AuditorSense
AuditorSense
  • 38
  • 71 995
System Boundaries partt 2 of 3 - AT Boundary
Matt continues his discussion on system boundaries
NIST 800-53
NIST 800-171
Cybersecurity
Security Boundary
Security Assessment
Переглядів: 714

Відео

System Boundaries: Part 1 of 3. Internal vs External
Переглядів 2,5 тис.3 роки тому
Matt begins a three part series on System Boundaries, what they are, and how they are used to assess security compliance.
NIST 800 171 & NIST 800-53: Incident Response
Переглядів 4,3 тис.3 роки тому
In this video Brendan discusses what Incident Response is, Incident Response requirements from NIST 800-171, and what can be done to satisfy the three controls from the Incident Response control family. To learn more about Incident Response and the Incident Response Life Cycle that was discussed in this video, please see NIST 800-61 "Computer Security Incident Handling Guide" - nvlpubs.nist.gov...
NIST 800-53: AU 5 - Response to Audit Processing Failures
Переглядів 5503 роки тому
What does "Response to Audit Processing Failures" mean? What should an auditor be looking for when assessing this control? What evidence should someone being audited provide? Jake sheds light on all of this and more!
NIST 800 171 and 800 53: Multi-Factor Authentication and where does SMS fit in
Переглядів 7173 роки тому
In this video Brendan discusses what Multi-Factor Authentication (MFA) is, acceptable types of Multi-Factor Authentication, and the NIST 800-171 and NIST 800-53 controls that require Multi-Factor Authentication. NIST 800-63B "Digital Identity Guidelines" - nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63b.pdf
What is a CMMC Readiness Assessment
Переглядів 4533 роки тому
What is the purpose of a CMMC readiness assessment? When should I perform a CMMC readiness assessment? What can I expect from a CMMC readiness assessment? In today's video, Brendan will answer the most asked questions about CMMC readiness assessments. CMMC-AB Marketplace: cmmcab.org/marketplace/
What You Should do to Prepare for CMMC
Переглядів 2943 роки тому
With the DoD beginning their phased rollout of CMMC implementation starting this year through 2025, defense contractors need to start preparing for CMMC sooner rather than later. In this video, Brendan will discuss what you should do to prepare for CMMC. See the following link to learn more about the seven pilots announced for fiscal year 2021: www.defense.gov/Newsroom/Releases/Release/Article/...
NIST 800-53: What is a Mobile Device?
Переглядів 2063 роки тому
This is a short video about what NIST considers a mobile device. It's required technology, what the controls are really focusing on, and some available resources for you to check out! NIST 800-124 Rev2 - nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-124r2-draft.pdf
AuditTrails - Achieving CMMC with the Cloud
Переглядів 2323 роки тому
Brendan discusses the cloud and CMMC and how the cloud can be used by organizations to achieve CMMC certification. CMMC NIST FAR DFARS CyberSecurity Auditing Assessments
AuditTrails : FIPS Validated vs FIPS Compliant
Переглядів 9094 роки тому
On this episode of AuditTrails, Jake takes you through the difference between FIPS-validated vs FIPS-compliant. The video includes what the main differences are, what we look for when we audit, and plenty of resources for you to leverage! Cryptographic Algorithm Validation Program - csrc.nist.gov/projects/cryptographic-algorithm-validation-program Cryptographic Standards and Guidelines - csrc.n...
DFARS NIST 800-171 SPRS Score Entry Walkthrough (with 12/14/2020 Updates!)
Переглядів 4,1 тис.4 роки тому
In this video Brendan provides a walk through of the Supplier Performance Risk System (SPRS) for entering your DFARS NIST 800-171 self-assessment score and introduces the SPRS calculator tool from the newly created cmmc-central.org. SPRS: www.sprs.csd.disa.mil/ cmmc-central.org: www.cmmc-central.org/ PIEE/SPRS Access & Tips: www.sprs.csd.disa.mil/pdf/PIEE-Access.pdf Please let us know in the co...
DFARS Interim Rule Explained
Переглядів 4564 роки тому
Brendan takes us on a tour of the DFARS Interim Rule and what it means to most people. He gives background, details, and most importantly our opinion on what organizations should be doing. DFARS Interim Rule: www.federalregister.gov/documents/2020/09/29/2020-21123/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of NIST SP 800-171 DoD Assessment Methodology:...
System Security Plan (SSP) - A Breakdown
Переглядів 12 тис.4 роки тому
On this episode of AuditTrails, Jake takes you through a sample SSP template and what it entails to satisfy NIST 800-171 and CMMC Requirements.
NIST 800-53 Revision 5 - A breakdown of changes!
Переглядів 3 тис.4 роки тому
In this video we will discuss the major changes from NIST 800-53 Revision 4 to Revision 5.
CMMC Video #3 RPO vs C3PAO
Переглядів 3864 роки тому
Brendan Discusses the difference between an RPO and C3PAO and what it means to organizations
AuditTrails: NIST 800-53 - AC-10, Concurrent Session Control
Переглядів 7834 роки тому
AuditTrails: NIST 800-53 - AC-10, Concurrent Session Control
AuditTrails: NIST 800-53 - AC-9, Previous Logon Notification
Переглядів 2204 роки тому
AuditTrails: NIST 800-53 - AC-9, Previous Logon Notification
AuditTrails: NIST 800-53 - AC-8, System Use Notification
Переглядів 5664 роки тому
AuditTrails: NIST 800-53 - AC-8, System Use Notification
NIST 800-171 Overview
Переглядів 8 тис.4 роки тому
NIST 800-171 Overview
CMMC vs. DFARS vs. FAR vs. NIST SP 800-171
Переглядів 2,8 тис.4 роки тому
CMMC vs. DFARS vs. FAR vs. NIST SP 800-171
AuditTrails: NIST 800-53 - AC-7, Unsuccessful Logon Attempts Guidance
Переглядів 4524 роки тому
AuditTrails: NIST 800-53 - AC-7, Unsuccessful Logon Attempts Guidance
AuditTrails: NIST 800-53 - AC-6, Least Privilege Guidance
Переглядів 4914 роки тому
AuditTrails: NIST 800-53 - AC-6, Least Privilege Guidance
Introduction to CMMC
Переглядів 9024 роки тому
Introduction to CMMC
AuditTrails: NIST 800-53 - AC-5, Separation of Duties Guidance
Переглядів 3484 роки тому
AuditTrails: NIST 800-53 - AC-5, Separation of Duties Guidance
AuditTrails: NIST 800-53 - AC-4, Information Flow Enforcement Guidance
Переглядів 4104 роки тому
AuditTrails: NIST 800-53 - AC-4, Information Flow Enforcement Guidance
Demystifying NIST 800-53
Переглядів 23 тис.4 роки тому
Demystifying NIST 800-53
AuditTrails: NIST 800-53 - AC-3, Access Enforcement Guidance
Переглядів 4614 роки тому
AuditTrails: NIST 800-53 - AC-3, Access Enforcement Guidance
AuditTrails: DFARS NIST 800-171 3.1.1 Access Control Discussion and Clarifications
Переглядів 7514 роки тому
AuditTrails: DFARS NIST 800-171 3.1.1 Access Control Discussion and Clarifications
AuditTrails: NIST 800-53 Series: AC Control Family, AC-2 ACCOUNT MANAGEMENT
Переглядів 1,4 тис.4 роки тому
AuditTrails: NIST 800-53 Series: AC Control Family, AC-2 ACCOUNT MANAGEMENT
AuditTrails: NIST 800-53 Series: AC Control Family, AC-1 ACCESS CONTROL POLICY AND PROCEDURES
Переглядів 9744 роки тому
AuditTrails: NIST 800-53 Series: AC Control Family, AC-1 ACCESS CONTROL POLICY AND PROCEDURES

КОМЕНТАРІ

  • @michaelj5325
    @michaelj5325 7 днів тому

    finally, a decent venn diagram! close enough to CMMC 2.0 to still be relevant...

  • @TechWithRandy
    @TechWithRandy 10 днів тому

    Thank you!!

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    I am writing this in 2024 and automation is the fashionable IT alleged panacea. In my opinion, it’s the automated systems you must monitor even more than non- automated ones. All it takes is for someone to mess with the automated ‘trusted’ systems and processes including the automated alerts that are supposed to flag bad things.

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    You can audit a private contractor on 1 billion criteria, civilians are civilians. All it takes is one employee getting resentful with his/ her civilian boss… or him/her getting radicalised because he/ she has fallen madly in love with a gorgeous undercover agent.

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    Do you check what cloud services your contractors use? How does international legislation work with cloud services as the servers in datacenters where data is stored and processed might be in different states or even in different countries? I, obviously, don’t want to pry into your business, I am just trying to learn how law and governance work in the cloud business given their infrastructure, so any direction from anyone to general principles of (international) law would be greatly appreciated. I live in the UK that has Data Protection Law and GDPR but it’s not in Europe and neither it is in the USA. One big cloud provider has a region in South America paired with a region in USA (if I remember correctly what I tried to learn). I find it fascinating (I know I am weird 😄). Thanks.

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    When you do an audit, do you walk the floor ie physically work in various departments to observe any Post-it notes with passwords affixed to displays or staff not locking their screens whilst they ‘quickly’ go to pick up something from the printer?

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    0:01 😃 🎵 You use Microsoft (?)

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    10:27 What if the organisation has a PaaS cloud service and the organisation has decentralised management and data management structures?

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    Thanks for sharing. I have no clue what you’re talking about but I understand it’s about securing an IT system. I am trying to learn about IT stuff, so please bear with me. Why do you use ‘privilege’ only when you mean special privileges (above the regular user’s)? Should not all accounts have their privilege settings to ring fence and control potential damage that can be inflicted even by a user with a minimum level of access? Also, what about the newly employed (inexperienced and maybe on their probation period) who might make an unintentional but very costly mistake? Should they not have a Read- only access to the live system (and maybe full access to a safely contained sandbox) whilst they learn the system?

  • @arunv.gnanachchenthan2157

    You missed some of the families and their control count when reading out the families.

  • @borna430
    @borna430 Рік тому

    Great information. Can the same type of diagram be acceptable to represent CMMC 2.0 diagram requirements?

  • @GlamLamWow
    @GlamLamWow Рік тому

    Thank you for the video. I got two points: 1. You were referring to Level 1 & 3, while level 3 is not published yet. Did you mean Level 2 instead? 2. Shouldn't the Readiness Assessment @ 3:50 be done after the POAM, and before the implementation? I thought the goal of it was to assess whether we had everything in place to implement the missing requirements.

  • @GlamLamWow
    @GlamLamWow Рік тому

    Great video. Can you please update the information with regards to CMMC 2.0?

  • @CFH298
    @CFH298 2 роки тому

    Part 3???

  • @maxmetrix4256
    @maxmetrix4256 2 роки тому

    website is not working

  • @libardomm.trasimaco
    @libardomm.trasimaco 2 роки тому

    Thanks!

  • @rval4833
    @rval4833 2 роки тому

    awesome!

  • @SikaSOHO
    @SikaSOHO 2 роки тому

    Thanks for video. Do you have video instructions how to actually fill this out ?

  • @diegocurt3553
    @diegocurt3553 2 роки тому

    Need to do more! These are good and needed!

  • @chrisadams27
    @chrisadams27 2 роки тому

    Its 3:30am and I can't sleep, so I can to watch this video!

  • @TheMrfuturisticbaby
    @TheMrfuturisticbaby 2 роки тому

    Really great video. Where can I find that PDF doc?

  • @joshuaboyd7695
    @joshuaboyd7695 2 роки тому

    Did you ever publish part 3

  • @chrish6659
    @chrish6659 2 роки тому

    Thank you for taking the time to share this, your work is appreciated!

  • @CellarRoot
    @CellarRoot 2 роки тому

    I came here for maybe some additional context on why NIST used to have the minimum failures defined but now they don't. I found it eventually in Nist 800-63b and it's kinda completely different than the previous version of 800-63b. "No more than 100 failed attempts" and then separately, they have a usability section with "Minimum of 10 failed attempts allowed" as a usability concern. :/ I had read some summaries of the earlier versions and they seem to have just said Minumum was 10 and maximum was 100. I'm trying to be a change maker and this stuff is SPAGETTI!

  • @josegregoriodiazvasquez1871
    @josegregoriodiazvasquez1871 2 роки тому

    Very good information, where can I download that template? or an updated one?

  • @gadgetdoc
    @gadgetdoc 2 роки тому

    This was very helpful. You have a super super cool channel. I'm looking through all of your videos and I know I'm going to be going through quite a few of them in the near future.

  • @nickibolz7735
    @nickibolz7735 2 роки тому

    Where do you actually download or access the NIST assessment? I can't find that anywhere. In order to get a score to enter, I need to take the assessment, assuringly.

    • @auditorsense4243
      @auditorsense4243 2 роки тому

      Hello Nicki, you can find the NIST SP 800-171 DoD Assessment Methodology and the scoring methodology (Annex A) at the following link: securedbycss.com/wp-content/uploads/2021/02/NIST-SP-800-171-Assessment-Methodology-Version-1.2.1-6.24.2020.pdf

    • @nickibolz7735
      @nickibolz7735 2 роки тому

      @@auditorsense4243 Thank you so much!

  • @kevinmalloy2180
    @kevinmalloy2180 2 роки тому

    The FAR was established in ‘74 not ‘47.

  • @tabathahill6408
    @tabathahill6408 2 роки тому

    Is this video free to use or share? Great job and thanks in advance!

    • @auditorsense4243
      @auditorsense4243 2 роки тому

      Free to use and share! We just ask that you do not remove the credits/give credit.

  • @BerniesBastelBude
    @BerniesBastelBude 2 роки тому

    although the structure changed somehow in rev. 5, this video helped a lot to understand the concept - thx!

  • @henrysaldana1
    @henrysaldana1 3 роки тому

    Website is not working

  • @MayaMaya-tl6kl
    @MayaMaya-tl6kl 3 роки тому

    Despite my expectations as it's written in the title, I couldn't find any information on NIST 800-53 and had to listen to what I knew.

  • @paularneson1936
    @paularneson1936 3 роки тому

    Fantastic Info! Thanks for making this!

  • @patriciathomas1618
    @patriciathomas1618 3 роки тому

    Dude, why are you whispering?

  • @ricsonandre9250
    @ricsonandre9250 3 роки тому

    Iziddoxoo

  • @angelavila8341
    @angelavila8341 3 роки тому

    What if you perform a self assessment and attain a negative score? Should that score be submitted? Should you try to address most issues and redo test? Should you use negative score and generate poam? On average what do companies score?

  • @18dnu
    @18dnu 3 роки тому

    Would you recommend any training on change management for NIST standards pertaining more specifically to Technical Writing or Documentation?

  • @jasonmcgee3757
    @jasonmcgee3757 3 роки тому

    SSP (System Security Plan?? Where does this come from? We have worked with DOD for 30 years and never heard of this. Are they expecting us to create it from scratch We do portaspotties...

  • @jasonmcgee3757
    @jasonmcgee3757 3 роки тому

    Is this for all DOD contractors?

    • @brendank8892
      @brendank8892 3 роки тому

      Entering your NIST SP 800-171 assessment details into the SPRS applies to DoD contractors that handle CUI and more specifically, have the contract clause DFARS 252.204-7019 "Notice of NIST SP 800-171 DoD Assessment Requirement" in their contract. 252.204-7019 is a newer contract clause that was added back in November of 2020 as an interim rule. We have a video explaining this further that can be found here: ua-cam.com/video/jfEPbQiqalE/v-deo.html&t= Additionally, you can find more information about contract clause DFARS 252.204-7019 here: www.acquisition.gov/dfars/252.204-7019-notice-nist-sp-800-171-dod-assessment-requirements.

  • @electricmauinui3871
    @electricmauinui3871 3 роки тому

    Im bidding for a federal contractor for the first time and Im trying to register an account on the PIEE page. However, I am stuck on the "Location Code/CAGE" line of the roles section. Do I need pre-existing paperwork to register?

  • @eto895
    @eto895 3 роки тому

    How do we come into which risk level to determine Low, Medium or High ?

    • @PabloSilva-ph6mk
      @PabloSilva-ph6mk 3 роки тому

      The level determination must be given by the information system owners... I believe that this example shows how to evaluate the criteria: The risk for a supermarket information system isn't as high as the risk for a bank information system. That said, a Bank information system has to be classified as a High level and the supermarket as moderate/low.

    • @eto895
      @eto895 3 роки тому

      @@PabloSilva-ph6mk Thanks

  • @lotususa2565
    @lotususa2565 3 роки тому

    Thanks for sharing the information

  • @JustinCarlson8
    @JustinCarlson8 3 роки тому

    Do you need to upload a POAM and SSP, or just post the score into SPRS?

    • @brendank8892
      @brendank8892 3 роки тому

      Sorry for the late response, but you do not upload the actual POAM or SSP to the SPRS. You will just upload information about these items into the SPRS. The SPRS currently does not allow any documents or attachments to be uploaded.

  • @Nsorkwame
    @Nsorkwame 3 роки тому

    Great summary! Thanks sir

  • @Nsorkwame
    @Nsorkwame 3 роки тому

    Very helpful: Thanks

  • @chadnash5181
    @chadnash5181 3 роки тому

    This is a really great video. Thanks man I like all your stuff. Any chance you can share that template or let me know where it came from? I like the layout and thr look of it

    • @auditorsense4243
      @auditorsense4243 3 роки тому

      Hi Chad, thank you. The template specifically is from ComplyUp. Here is the link! www.complyup.com/cmmc-ssp-template/

  • @lindawisniewski3059
    @lindawisniewski3059 3 роки тому

    Do you need the score of 110 to be compliant as a basic user for the DOD?

    • @brendank8892
      @brendank8892 3 роки тому

      You do not need a score of 110 for the NIST 800-171 self-assessment to be compliant with DFARS 252.204-7012/7019. However, if the NIST 800-171 security requirements (controls) are not completely implemented, you must develop a Plan of Action & Milestones (POA&Ms). For every security control that is not implemented, you must document the security control in the POA&M, and describe when and how the unimplemented security control will be met. For more information on this, I recommend you check out the NIST SP 800-171 DoD Assessment Methodology, which can be found here: www.acq.osd.mil/dpap/pdi/cyber/docs/NIST%20SP%20800-171%20Assessment%20Methodology%20Version%201.2.1%20%206.24.2020.pdf Now keep in mind, POA&Ms are only acceptable for DFARS 252.204-7012/7019. When the Cybersecurity Maturity Model Certification (CMMC) is rolled out over the next few years, you cannot obtain a CMMC certification if your organization has unimplemented security requirements. For CMMC, you must have all required security practices and processes implemented at the time of the CMMC assessment. Outstanding security practices or processes will result in an organization failing the CMMC assessment.

  • @uche2564
    @uche2564 4 роки тому

    Do you know how long has the RMF has been in use by private organizations? I understand it was initially for federal use only but its now being used in the private sector. I ask because I just passed my ISC CAP exam, got my certification and im looking for jobs and I see a lot of clearance require jobs linked to the RMF, not many non cleared jobs in the private sector.

    • @auditorsense4243
      @auditorsense4243 3 роки тому

      Hello, sorry for the late reply. NIST RMF was developed back in 2014 with input from thousands of private sector organizations/individuals. That being said, there is not any guidance or dates surrounding private sector adoption as it is up to each individual organization. I am comfortable saying that adoption has increased vastly over the past few years among the private sector.

  • @erikblue6275
    @erikblue6275 4 роки тому

    Can you explain, with an exampke if possible, of how controls are more "outcome based" and how that differs from before?

    • @auditorsense4243
      @auditorsense4243 4 роки тому

      The controls have been re-written using strong action verbs to clearly define the goal of each control. The overall structure of each control is more outcome focused rather than impact focused. A good example is SC-10: Rev 4, the control reads: "The information system terminates the network connection associated with a communications session at the end of the session or after [Assignment: organization-defined time-period] of inactivity.". Rev 5, the control reads: "Terminate the network connection associated with a communications session at the end of the session or after [Assignment: organization-defined time period] of inactivity." The control is a lot more clear and concise on the end goal of the control implementation.

  • @rjodoin
    @rjodoin 4 роки тому

    Really good explanation. Can you provide the URL to the NIST website you used in the video? I can't seem to find that web page! Thanks.

    • @auditorsense4243
      @auditorsense4243 4 роки тому

      Hi Richard, glad you liked the video! I've added a link NIST's 800-53 webpage in the video description. Let us know if you have any other questions and be sure to check out our other videos!