Search
Joshua Duvall
Jan 31, 20203 min read
DoD Contractors Beware: CMMC & DFARS 252.204-7012 & NIST SP 800-171
Later today, the Department of Defense will release version 1.0 of its Cybersecurity Maturity Model Certification ("CMMC"). With the...
Joshua Duvall
Dec 16, 20192 min read
DoD Publishes CMMC Draft Version 0.7
The Department of Defense ("DoD") recently published its Draft Cybersecurity Maturity Model Certification ("CMMC") Version 0.7 (dated...
Joshua Duvall
Jun 23, 20193 min read
DoD Should Create Objective Guidelines for Selecting the Appropriate CMMC "Go/No-Go" Thre
The Department of Defense (DoD) will likely publish a draft Cybersecurity Maturity Model Certification (CMMC) standard sometime this...
Joshua Duvall
Jun 8, 20191 min read
DoD to Propose Cybersecurity Maturity Model Certification (CMMC)
DoD to propose Cybersecurity Maturity Model Certification (CMMC)––via third-party audit––and it will add another layer to defense...
Joshua Duvall
May 8, 20191 min read
Verizon 2019 Data Breach Investigations Report
The 2019 DBIR is finally here! Some interesting items at first glance: – 32% of breaches involved phishing – 33% included Social attacks...
Joshua Duvall
Apr 30, 20191 min read
Sedona Conference Publishes Commentary on Attorney-Client Privilege and Work Product Protection for
The Sedona Conference Working Group 11 on Data Security and Privacy Liability (WG11) publishes commentary on the application of the...
Joshua Duvall
Apr 2, 20191 min read
Got DoD Cyber Compliance? DoD to Create New Cyber Standards
Got DoD Cyber Compliance? For DoD contractors, it appears that DFARS 252.204-7012 (NIST SP 800-171) compliance was just the beginning....
Joshua Duvall
Dec 21, 20174 min read
Cybersecurity––Penetration Testing Under a Lawyer’s Umbrella
Nowadays, “malware,” “ransomware,” and “hacking” are ubiquitous terms. Take a quick glance at your LinkedIn feed and you might see...
Joshua Duvall
Nov 28, 20174 min read
Cyber DFARS Compliance and Agency Evaluations (NIST SP 800-171)
December 31, 2017 marks the deadline for compliance with DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident...
Joshua Duvall
Nov 26, 20173 min read
The Intersection of Law, Cybersecurity, and Data Breaches
In 2012, Robert Mueller famously professed, “I am convinced that there are only two types of companies: those that have been hacked and...