Logo

    Estimating the Cost of NIST SP 800-171

    en-usOctober 12, 2023
    What was the main topic of the podcast episode?
    Summarise the key points discussed in the episode?
    Were there any notable quotes or insights from the speakers?
    Which popular books were mentioned in this episode?
    Were there any points particularly controversial or thought-provoking discussed in the episode?
    Were any current events or trending topics addressed in the episode?

    About this Episode

    The government recently released a new federal acquisition regulation that requires NIST SP 800-53 controls for federal information systems operated by contractors. Buried inside that rule are several cost estimates for implementing and maintaining SP 800-53. Meanwhile, the government has never published cost estimates for NIST SP 800-171 even though it is derived directly from SP 800-53. In this episode we use are knowledge of SP 800-53 to do the impossible and estimate SP 800-171 using the government's own numbers.

    Episode Links:

    LinkedIn Poll: https://www.linkedin.com/posts/jacob-evan-horne_information-hazards-are-one-of-my-favorite-activity-7116107489045004288-BfrM

    FAR Rule: https://www.federalregister.gov/documents/2023/10/03/2023-21327/federal-acquisition-regulation-standardizing-cybersecurity-requirements-for-unclassified-federal

    Fuzzy Math @ CS2 San Diego (2021): https://www.youtube.com/watch?v=843K3hkLquk

    SolarWinds Hack: https://www.gao.gov/blog/solarwinds-cyberattack-demands-significant-federal-and-private-sector-response-infographic

    EO 14028: https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/

    DFARS 7012: https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.

    DFARS 7010: https://www.acquisition.gov/dfars/252.239-7010-cloud-computing-services.

    FIPS 199: https://csrc.nist.gov/pubs/fips/199/final

    SP 800-53: https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final

    SP 800-171: https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final

    SP 800-171B cost estimate (2019): https://csrc.nist.gov/pubs/sp/800/171/b/ipd

    Recent Episodes from Sum IT Up: CMMC News Roundup

    What’s Next for 800-171r3?

    What’s Next for 800-171r3?

    Register for CS2 | Boston here: https://cs2.cloud/boston

    NIST has released their summary of public comments received on the final drafts of SP 800-171 revision 3 and SP 800-171A revision 3. Jason and Jacob dive into when to expect the final revisions and what to expect in the revised requirements.

    Podcast listeners get a discount on CS2 registration, just use the code: SUMITUPBOSTON

    Episode Links:

    NIST CUI Project Page: https://csrc.nist.gov/projects/protecting-controlled-unclassified-information

    171r3 Blog: https://www.summit7.us/blog/nist-800-171-rev3-final-draft

    ORC Control Poll: https://www.linkedin.com/posts/jacob-evan-horne_supply-chain-security-pop-quiz-nist-control-activity-7168287222444576769-7iw_

    What comes after CMMC public comments?

    What comes after CMMC public comments?

    Register for CS2 | Boston here: https://cs2.cloud/boston

    The public comment period on the CMMC proposed rule has closed so what happens next? In this episode we wade through the red tape in store over the next 12 months.

    Podcast listeners use code SUMITUPBOSTON for a discount on registration

    Episode Links: CS2 Boston: https://cs2.cloud/boston

    “Midnight Rulemaking”: https://www.gao.gov/products/gao-23-105510

    DoD's Rule Overview: https://youtu.be/DqRf0DiVBVI?si=2kTZcX45zD5ZPsnp

    We Are the World: https://youtu.be/cYfe8RYcz-w

    CS2 Boston Preview

    CS2 Boston Preview

    Register for CS2 | Boston here: https://cs2.cloud/boston

    It's almost Springtime and that means it's almost time for another CS2 conference. CS2 Boston will be the 13th event in the series and, as always, there's an all-star lineup covering every nook and cranny of DFARS, NIST, and CMMC.

    Podcast listeners get 20% off registration with the code SUMITUPBOSTON

    Episode Links:

    CS2 Boston: https://cs2.cloud/boston

    DoD video overview: https://youtu.be/DqRf0DiVBVI?si=rDYWHsAHr6jwPPVm

    2024 Rulemaking Calendar

    2024 Rulemaking Calendar

    Register for CS2 | Boston here: https://cs2.cloud/boston

    If you thought the publication of one major DoD cyber rule at the end of 2023 caused a lot of issues how about FIVE potential rules and two NIST revisions in 2024? This week we outline the seven rules to watch for in 2024.

    Listener discount code: SUMITUPBOSTON

    Episode Links:

    [Webinar] The Top 10 Questions From the CMMC Rule: https://www.summit7.us/webinars/the-top-10-questions-from-the-cmmc-rule

    CS2 Boston: https://cs2.cloud/boston

    Midnight Rulemaking: https://www.gao.gov/products/gao-23-105510

    The Truth About the False Claims Act

    The Truth About the False Claims Act

    Register for CS2 | Boston: https://cs2.cloud/boston

    This week we're joined by Alex Canizares to catch up on enforcement trends under the False Claims Act. As a former DOJ trial attorney, Alex walks us through the finer details of FCA cases and what it means for CMMC, defense contractors, and the road ahead.

    Episode Links:

    Alex Canizares: https://www.linkedin.com/in/alexandercanizares/

    Perkins Coie Blog: https://www.perkinscoie.com/en/news-insights/dod-issues-proposed-cmmc-rule-requiring-cybersecurity-assessments-of-contractors.html

    Perkins Coie Blog: https://www.perkinscoie.com/en/news-insights/proposed-far-rules-introduce-new-compliance-obligations-and-false-claims-act-risks-for-government-contractors.html

    Cyber Civil Fraud Initiative: https://www.justice.gov/opa/pr/deputy-attorney-general-lisa-o-monaco-announces-new-civil-cyber-fraud-initiative

    CS2 discount code for our listeners: SUMITUPBOSTON

    CMMC and the Supreme Court

    CMMC and the Supreme Court

    The Supreme Court is set to upend decades of administrative law doctrine and it will have huge impacts on the cyber regulation landscape. In this episode we sit down with Jim Dempsey, a lecturer at the UC Berkeley Law School and a senior policy advisor at the Stanford Cyber Policy Center, to understand what SCOTUS is up to and what the heck is has to do with CMMC?

    Episode Links:

    Cyber Law Fundamentals: https://iapp.org/resources/article/cybersecurity-law-fundamentals/

    Lawfare Article: https://www.lawfaremedia.org/article/a-cyber-threat-to-u.s.-drinking-water

    Cyber Law Podcast: https://open.spotify.com/show/3Co2wdTUaZr4Xqnlxs4soG?si=64382c0b7b7a49c9

    Tech Policy Podcast: https://open.spotify.com/episode/1klWdGIAxI7YBTljMvI412?si=ea93f23b3f9143cb

    Dissed Podcast: https://open.spotify.com/episode/70GmGuWyEyKI2qNLcqlSIv?si=c69a3b6337ea4227

    National Cyber Strategy: https://www.whitehouse.gov/briefing-room/statements-releases/2023/03/02/fact-sheet-biden-harris-administration-announces-national-cybersecurity-strategy/

    Chevon Deference: https://ballotpedia.org/Chevron_deference_(doctrine)

    Auer Deference: https://ballotpedia.org/Auer_deference

    CMMC Predictions for 2024

    CMMC Predictions for 2024

    With five rulemaking efforts, multiple NIST revisions, and everything else going on in the DoD cyber regulation space it's hard to keep up with what's happening. In this episode we try and predict what's coming around the corner in 2024.

    Episode Links:

    Register for CS2 Boston: https://cs2.cloud/boston

    DoD IG Report Episode: https://youtu.be/_3GLX6ele_E?si=KKhtgbjsxiLXWVJd

    Stephanie Siegmann: https://youtu.be/d1yweDy2wV4?si=naLAhZPV794TAC66

    DoD IG Audit: https://www.linkedin.com/posts/jacob-evan-horne_dod-ig-dod-process-for-accrediting-c3paos-activity-7114319133088866304-uhU5

    RAS Syndrome: https://en.wikipedia.org/wiki/RAS_syndrome

    New Strategy, Who NDIS?

    New Strategy, Who NDIS?

    The DoD has released yet another strategy document that claims to have the answer for expanding the defense supply chain while also increasing cybersecurity requirements. Maybe this time it will be different? This week we dive into the National Defense Industrial Strategy to see if there is anything to learn about the DoD's position on the impacts of CMMC.

    Episode Links:

    Register for CS2 Boston: https://cs2.cloud/boston

    NDIS: https://www.businessdefense.gov/NDIS.html

    DoD Cyber Strat: https://www.defense.gov/News/Releases/Release/Article/3523199/dod-releases-2023-cyber-strategy-summary/

    “The Last Supper”: https://www.washingtonpost.com/archive/business/1997/07/04/how-a-dinner-led-to-a-feeding-frenzy/13961ba2-5908-4992-8335-c3c087cdebc6/

    View the full webinar, CMMC Published: A Comprehensive Overview of the Proposed CMMC Rule On-Demand here: https://www.summit7.us/webinars/proposed-cmmc-rule

    Cloudy With a Chance of Memos

    Cloudy With a Chance of Memos

    FedRAMP moderate “equivalency” has been a thing since 2016, but DoD never really defined the term until January 2024. “The memo” has defense suppliers and the people behind their cloud apps in panic mode. In this episode we dive into what the memo says, potential reasons why, and whether equivalency will still be a thing in the future at all.

    Episode Links:

    DFARS 7012: https://www.acq.osd.mil/dpap/dars/dfars/html/current/252204.htm#252.204-7012

    The memo (PDF): https://dodcio.defense.gov/Portals/0/Documents/Library/FEDRAMP-EquivalencyCloudServiceProviders.pdf

    Equivalency circa 2018: https://www.nist.gov/news-events/events/2018/10/controlled-unclassified-information-security-requirements-workshop

    FedRAMP: https://www.fedramp.gov/program-basics/

    NIST SP 800-171r3: https://csrc.nist.gov/pubs/sp/800/171/r3/fpd

    7 Tips for Crafting Good Public Comments

    7 Tips for Crafting Good Public Comments

    Register for the upcoming webinar; CMMC Published: A Comprehensive Overview of the Proposed CMMC Rule: https://www.summit7.us/webinars/proposed-cmmc-rule

    Thinking about submitting comments on the CMMC proposed rule? Not sure where to start? In this episode we go over the “commenter's checklist” from regulations.gov to help you evaluate the quality of your public comments on federal rules, NIST publications, and more.

    Episode Links:

    Summit 7 Webinar: https://www.summit7.us/webinars/proposed-cmmc-rule

    Commenter's Checklist (PDF): https://s3.amazonaws.com/prod-regulations-faq/pdf/Tips-For-Submitting-Effective-Comments.pdf

    CMMC Proposed Rule: https://www.federalregister.gov/documents/2023/12/26/2023-27280/cybersecurity-maturity-model-certification-cmmc-program

    CMMC Guidance Documents: https://www.federalregister.gov/documents/2023/12/26/2023-27281/cybersecurity-maturity-model-certification-cmmc-program-guidance

    NIST SP 800-171 revision 3 draft: https://csrc.nist.gov/projects/protecting-controlled-unclassified-information

    Logo

    © 2024 Podcastworld. All rights reserved

    Stay up to date

    For any inquiries, please email us at hello@podcastworld.io