NIST Releases Quick-Start Guide for Cybersecurity Supply Chain Risk Management

November 6, 2024

NIST released an initial public draft of the Cybersecurity Supply Chain Risk Management: Due Diligence Assessment Quick-Start Guide. People who…

CMMC Finalized: What You Need to Know

October 25, 2024

In October 2024, the DoD published the final version of the Cybersecurity Maturity Model Certification (CMMC), nearly three full years…

Defending City Governments Against Ransomware

August 21, 2024

Ransomware is a cybersecurity threat that continues to become more common and increasingly sophisticated. All industries are vulnerable to attacks,…

Cybersecurity Lessons from the CrowdStrike Outage

July 29, 2024

On July 18th, a bug in a CrowdStrike software update led to a massive IT outage that had global ramifications.…

FedRAMP JAB Authorization vs Agency Authorization

June 5, 2024

***In August 2024, FedRAMP discontinued the JAB Authorization option.*** Cloud Service Providers (CSPs) that want to sell their Cloud Service…

NIST Releases Four Draft Publications Focused on AI Security

May 7, 2024

The National Institute of Standards and Technology (NIST) released four draft publications designed to help organizations improve the safety, security,…

Draft Rules Published for Cyber Incident Reporting Requirements

March 29, 2024

On March 27, the US Cybersecurity and Infrastructure Security Agency (CISA) published draft rules detailing requirements for critical infrastructure companies…

Safeguards Rule Breach Notification Requirements Updated for Non-Banking Financial Institutions

November 2, 2023

The Federal Trade Commission (FTC) has given the green light to changes to the GLBA Safeguards Rule Breach Notification requirement.…

Comparing FedRAMP and GovRAMP

September 12, 2023

***This blog was updated reflect the branding change from StateRAMP to GovRAMP, and the discontinuation of the FedRAMP JAB Authorization…

NIST CSF 2.0 Draft Released

August 21, 2023

The widely used NIST Cybersecurity Framework (CSF) is getting its first major upgrade in nearly a decade. Following more than…

Finding a credible expert with the appropriate background, expertise, and credentials can be difficult. CompliancePoint is here to help.