top of page



Micro Blog - 3 Questions about Potential CMMC Changes
Is the new CMMC rule going to be a draft rule or an interim final rule? While an interim final rule was originally scheduled for release...

Vincent Scott
Jan 18, 20232 min read


'The Fifth Risk' of Vulnerability Management
As seen on GRC Viewpoint: https://lnkd.in/dHQjaGQz. Maintaining an environment which centralizes not only the protection, but the...

Vincent Scott
Nov 26, 20224 min read


Microsoft Exchange Server – Two Zero Day Vulnerabilities Found
On September 29th, Microsoft announced Zero Day vulnerabilities which affect the 2013, 2016 and 2019 versions of Microsoft Exchange. Note...

Jack Poltorak
Oct 11, 20221 min read


Handling CUI
This question of U.S. ONLY and CUI comes up a lot. To be clear, although I have deep experience on the sharing of intelligence...

Vincent Scott
Jul 1, 20223 min read


DIB Contractors should start considering an Evidence Locker for CMMC
Organizations seeking certification, or OSC, in the Defense Industrial Base (DIB) should start considering the creation and maintenance...

Vincent Scott
Jun 21, 20224 min read


CMMC Rollout: Where to Next?
Several people have asked me about this one. I posted this in the NDIA forum a week or so ago to generate discussion there on the current...

Vincent Scott
Jun 1, 20224 min read


Leadership in the Remote Work Environment
Today, a set of questions came across my desk from a reporter for a high-tech magazine. It piqued my interest, so I provided some input...

Vincent Scott
Mar 5, 20227 min read


When is Encryption Enough?
Based on the LinkedIn exchanges of views on encrypted CUI and covered systems linked below, I have, as promised crafted an input to the...

Vincent Scott
Feb 17, 20223 min read


The #1 Problem in Cybersecurity: The Truth You Don’t Want to Know
The Truth You Don’t Want to Know My new favorite saying, and it seems to be rampant in the halls of success, but perhaps nowhere more so...

Vincent Scott
Jan 13, 20223 min read


Scoping Guide
Although the new Cybersecurity Maturity Model Certification (CMMC) Scoping Guides bring much needed clarification, specific aspects of...

Vincent Scott
Jan 5, 20228 min read


The FedRAMP System needs updating; it was never intended for commercial use
As we move forward with accountability around cyber for the Defense Industrial Base (DIB), the specific language in the rules, controls,...

Vincent Scott
Dec 11, 20214 min read


How Do We Right the CMMC Ship?
Previously I wrote CMMC Trip to Tartarus story under the banner “CMMC is impossible and here is why!” I did not receive many comments...

Vincent Scott
May 31, 20218 min read


CMMC: A Trip to Tartarus
So I normally don’t go in for the sensationalized headline. I abhor them in fact, but in this case, I think it is needed. Put the breaks...

Vincent Scott
Apr 22, 20216 min read


CMMC and the Challenge of Documentation
History A long-time requirement for any auditable process or standard has been documentation. I sometimes think that early cave paintings...

Vincent Scott
Apr 19, 20217 min read


Observations from a CMMC Protest paper: A plain English translation
I have put this together as a review of the paper posted by Bob Metzger’s law firm, New DOD Cyber Rules Create Fertile Bid Protest...

Vincent Scott
Jan 26, 20213 min read


Cyber Operations, Cyber Standards, and Solar Winds
In the course of the much appreciated exchange of ideas in a LinkedIn thread, the concept of Cyber Standards like CMMC (the new DoD...

Vincent Scott
Jan 17, 20213 min read


CUI, DFARS, and the Catch-22
Federal Government: "Put CUI controls in place so we can give you a contract." Federal Contractors: "No. Give us the contract and tell us...

Vincent Scott
Dec 12, 20205 min read


Cybersecurity in an Uncertain World
For a commercial enterprise, how much cybersecurity investment needs to be determined from a risk assessment based on a number of...

Vincent Scott
Nov 22, 20203 min read


Is Your Dashboard Zombie Green?
Some years ago a good friend of mine sarcastically quipped, "Yeah that scorecard is green, Zombie Green!" It became a running joke on our...

Vincent Scott
Aug 5, 20203 min read


FAR, DFAR, and NIST 800-171; The Complexities of Compliance
The Short Answer For anyone who wants to skip to the end, here it is. In order to be DoD cybersecurity compliant today, you should have...

Vincent Scott
Apr 29, 20206 min read
bottom of page
