Profile

CommunityPlatform_1350x900.jpg

Drew Scheifele

Edit My Profile


My Content

1 to 5 of 5 total
Posted By Drew Scheifele 07-05-2022 09:27:00 AM
Found In Egroup: Cybersecurity
\ view thread
Hi Demarius,Contra Costa County in California developed a set of questions to align with each of the NIST CSF subcontrols that may be helpful for your project. Their spreadsheet, local contact and open source language are available here: https://ehsd.org/smsa/Best,Drew -- Andrew Scheifele, PhD CEO ...
Posted By Drew Scheifele 06-30-2022 03:45:00 PM
Found In Egroup: Cybersecurity
\ view thread
If you want to build support for restricting USB storage of regulated data, this article may help (or at least be fun reading for the long weekend). Either way, remind your vendors not to go out drinking with 460,000 PII records on a USB drive. https://www.nytimes.com/2022/06/28/world/asia/usb-jap ...
Posted By Drew Scheifele 05-11-2022 02:47:59 PM
Found In Egroup: HECVAT Users
\ view thread
Hi all,We just took a quick look at ~150 recent HECVAT submissions through .The mean time between EDU launching the survey and vendor acknowledgement of survey was 21 days with a median time of 9 days. Throwing out the significant outliers the average time drops to 14 days (median 8 days). So bottom ...
Posted By Drew Scheifele 04-06-2022 12:26:00 PM
Found In Egroup: Cybersecurity and Privacy Governance, Risk, and Compliance
\ view thread
Hi Mike,You may want to start with the CMMC level 2 (CUI) scoping guide. Released Dec 2021.https://www.acq.osd.mil/cmmc/docs/Scope_Level2_V2.0_FINAL_20211202_508.pdfBest regards,Drew -- Andrew Scheifele, PhD CEO & Co-Founder | SaltyCloud PBC CMMC Registered Practitioner Techstars ASAP '20 +1 ...
Posted By Drew Scheifele 03-21-2022 11:02:00 AM
Found In Egroup: NIST 800-171 Compliance
\ view thread
Hi Kevin,You are correct. A CMMC certified third party assessment organization (C3PAO) cannot provide both pre-audit getting ready type services and then do the actual 3rd party assessment for the same client. Firms can offer both types of services, but for any given client they must choose to provide ...