CMMC Level 2 MFA: Phishing-Resistant Logins With FIDO2 Security Keys
If you’re chasing CMMC Level 2, you already know the ugly truth: phishing is still the easiest way into a DoD contractor. Attackers don’t need zero-days when they can steal…
If you’re chasing CMMC Level 2, you already know the ugly truth: phishing is still the easiest way into a DoD contractor. Attackers don’t need zero-days when they can steal…
Microsoft Teams can feel like a conference room, a file cabinet, and a phone system all in one. That’s great for speed, but it’s also how Controlled Unclassified Information (CUI)…
If you’re preparing for CMMC Level 2, BitLocker is one of those controls that sounds simple until the assessor asks, “Show me proof.” The goal isn’t just turning on encryption,…
When an assessor asks, “Show me your proof,” they’re not asking if you meant to encrypt laptops. They want evidence that encryption is on, it stays on, and it covers…
CMMC POA&M for Level 2: How I Write It, Age It, and Avoid Assessor Flags (Template Included) If you’re heading into a CMMC Level 2 assessment, your CMMC POA&M can…
How many “temporary” accounts are still active in your tenant right now? If you handle CUI, that question isn’t academic. Under CMMC user provisioning expectations, every account needs a clear…
If you’re a small defense contractor, your CMMC SSP template can’t read like a policy brochure. It has to read like a map. A map of where CUI lives, who…
If you’re chasing CMMC Level 2, the fastest way to blow your schedule (and your budget) is to scope Microsoft 365 the wrong way. I see it all the time:…
If I’m walking into a CMMC assessment, I don’t want my patching story to sound like “we try our best.” I want it to sound like a process with clear…
If you’re handling CUI in Microsoft 365, you don’t get to treat retention and holds like a “set it once” task. Under CMMC Level 2, I’ve found auditors and incident…