Optic Cyber
Optic Cyber
  • 72
  • 165 177
Customer Responsibilities Matrix (CRM) - What is it?
Want to learn more about a Customer Responsibilities Matrix (CRM) and why the DoD would think their contractors need them? Check out this video to learn what they are and why they are important.
Presented by Tom Conkle, CISSP (@TomConkle)
Reach out at Info@OpticCyber.com if you have any questions regarding the requirements! Check out our services at www.opticcyber.com/services/cmmc-services
32 CFR Part 170
Cybersecurity Maturity Model Certification (CMMC) Program: dodcio.defense.gov/cmmc/about/
Office of the Department of Defense Chief Information Officer (CIO)
CMMC Overview: dodcio.defense.gov/cmmc/about/
CMMC Guidance Documentation: dodcio.defense.gov/CMMC/Resources-Documentation/
Optic Cyber Solutions
Customer Responsibilities Matrix: www.opticcyber.com/resources.html
SP 800-171 Profile: www.opticcyber.com/resources.html
SPRS Scoring Worksheet: www.opticcyber.com/resources.html
มุมมอง: 58

วีดีโอ

CMMC Program Rule - 32 CFR Released!
มุมมอง 3432 หลายเดือนก่อน
The final rule is here, what happens now? Watch this video to learn more about what made it into 32 CFR, Part 170! Presented by Kelly Hood, CISSP (@KellyHood_) Reach out at Info@OpticCyber.com if you have any questions regarding the requirements! Check out our services at www.opticcyber.com/services/cmmc-services 32 CFR Part 170 Cybersecurity Maturity Model Certification (CMMC) Program: dodcio....
NIST SP 800-171 Rev 3 - Overview
มุมมอง 2353 หลายเดือนก่อน
NIST SP 800 171 Rev 3 is here! Check out this video to learn about changes in Rev 3 and where to dig in! Presented by Tom Conkle, CISSP (@TomConkle) Optic Cyber Solutions strives to help organizations identify and address their blind spots through our assessment, implementation, and advising services. Reach out at Info@OpticCyber.com if you have questions regarding the Rev 3 changes or to learn...
CMMC 2.0 - What do I need to do?
มุมมอง 4224 หลายเดือนก่อน
Trying to figure out how to get started with CMMC? Check out this video for an overview of what you need to know! Presented by Tom Conkle, CISSP (@TomConkle) Reach out at Info@OpticCyber.com if you have any questions regarding the requirements! Check out our services at www.opticcyber.com/services/cmmc-services Office of the Under Secretary of Defense for Acquisition & Sustainment Securing the ...
NIST SP 800-171 Rev 2 - Overview
มุมมอง 5635 หลายเดือนก่อน
Looking for an overview of NIST SP 800-171 Rev 2? In this video, we address common questions about standard, clarifying its purpose, when it's necessary, and what's in it! Specifically, we dive into Revision 2, released in 2020, which remains mandated by many requirements and regulations today. Presented by Kelly Hood, CISSP (@KellyHood_) Optic Cyber Solutions strives to help organizations iden...
CMMC 2.0 Overview
มุมมอง 9186 หลายเดือนก่อน
Trying to figure out what CMMC actually is and if you should care? Check out this video for an overview of the Cybersecurity Maturity Model Certification (CMMC) program and who's required to do what! Presented by Kelly Hood, CISSP (@KellyHood_) Reach out at Info@OpticCyber.com if you have any questions regarding the requirements! Check out our services at www.opticcyber.com/services/cmmc-servic...
What Changed? - NIST SP 800-171 Rev2 to Rev3
มุมมอง 8827 หลายเดือนก่อน
The final update to NIST SP 800 171 Rev 3 is here! Check out this video to learn about what changed and where to dig in! Presented by Tom Conkle, CISSP (@TomConkle) Optic Cyber Solutions strives to help organizations identify and address their blind spots through our assessment, implementation, and advising services. Reach out at Info@OpticCyber.com if you have questions regarding the Rev 3 cha...
Profiles - NIST Cybersecurity Framework 2.0
มุมมอง 3K8 หลายเดือนก่อน
Trying to figure out how to use the CSF Profiles? Check out this video to learn more about what Profiles are, the different types, and how to get started! Presented by Kelly Hood, CISSP (@KellyHood_) Optic Cyber Solutions strives to secure your business, keeping you in control through our assessment, implementation, and advising services. For more information about Optic Cyber Solutions and how...
Do I Measure Up? - NIST Cybersecurity Framework 2.0
มุมมอง 4.1K9 หลายเดือนก่อน
Discover what the release of the NIST Cybersecurity Framework (CSF) 2.0 means for you and what to do now! Align your capabilities to the updated Framework, identify gaps in your current strategy, and create a roadmap to build confidence in your cybersecurity. Presented by Kelly Hood, CISSP (@KellyHood_) Optic Cyber Solutions strives to secure your business, keeping you in control through our as...
Overview - NIST Cybersecurity Framework 2.0
มุมมอง 14K9 หลายเดือนก่อน
Keep hearing about the NIST Cybersecurity Framework 2.0, but not sure what it is or why you'd use it? Check out this video to get an introduction to the CSF and learn about its 3 primary components: the Core, the Tiers, and the Profiles. Presented by Kelly Hood, CISSP (@KellyHood_) Optic Cyber Solutions strives to secure your business, keeping you in control through our assessment, implementati...
What Changed? - NIST Cybersecurity Framework 2.0
มุมมอง 27K10 หลายเดือนก่อน
The final update to the NIST Cybersecurity Framework 2.0 is here! Check out this video to learn about what changed and where to dig in! Presented by Kelly Hood, CISSP (@KellyHood_) Optic Cyber Solutions strives to help organizations identify and address their blind spots through our assessment, implementation, and advising services. For more information about Optic Cyber Solutions and how we ca...
FISMA Overview
มุมมอง 2K11 หลายเดือนก่อน
Confused about the Federal Information Security Modernization Act (FISMA) & its relevance to you? Discover the essentials in our latest video. Learn why FISMA is crucial for safeguarding government data operated by both federal agencies & commercial companies. Got questions? Contact us at Info@OpticCyber.com. Find out how Optic can assist you in meeting your FISMA requirements and implementing ...
CMMC 2.0 Proposed Rule - Public Comment (Dec 2023)
มุมมอง 265ปีที่แล้ว
The CMMC v2.0 Proposed Rule has been released for public comment. Check out this video for an overview of what changed (and what didn't)! Presented by Tom Conkle, CISSP (@TomConkle) Reach out at Info@OpticCyber.com if you have any questions regarding the requirements! Check out our services at www.opticcyber.com/services/cmmc-services Optic Cyber Solutions Resources Resources Home Page: www.opt...
Current Cybersecurity Requirements for the DIB
มุมมอง 149ปีที่แล้ว
Keep hearing everyone talking about CMMC and NIST SP 800-171, but not sure what's actually required today? Check out this video to learn about the cybersecurity requirements that are already in place today for DoD contractors! Reach out at Info@OpticCyber.com if you have any questions regarding the requirements! Check out our services at www.opticcyber.com/services/cmmc-services Presented by Ke...
NIST 800 171 Rev3 - FPD Overview
มุมมอง 331ปีที่แล้ว
Trying to figure out what NIST is proposing to change in SP 800-171 Rev3? Check out this video to get an overview of what's being added, what's being withdrawn, and what other resources NIST provided to help us figure it out! Reach out at Info@OpticCyber.com if you have questions regarding the Rev 3 changes or to learn how Optic can help you stay ahead of the curve and prepare CMMC. Presented b...
NIST SP 800-53 - Patch Process Overview
มุมมอง 346ปีที่แล้ว
NIST SP 800-53 - Patch Process Overview
System & File Scanning (SI.L1-3.14.5)
มุมมอง 93ปีที่แล้ว
System & File Scanning (SI.L1-3.14.5)
Update Malicious Code Protection (SI.L1-3.14.4)
มุมมอง 89ปีที่แล้ว
Update Malicious Code Protection (SI.L1-3.14.4)
Secure Your Business - Build a Cybersecurity Program that Works for You
มุมมอง 62ปีที่แล้ว
Secure Your Business - Build a Cybersecurity Program that Works for You
Malicious Code Protection (SI.L1-3.14.2)
มุมมอง 97ปีที่แล้ว
Malicious Code Protection (SI.L1-3.14.2)
Flaw Remediation (SI.L1-3.14.1)
มุมมอง 155ปีที่แล้ว
Flaw Remediation (SI.L1-3.14.1)
Public-Access System Separation (SC.L1-3.13.5)
มุมมอง 113ปีที่แล้ว
Public-Access System Separation (SC.L1-3.13.5)
Boundary Protection (SC.L1-3.13.1)
มุมมอง 225ปีที่แล้ว
Boundary Protection (SC.L1-3.13.1)
Manage Physical Access (PE.L1-3.10.5)
มุมมอง 77ปีที่แล้ว
Manage Physical Access (PE.L1-3.10.5)
Full Draft - NIST Cybersecurity Framework 2.0
มุมมอง 7Kปีที่แล้ว
Full Draft - NIST Cybersecurity Framework 2.0
Physical Access Logs (PE.L1-3.10.4)
มุมมอง 105ปีที่แล้ว
Physical Access Logs (PE.L1-3.10.4)
Escort Visitors (PE.L1-3.10.3)
มุมมอง 136ปีที่แล้ว
Escort Visitors (PE.L1-3.10.3)
Limit Physical Access (PE.L1-3.10.1)
มุมมอง 89ปีที่แล้ว
Limit Physical Access (PE.L1-3.10.1)
Media Disposal (MP.L1-3.8.3)
มุมมอง 70ปีที่แล้ว
Media Disposal (MP.L1-3.8.3)
Authentication (IA.L1-3.5.2)
มุมมอง 119ปีที่แล้ว
Authentication (IA.L1-3.5.2)

ความคิดเห็น

  • @rickrandall3174
    @rickrandall3174 24 วันที่ผ่านมา

    Good summary. Well done! 👍

  • @horaceward1657
    @horaceward1657 2 หลายเดือนก่อน

    Thank You Are you a C3PAO

    • @OpticCyber
      @OpticCyber 2 หลายเดือนก่อน

      We are a Registered Practitioner Organization (RPO) with Registered Practitioner (RP) and Certified CMMC Professional (CCP) on staff. Feel free to reach to Info@OpticCyber.com and we can provide you a POC to help!

    • @OpticCyber
      @OpticCyber 2 หลายเดือนก่อน

      We are a Registered Practitioner Organization (RPO) with Registered Practitioner (RP) and Certified CMMC Practitioner (CCP) on staff. Feel free to reach out to Info@OpticCyber.com and we can send you a POC to help!

    • @OpticCyber
      @OpticCyber หลายเดือนก่อน

      We are not a C3PAO. Optic Cyber Solutions is an RPO and help companies prepare for certification. Reach out to info@OpticCyber.com and we can direct you!

  • @MrKhann
    @MrKhann 2 หลายเดือนก่อน

    Thank you Kelly! very articulate and awesome explanation. Would it be possible for you to share with me resources or video link for maturity assessment based on NIST?

  • @mamok3479
    @mamok3479 2 หลายเดือนก่อน

    Instead of presenting your essay as it is, make more relatable with every day IT experience

  • @OmarElliottgreen
    @OmarElliottgreen 2 หลายเดือนก่อน

    Perfect timing Kelly! Thanks!

  • @srleb3462
    @srleb3462 3 หลายเดือนก่อน

    Thanks for informative video

  • @troyschramii4828
    @troyschramii4828 3 หลายเดือนก่อน

    Can you update the links to the template resources? they've been moved

  • @troyschramii4828
    @troyschramii4828 3 หลายเดือนก่อน

    Do you have a copy of this presentation you made that you can share?

  • @abhijeetpatil1619
    @abhijeetpatil1619 3 หลายเดือนก่อน

    How this "Farmework" have to do with using ISA/IEC 62443 standards to secure ICS?

  • @xemphim4833
    @xemphim4833 5 หลายเดือนก่อน

    Nice video

  • @justkimmiann
    @justkimmiann 5 หลายเดือนก่อน

    These videos are great! Thank you for sharing!

  • @samrendr1
    @samrendr1 5 หลายเดือนก่อน

    Informative knowledgable

  • @tripline8076
    @tripline8076 5 หลายเดือนก่อน

    Great job! Wish you had a list of the security requirement questions. The SSP on the NIST portal is still using rev2 template. Looking to see when rev3 SSP template will come out.

    • @OpticCyber
      @OpticCyber 5 หลายเดือนก่อน

      Hello! We have an updated Rev3 SSP template on our Resources page under the NIST SP 800-171 section here: www.opticcyber.com/resources.html Hope this helps!

  • @troywisdom704
    @troywisdom704 6 หลายเดือนก่อน

    Thank you for taking the time to explain POA&M. As someone trying to learn about the process, this was helpful!

  • @ravian8711
    @ravian8711 6 หลายเดือนก่อน

    Very well explained 🎉

  • @j4r3kk88
    @j4r3kk88 7 หลายเดือนก่อน

    Lol, what a luck I have today , that I find You. You explain this very well. In my life upgrade I was not wishing any more than Your YT Video. Fantastic.. :)

  • @DrSharonMK
    @DrSharonMK 7 หลายเดือนก่อน

    Thanks for the breakdown. The MaPT can't be downloaded. It redirects to Hubspot, requiring the administrator's login. I would to see that template.

    • @OpticCyber
      @OpticCyber 7 หลายเดือนก่อน

      Hello, I apologize for the issues! Please try this link: 43828014.hs-sites.com/nist-cybersecurity-framework-2.0-do-i-measure-up It will take you to Hubspot, but should not require any sort of administrator's login.

  • @EmilioRivera-vd1ok
    @EmilioRivera-vd1ok 7 หลายเดือนก่อน

    How can I get your slides on this?

    • @OpticCyber
      @OpticCyber 7 หลายเดือนก่อน

      Please email Info@OpticCyber.com requesting the slides and I'll get them right over!

  • @bakhtavarvachha2316
    @bakhtavarvachha2316 7 หลายเดือนก่อน

    Presented in a really nice way. Great job

  • @arthurkatz8035
    @arthurkatz8035 7 หลายเดือนก่อน

    Thanks Kelly

  • @w.c.7247
    @w.c.7247 8 หลายเดือนก่อน

    My go to for NIST CSF knowledge in plain language. Since you asked in your video about potential future topics : - )..curious if you were familiar with the NIST CSF Financial Services Sector profile ("CRI Profile")?

    • @OpticCyber
      @OpticCyber 8 หลายเดือนก่อน

      Thanks! That's a great idea - I have some familiarity with the CRI Profile but haven't gotten to dig into the 2.0 update yet. I'll have to add that to my list!

  • @darrenmoore3677
    @darrenmoore3677 8 หลายเดือนก่อน

    thank you for providing a great 'bridge' between v1.1 -> v2.0 - very helpful

  • @waleedacademy
    @waleedacademy 8 หลายเดือนก่อน

    Great content

  • @yogeshnandikol1357
    @yogeshnandikol1357 8 หลายเดือนก่อน

    Great Content , Thanks for the details. Could you please recommend from where to do NIST certification? Thanks

    • @OpticCyber
      @OpticCyber 8 หลายเดือนก่อน

      While NIST doesn't provide "certification" criteria for the CSF, there are companies that provide training for individual certifications as well as others that conduct CSF program assessments. Optic Cyber Solutions would be happy to conduct a CSF assessment of your cybersecurity program - please reach to Info@OpticCyber.com for more information!

  • @gurugamer8632
    @gurugamer8632 8 หลายเดือนก่อน

    What type of appliance is commonly used for NIST cybersecurity?

    • @OpticCyber
      @OpticCyber 8 หลายเดือนก่อน

      There are many Governance, Risk, and Compliance (GRC) tools that track cybersecurity governance against the CSF to help ensure you have appropriate coverage for the CSF. Additionally, they provide processes for helping align business risk to the CSF enabling you to ‘right-size’ your capabilities to properly manage risk. Additionally, CSF Profiles are a great way tool to help implement the CSF.

  • @muralisunnam
    @muralisunnam 9 หลายเดือนก่อน

    Thank you for the awesome content Kelly Hood

  • @ishwaryanarayan1010
    @ishwaryanarayan1010 9 หลายเดือนก่อน

    Do you have any openings for cyber security professional out there ?

  • @loharris1997
    @loharris1997 9 หลายเดือนก่อน

    Thank you Kelly!

  • @akocemong
    @akocemong 9 หลายเดือนก่อน

    What are the subcategories from the Framework that can be incorporated into vulnerability management process?

    • @OpticCyber
      @OpticCyber 9 หลายเดือนก่อน

      Looking from a preventative point of view, a few of the Subcategories that we typically consider when developing vulnerability management programs include: GV.PO-02 to establish the policy and plan, ID.RA-01 to identify vulnerabilities, ID.RA-05 to priorities them for remediation, ID-RA-06 to manage them, ID.IM-04 to plan for addressing exploited vulnerabilities, and PR.PS-02 to enable routine patching.

  • @JSAGOO
    @JSAGOO 9 หลายเดือนก่อน

    Thank you 🙏🏻

  • @javier_
    @javier_ 9 หลายเดือนก่อน

    Thank you!

  • @lahcentizi
    @lahcentizi 9 หลายเดือนก่อน

    Excellent explanation, thanks for sharing

  • @mohchinkhan237
    @mohchinkhan237 9 หลายเดือนก่อน

    Very well explained… looking forward for more videos in future

  • @jsantosandrade
    @jsantosandrade 9 หลายเดือนก่อน

    Is NIST CSF v1.1 retired now?

    • @OpticCyber
      @OpticCyber 9 หลายเดือนก่อน

      The Cybersecurity Framework v1.1 has been archived on NIST's website now that v2.0 has been released. NIST is recommending that companies use v2.0 moving forward; however, since the CSF isn't a compliance standard v1.1 can still be used if desired.

  • @AndersonLacruz-h5f
    @AndersonLacruz-h5f 10 หลายเดือนก่อน

    Thanks for taking the time to break this down and provide details of changes

  • @Mjonir_42
    @Mjonir_42 10 หลายเดือนก่อน

    Wonderful video congrats

  • @gianfrancocappello8601
    @gianfrancocappello8601 10 หลายเดือนก่อน

    Thank you Kelly for this helpful summary on NIST CSF 2.0!

  • @Jimhuang1
    @Jimhuang1 10 หลายเดือนก่อน

    Many thanks for you sharing 😀

  • @JCMathis621
    @JCMathis621 10 หลายเดือนก่อน

    Love the videos. They have all been very helpful and no nonsense, just straight to the point and informative! Thank you!

  • @velo1337
    @velo1337 10 หลายเดือนก่อน

    This Video explains the Changes to the Framework. 13:20 is basically all you need to know

  • @checkat5
    @checkat5 10 หลายเดือนก่อน

    Thanks for the great and significant explanation on the frameworks differences.

  • @duke97
    @duke97 10 หลายเดือนก่อน

    Thanks Kelly, can you share slide ?

    • @OpticCyber
      @OpticCyber 10 หลายเดือนก่อน

      Yes, no problem. If you can send an email to Info@OpticCyber.com, we'll send the slides over!

  • @dancingkidkul9325
    @dancingkidkul9325 10 หลายเดือนก่อน

    Hey, Quick question. If we have NIST CSF implemented in the organization then do we need to implement Govern as well or its not mandatory and needed?

    • @OpticCyber
      @OpticCyber 10 หลายเดือนก่อน

      The CSF is intended to be flexible for companies to implement in a way that works best for them. Therefore, you could choose to tailor the new Govern Function out; however, this area was expanded to emphasize the need for having a cybersecurity strategy to help manage cybersecurity risk and drive cyber resilience.

  • @roddyforward
    @roddyforward 10 หลายเดือนก่อน

    Great and concise explanation Kelly. Congrats and thanks for sharing!

  • @herpderp1238
    @herpderp1238 10 หลายเดือนก่อน

    Are there subcategories that carry overt from 1.0? For example, in every list they've published, under Identify's Risk assessment it goes ID.RA-01, 02, 03, 04, and 05 then skips to ID.RA-07. Does this mean that the ID.RA-06 remains unchanged?

    • @OpticCyber
      @OpticCyber 10 หลายเดือนก่อน

      They haven't published a detailed mapping of how the Subcategories were moved around, but if you check out the Discussion Draft released last April, it will give you a starting point since it does include that level of detail (www.nist.gov/system/files/documents/2023/04/24/NIST%20Cybersecurity%20Framework%202.0%20Core%20Discussion%20Draft%204-2023%20final.pdf). In the example you provided, ID.RA-06 is still included in the updated CSF 2.0, but has had some wording changes to expand it's outcome.

    • @herpderp1238
      @herpderp1238 10 หลายเดือนก่อน

      thank you for the response, also my mistake in my example I meant to use ID.AM, ID.AM jumps from -05 to -07@@OpticCyber

    • @herpderp1238
      @herpderp1238 10 หลายเดือนก่อน

      that doc is exactly what I needed, much appreciated!@@OpticCyber

    • @OpticCyber
      @OpticCyber 10 หลายเดือนก่อน

      @@herpderp1238Glad to help! In the case of ID.AM-06, it was removed and the concepts are now included under the new GV.RR.

  • @aae7583
    @aae7583 10 หลายเดือนก่อน

    glad this video popped up in my algo. I am taking the CISSP in two weeks. very helpful.

  • @Jimhuang1
    @Jimhuang1 10 หลายเดือนก่อน

  • @quitefar03
    @quitefar03 10 หลายเดือนก่อน

    great review Kelly

  • @tiagocaldas
    @tiagocaldas 10 หลายเดือนก่อน

    Thanks for the "cut to the chase" approach. Very good!

  • @jasonpowell1924
    @jasonpowell1924 10 หลายเดือนก่อน

    Great job!