

What We Do
-
We help organizations build cybersecurity into their day-to-day practices, and comply with applicable cybersecurity regulations
-
We help federal contractors meet NIST SP 800-171, CMMC, and DFARS 202.254-7012 requirements

Why Cybersecurity is Necessary
-
The Department of Defense (DoD) created the Internet for government use and did not anticipate that the whole world would eventually use it
-
Access controls weren't built into the Internet, so anyone can use it, including bad actors
-
As a result, Internet cybercrime is pervasive, impacting everyone, everywhere

The Result
-
Organizational cyber resiliency
-
Compliance with NIST, CMMC, and other major cybersecurity standards
-
Protection of your people, data, assets, and reputation

What You Need to Do to Be
NIST SP 800-171 Compliant
1
Evaluate compliance with NIST SP 800-171 security control families.
2
Perform gap analysis.
3
Minimize scope of covered data and systems.
4
Create and review the System Security Plan (SSP).

5
Create and review the Plan of Action and Milestones (POAM).
6
Report gaps and POAM to Buyer in accordance with contractual obligations.
7
Meet requirements for prompt reporting of cyber incidents on the DIBNET website.
8
Flow down requirements to covered subcontractors.
Services We Provide

Identify security roles, and scope of covered data and systems.


Assess staff knowledge and awareness of NIST 800-171 and organizational security.


Analyze risks and perform comprehensive SWOT and security assessments.


Develop System Security Plan (SSP), Plan of Action and Milestones (POAM), and policies.


Plan training curriculum and covered topics.


Train staff according to scope of influence, role, responsibilities, policies and procedures.


Document evaluation and training results.


Evaluate staff and system performance against benchmarks.



