Jacob Horne’s Post

View profile for Jacob Horne, graphic

CMMC Town Crier | Ask me about NIST cybersecurity controls | Smashing compliance frameworks for fun and profit | Cyber policy wonk |

New podcast is up: scheduled post while on vacay edition. Anyways, what I used to say: 90% of the questions in the CMMC ecosystem could be answered if people read the first three chapters of NIST SP 800-53. What I say now: 90% of the questions in the CMMC ecosystem could be answered if people took the new RMF-series training courses from NIST. There is a one hour course for each RMF special publication: 𝗦𝗣 𝟴𝟬𝟬-𝟯𝟳 - Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy 𝗦𝗣 𝟴𝟬𝟬-𝟱𝟯 - Security and Privacy Controls for Information Systems and Organizations 𝗦𝗣 𝟴𝟬𝟬-𝟱𝟯𝗔 - Assessing Security and Privacy Controls in Information Systems and Organizations 𝗦𝗣 𝟴𝟬𝟬-𝟱𝟯𝗕 - Control Baselines for Information Systems and Organizations There is new info. There are new charts. The courses are good. You should take them. The courses should be mandatory pre-requisites to any CMMC training. Check out the latest podcast for our course review (links below 👇) Like ❤️ and subscribe 🔔

  • No alternative text description for this image
CM PRaVDA

Design PM | @LifestYleBroker | IoT & BIM Coordinator

1mo

There is a one hour course 🎞️ for each RMF special publication: “BRUNCH-n-LEARN” 👀 but where??? Q: can SIMPLIFIED naming of FRAMEWORKS help everyone get on the “same page” 📄 … it worked for Larry Page EXAMPLE: the ABC, 123, xYz of NIST, ISO or any “GOV.reg” 🤔 perhaps every FRAMEWORK or public POLICY should have its own standardized DOMAIN to streamline any regulation lookup… 🎞️ 🗣️ 🎙️ 📃 review and comments by industry experts? 𝗦𝗣 𝟴𝟬𝟬-𝟯𝟳 - RMF: (SPC) Security and Privacy Controls ISO 𝗦𝗣 𝟴𝟬𝟬-𝟱𝟯 - GENERAL (SPC) Security & Privacy Controls ISO 𝗦𝗣 𝟴𝟬𝟬-𝟱𝟯𝗔 - ASSESSING (SPC) Security & Privacy ISO 𝗦𝗣 𝟴𝟬𝟬-𝟱𝟯𝗕 - BASELINES controlls(SPC) for an ISO

Like
Reply
Victoria Yan Pillitteri

Security Engineering and Risk Management

1mo

For inquiring minds - yes, it’s a real human doing the narration!

Greg Zacharski

Director of Strategic Development | CyberNINES

1mo

…but where’s the EZ-button to compliance. 🤣

Linda Rust

Strategic advisor | Translating cybersecurity to business | Engaging Fortune 100 C-suite and Board, private equity (PE), and company owners | vCISO | Step Zero™ rapid cybersecurity estimates for M&A and compliance gaps

1mo

Hot tip and good advice. Will do.

Like
Reply
👉Zach M.

Aspiring GRC Analyst driven to defend an organization through innovative customer support and technical solutions👉CompTIA Security+ Certified

1mo

Thank you, Jacob Horne and Jason Sproesser for all of your dedication and research! The world of Cybersecurity and GRC in general is enhanced through your discussions!

Like
Reply
See more comments

To view or add a comment, sign in

Explore topics