16 Mar ISMS Consulting Should My Org Be on a Microsoft 365 “Government Cloud”? March 16, 2023 By Pivot Point Security Should My DIB Org Be on a Microsoft 365 “Government Cloud”? The US government is increasingly focused on protecting Controlled Unclass... Continue reading
15 Mar ISMS Consulting Should we be in Microsoft 365 GCC, GCC High, or Commercial? March 15, 2023 By Pivot Point Security Companies of all sizes in the US Defense Industrial Base (DIB) that handle Controlled Unclassified Information (CUI) must achieve full ... Continue reading
28 Apr InfoSec Risk Assessment Security Risk Assessment – How to Rank Your Risks January 14, 2024 By Richard Barrus The "Goldilocks and the Three Bears" Approach I’m sure most people are familiar with the children’s tale of “Goldilocks and the Three ... Continue reading
28 Jun Third Party Risk Management Hiring Security Talent? Give Professional Certifications the Weight They Deserve (Not More) January 13, 2024 By Richard Barrus Recently I earned a Certified Third Party Risk Assessor (CTPRA) designation from the Shared Assessments Program. This certification int... Continue reading
16 Apr Third Party Risk Management Agreed Upon Procedures (AUP) vs. SOC 2 January 4, 2024 By Richard Barrus Editor’s Note: This post was originally published in April 2017. It has been updated to reflect the name change from AUP to SCA. A Sta... Continue reading