Join Eric, Ruby, Paul, and Roz as they break down the NIST IR 8286 series and SP 800-30 guidance for cybersecurity risk assessment. This episode explores how to set enterprise risk appetite, create and score risk scenarios (including threats and vulnerabilities), use business impact analysis for prioritization, and aggregate, monitor, and report risks for executive risk decisions. The team uses relatable examples and practical case studies to show how to turn risk analysis into real-world, risk-based decisions.
About the podcast
This podcast contains dialog, voices and materials that are generated by Artificial Intelligence tools, but reviewed and published by the creator. Welcome to CMMC Unlocked, the definitive podcast for defense contractors, cybersecurity professionals, and compliance leaders navigating the complex world of the Cybersecurity Maturity Model Certification (CMMC). Hosted by a seasoned Certified CMMC Assessor and Instructor with years of hands-on experience in assessments, gap analyses, and implementation services, this series pulls back the curtain on what it really takes to achieve and maintain CMMC compliance. This podcast contains dialog, voices and materials that are generated by Artificial Intelligence tools, but reviewed and published by the creator. Each episode dives deep into the practical realities of CMMCâfrom interpreting the latest updates from the DoD and Cyber-AB, to demystifying assessment criteria, to sharing real-world lessons learned from the field. Whether you're a small business just starting your compliance journey or a prime contractor preparing for a Level 2 assessment, this podcast delivers actionable insights, expert interviews, and strategic guidance to help you succeed. What Youâll Learn: How to prepare for a CMMC assessment (and what assessors are really looking for) Common pitfalls and how to avoid them Implementation strategies that work for organizations of all sizes Updates on CMMC rulemaking, timelines, and policy changes Stories from the field: anonymized case studies and lessons learned Why Listen? Because compliance isnât just about checking boxesâitâs about protecting our national defense supply chain. And no one understands that better than someone whoâs been in the trenches, guiding organizations from uncertainty to certification.
Share this episode
Share with friends and family