3 ruling removes the requirement for courts to defer to federal agencies' interpretations of ambiguous statutes, complicating the Biden admin…
  continue reading
 
Today's Daily Scoop Podcast delves into the transformative impact of user-focused technology on government missions, with a special emphasis on the Department of Defense's UX overhaul. The discussion opens with an in-depth analysis of the NATO summit in Washington D.C., a pivotal event involving expanding support for Ukraine and launching new cyber…
  continue reading
 
The GSA has announced an AI-themed hackathon, inviting the public to reimagine federal websites using artificial intelligence and cloud tools. Co-sponsored by OpenAI and Microsoft, the event will provide participants with access to large language models, coding technologies, and AI response consistency features. Scheduled for July 31 in Washington,…
  continue reading
 
- For folks not familiar with you or the Miggo team, can you tell us a bit about your background? - How do you define ADR and why do you think we have seen the need for this new category of security tooling to come about? - Most organizations are struggling with vulnerability overload, with massive vulnerability backlogs and struggles around vulner…
  continue reading
 
The Department of Commerce’s Tech Hubs program, a key initiative supported by the CHIPS and Science Act, aims to bolster federal research and innovation in emerging technologies, especially in areas outside major cities. Senior Biden administration officials discussed the program's impact during a call announcing 12 new initiatives that will receiv…
  continue reading
 
Vulnerabilities are everywhere and on every IT asset within an organization. This makes vulnerability management one of the most important – if not the most important – risk mitigation activities an organization undertakes. But, the complexities inherent in many organizations combined with the sheer number of vulnerabilities leaves many not knowing…
  continue reading
 
The General Services Administration (GSA) has launched a new initiative to prioritize generative AI technologies in the FedRAMP cloud authorization process, aligning with a 2023 executive order. This effort focuses on accelerating the approval of AI capabilities such as chat interfaces, code generation, and image generators to enhance their integra…
  continue reading
 
In this episode of the Daily Scoop Podcast, host Billy Mitchell discusses the Department of Defense's evolving strategy towards artificial intelligence. The Joint Staff, under the guidance of Lieutenant General Todd Isaacson, has initiated an AI task force, which recently completed a crucial 90-day review to identify viable AI applications and nece…
  continue reading
 
Today, we're honored to be joined by Den Jones, Founder and CEO of 909Cyber and a veteran in cybersecurity. With a robust career that includes roles as Chief Security Officer at SonicWall, CSO at Banyan Security and Senior Director of Enterprise Security at Cisco, Den brings a wealth of experience to the table. He's a Stanford alumnus with a focus …
  continue reading
 
On today's Daily Scoop Podcast, we explore the Department of Energy's (DOE) newly issued reference guide for the use of generative AI tools by its employees and contractors. Released on the DOE's internal network on June 14, this 61-page document outlines best practices and mentions that tools like ChatGPT are available by request. While it isn't c…
  continue reading
 
Chris DeRusha, former Federal Chief Information Security Officer and Deputy National Cyber Director, has joined Google Cloud to lead its global public sector compliance initiatives. DeRusha's new role will involve expanding Google Cloud's offerings in artificial intelligence, cloud computing, and security across public sector entities globally. He …
  continue reading
 
In this episode of The Daily Scoop Podcast, Eric Mill, GSA’s Executive Director for Cloud Strategy, shares comprehensive updates on the modernization of the FedRAMP program, including strategic hires and a new partnership approach aligned with the Department of Defense to enhance cloud authorizations. Additionally, the episode delves into a recent …
  continue reading
 
Today on The Daily Scoop Podcast, Capt. Brian Erickson was appointed as the U.S. Coast Guard’s first ever chief data officer in 2021. Not long after that, the service added artificial intelligence to his portfolio, making him also the first chief data and AI officer for the Coast Guard. Now Erickson has been called on by the Department of Homeland …
  continue reading
 
In this episode, Jacob speaks with Mr. Mark Nicholls! Mark is the CEO of Information Professionals Group and has over 30 years of experience! In the episode they discuss the business case for information security, and how cybersecurity professionals can effectively communicate with the C-suite and other business leaders! Here are some highlights fr…
  continue reading
 
Today, we’re honored to have Rob Sherwood on the podcast. Rob is a seasoned cybersecurity professional with extensive experience in policy management, PKI architecture, and identity management. With over two decades in the field, Rob has left a lasting impact through his dedication to standards development, including his significant contributions t…
  continue reading
 
- First off, for those that don't know you or your work, would you mind telling us a bit about your background? - You recently published a paper titled "Secure-by-Design at Google" which got a lot of attention. Can you tell us about the paper and some of the key themes it emphasizes? - In the paper you discuss some of the unique aspects of software…
  continue reading
 
- First off, for folks that don't know you, can you tell us a bit about your current role and background? - On that same note, can you tell the audience a bit about Anduril, the mission of the organization and some of the current initiatives it is working on? - What are some of the biggest challenges of being a new entrant in a space such as the Do…
  continue reading
 
- For those that don't know you or haven't come across you quite yet, can you tell us a bit about your background in tech/cyber and your role with GitHub? - What exactly is the GitHub Advisory Database and what is the mission of the team there? - There's been a big focus on vulnerability databases, especially lately with some of the challenges of t…
  continue reading
 
The Department of Veterans Affairs, like many federal agencies, is facing a tightening budget landscape. Because of that, resources to support modernization and emerging tech adoption can be hard to come by. FedScoop reporter Caroline Nihill spoke recently with Charles Worthington, the dual-hatted chief technology officer and chief AI officer for t…
  continue reading
 
FedRAMP just came out with *three* new bodies governing the program going forward: the TAG, the Board, and the FSCAC. There's a lot of uncertainty right now, not to mention confusion and misinformation. Why are these changes happening? What does it mean for CSPs, 3PAOs, and agencies? Is the JAB gone?!! Matt Strasburg and Jeremiah Thompson shed ligh…
  continue reading
 
Today on The Daily Scoop Podcast… from The Scoop News Group.Pentagon CIO John Sherman is leaving government And, Microsoft rolls back a highly criticized AI security tool.The Daily Scoop Podcast is available every Monday-Friday afternoon.If you want to hear more of the latest from Washington, subscribe to The Daily Scoop Podcast on Apple Podcasts, …
  continue reading
 
In this episode, Jacob speaks with Penetration Tester & Social Engineer Chris Silvers! Chris Silvers is the founder of CG Silvers Consulting! Chris has a vast amount of experience ranging from CMMC assessments to penetration testing. He even won the prestigious DEF CON black badge during the DEF CON 24 Social Engineering Capture the Flag (SECTF)! I…
  continue reading
 
In this episode of Compliance Therapy™ we dive into the world of Zero Trust architecture with industry experts John Kindervag, the creator of Zero Trust, Dave Lewis, and Drew Church. Discover practical insights and strategies for implementing Zero Trust across various sectors. Our panel discusses the critical role of Zero Trust in modern cybersecur…
  continue reading
 
As federal agencies move full-scale to adopt artificial intelligence technologies in coordination with the 2023 Biden administration AI executive order, it might seem that more secretive intelligence agencies like the CIA would be less forthcoming about their work in the space. Sure, there are some things the agency can’t share and certain requirem…
  continue reading
 
The number of compliance frameworks is seemingly endless. The lack of standards is problematic enough. Even more problematic, however, is how the compliance frameworks overlaps with one another. When it comes to International Trade and Export Compliance, the problem is overlap is accentuated by the fact that there is not a definitive ‘framework’ fo…
  continue reading
 
Some recent estimates have postulated that data is now the world’s most valuable asset. Unlike other assets, like oil, for example, data proliferates on a staggering scale. In other words, it doesn’t seem to be finite, subject the law of scarcity. This hammers home the importance of answering the question that each of you are wrestling with: how do…
  continue reading
 
- For those don't know your background or Nucleus Security, can you start by telling us a bit about both? - You have experience and a background in the Federal environment, and Nucleus recently achieved their FedRAMP authorization, can you tell us a bit about that process? - When you look at the Federal/Defense/IC VulnMgt landscape, what are some o…
  continue reading
 
- For those unfamiliar, please tell us a bit about your background, as well as about RAD Security. What do you all focus on and specialize in? - Your team recently was part of the RSAC Innovation Sandbox. Can you tell us a bit about that experience, and being able to highlight the innovative capabilities of RAD to such a key audience? - You recentl…
  continue reading
 
One of the greatest challenges to security compliance are exception cases. What are exception cases? They are the cases in which a particular compliance objective cannot be achieved, as required. The reasons are myriad: cost, environmental constraints, vendor dependency, and technical limitations. Building an exception case is key to achieving comp…
  continue reading
 
In this episode of Compliance Therapy™, Igor Volovich talks with Heidi Saas, a Data Privacy and Technology attorney, about managing data protection, new privacy rules, and the role of technology in compliance. They also cover the SEC's charges against SolarWinds and its CSO, discussing the impact on the cybersecurity industry and the importance of …
  continue reading
 
Today we had the honor to talk with Matthew Graham, the Director of US Federal Practice at Prescient Security. Matthew is a seasoned cybersecurity expert whose extensive career has spanned technical and strategic leadership roles. With a rich background that includes high-level certifications such as CISSP, CASP+, and CCNA, Matthew brings a wealth …
  continue reading
 
The Army has awarded Palantir a $480 million deal to support its Maven Smart System prototype, the Pentagon announced Wednesday. The U.S. military has recently been using this type of artificial intelligence technology in the Central Command area of responsibility in the Middle East. The Maven Smart System uses AI generated algorithms and memory le…
  continue reading
 
Tune into this episode of Compliance Therapy™ as Mark Whitteker from Cisco discusses his journey from engineering to management, overseeing government security solutions. Discover how Cisco addresses cybersecurity compliance challenges for DoD and Intel organizations using innovative technologies to maintain robust security protocols. Learn about M…
  continue reading
 
Tune into Compliance Therapy™ as we wrap up our discussion with Jacob Horne, Chief Cybersecurity Evangelist at Summit 7. Discover how Jacob's extensive experience in DoD contracting and defense acquisition shapes his strategy for addressing cybersecurity challenges within the defense industrial base. This episode delves into crucial compliance stan…
  continue reading
 
Loading …

Quick Reference Guide