CMMC, NIST, CUI, & DFARS News and Analysis for May 2023


CMMC, NIST, CUI, & DFARS News and Analysis for May 2023


In this episode Jacob and Jason discuss their takeaways from the May Cyber AB Town Hall, including Jacob's guest appearance. The initial public draft of NIST SP 800-171r3 was released; and in this episode the fellas give their initial feedback and analysis on it. Additionally, we discuss the proposed rule to expand eligibility into the DIB CS program, the recently published ND-ISAC Cybersecurity Handbook for SMBs, and the MS Volt Typhoon campaign.

Episode Links:

NIST SP 800-171r3 Draft: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r3.ipd.pdf

NIST Security Controls: Deep Dive with Dr. Ron Ross: https://www.youtube.com/watch?v=vAPFmga_NtI

Cooey Center of Excellence:: https://discord.com/invite/rPtTes5bqA

NIST SP 800-53r5: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf

The Cyber AB May Townhall: https://cyberab.org/News-Events/Town-Halls

DIB CS Proposed Rule: https://www.federalregister.gov/documents/2023/05/03/2023-09021/department-of-defense-dod-defense-industrial-base-dib-cybersecurity-cs-activities

ND-ISAC Handbook for SMBs: https://ndisac.org/wp-content/uploads/2023/05/Securing-SMB-Manufacturing-Supply-Chain-Resource-Handbook-Final_4MAY2023.pdf

MS Volt Typhoon Threat Brief: https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/

CISA VoltTyphoon Cybersecurity Advisory: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a