Cybersecurity & Risk Management

Is Your Firm's Cybersecurity Certifiable?

Azunna Anyanwu
Featured image for: Is Your Firm's Cybersecurity Certifiable?

When NIST 800-171 (Protecting Controlled Unclassified Information (CUI) in Nonfederal Systems and Organizations) was released in December 2016, it was relatively limiting (applying to a specific class of data called CUI). However, the security controls that are included (derived from NIST 800-53) are relevant to every organization and a great foundation to develop a cyber security standard.

Initially, vendors were allowed/expected to self-certify their organization’s adherence to the standard. It’s been an open secret that the government would only accept vendor’s self-certification for a limited time. Beginning September 2020 (just 1 year from now!), there will be 3rd party assessors to validate how well companies are protecting their information assets.

Are you ready? If not, Aronson LLC would be happy to advise and guide you on your security journey. Feel free to message me directly and I’ll get you connected.

FYI – Just because you don’t have any DOD contracts doesn’t mean you may not be affected. Government contractors will have to pass on these requirements to their suppliers and vendors that manage or store sensitive and critical systems and data (think cloud providers, SaaS applications, etc). Be prepared!

For more details, check out this blog post!

cyber #cybersecurity #NIST

Additional Insights

Read: Lessons Learned on The Journey to Becoming a CISO
Featured image for: Lessons Learned on The Journey to Becoming a CISO
Cybersecurity & Risk Management

Lessons Learned on The Journey to Becoming a CISO

Bridging the gap between technology strategy and implementation to enable the business outcomes clients desire.

Azunna Anyanwu
Read: What Does Agile Have to Do with Cybersecurity Maturity?
Featured image for: What Does Agile Have to Do with Cybersecurity Maturity?
Cybersecurity & Risk Management

What Does Agile Have to Do with Cybersecurity Maturity?

Adopting an agile mindset and incremental methodology is fundamental to achieving meaningful cybersecurity maturity and organizational security culture.

Azunna Anyanwu

Stay Informed on Technology Leadership

Get insights on IT strategy, cybersecurity, and digital transformation delivered to your inbox.