The People Behind the Progress: 10 years of Defending.
A 10-year reflection on the people, judgment, learning, and operational security mindset behind InfusionPoints’ continuous defense mission.
Read full blog hereThe full InfusionPoints blog library, separated from podcasts so readers can scan, search, and dig into the topics that matter.
The full InfusionPoints blog library, migrated into the new site experience with practical guidance for authorization, continuous trust, secure cloud operations, and mission defense.
A 10-year reflection on the people, judgment, learning, and operational security mindset behind InfusionPoints’ continuous defense mission.
Read full blog herePersonnel security, access models, staffing, and IL6 readiness under DISA’s latest Cloud Service Provider Security Requirements Guide.
Read full blog hereAgencies own the risk, but providers own the fix. See what CSPs and contractors must deliver under BOD 26-04 and what evidence agencies should demand.
Read full blog hereCR26 changes FedRAMP engineering skills: infrastructure as code, serverless architecture, CI/CD controls, continuous vulnerability engineering, observability, security logging, and governed AI.
Read full blog hereAWS-Native Security Operations Series | Part 5 of 6. How Command Center turns AWS security signals into managed action, evidence, authorization visibility, and continuous trust.
Read full blog hereHow VNSOC360° brings AI speed and human judgment into continuous security operations without losing trust, accountability, and proof.
Read full blog hereThe directive replaces static patch schedules with risk-based timelines as short as 3 calendar days. Here is what changes and how agencies should prepare.
Read full blog hereCommunity colleges do not need more cybersecurity noise. See how VNSOC360° helps close the gap between what colleges must protect and what lean teams can operate.
Read full blog hereAWS-Native Security Operations Series | Part 4 of 6. How AWS Config, conformance packs, Command Center, and ConMon-as-a-Service replace point-in-time audits with an always-on compliance posture.
Read full blog hereAWS-Native Security Operations Series | Part 3 of 6How CloudTrail, CloudWatch, Kinesis, OpenSearch, and S3 work together to capture, process, and preserve the evidence your…
Read full blog hereAWS-Native Security Operations Series | Part 2 of 6A look inside the six AWS security services that power the Defend pillar of the InfusionPoints Continuous Trust…
Read full blog hereThe case for building your security operations stack on the same infrastructure your customers must authorize against.This is Part 1 of the AWS-Native Security Operations…
Read full blog hereRev5 isn't going away overnight. Existing Rev5 certifications remain valid through at least December 31, 2028, and FedRAMP will keep accepting new Rev5 applications until June…
Read full blog hereFedRAMP 20x is no longer the experimental track. Under CR26, it's the primary path FedRAMP wants every new CSP to take, and the direction it wants existing Rev5 providers to…
Read full blog hereHow VDR, VER, CR26, and CISA guidance are reshaping vulnerability management into a continuous operating model for federal cloud trust. For years, vulnerability management in…
Read full blog hereWhat continuous defense actually looks like when it's built into operations not bolted on beside them. Updated based on FedRAMP CR26.There's a version of security that looks…
Read full blog hereOur full post on CR26 release is coming shortly, but here is a teaser!What's New vs. the Earlier VDR/VER Process Documents
Read full blog hereThe agency name matters less than the data, and the data moves through a system.
Read full blog herePurpose-Driven Security. Built to Last.At InfusionPoints, purpose isn't a tagline. It's an operating model.Most cybersecurity companies are built to be acquired.They raise…
Read full blog hereThe Department of Defense (DoD) faces increasing pressure to modernize mission systems while maintaining strict compliance with the Department of Defense’s Cloud Computing…
Read full blog hereIn 2020, a major software vendor passed its annual security compliance audit with no significant findings. Weeks later, threat actors were discovered to have maintained…
Read full blog hereDoW and FedRAMP are both pushing authorization toward greater speed, reuse, and continuous validation, whether through SWFT, cATO maturity, or FedRAMP 20x’s evidence-first…
Read full blog hereFedRAMP just released a new batch of Requests for Comment (RFCs), and while not every update is major on its own, together they point to a clear direction:CSPs need to review…
Read full blog hereFor a bit over a decade, the “FedRAMP world” and “DoD authorization world” have felt like parallel universes. One prioritized government-wide reuse of cloud authorizations; the…
Read full blog hereAs FedRAMP modernization accelerates under FedRAMP 20x, the Program Management Office (PMO) has introduced a new communication channel: FedRAMP Public Notices.These notices…
Read full blog hereCloud service providers supporting federal customers have grown accustomed to the steady—if not always smooth—pace of FedRAMP requirements. But in 2026, the landscape is…
Read full blog hereIn January, FedRAMP released six interrelated Requests for Comment (RFCs) at once. This unusually large update signals a major shift in how cloud security authorizations will…
Read full blog hereWhen FedRAMP 20X was first introduced, one thing was immediately clear: this wasn’t just another incremental update to the authorization process. It was a fundamental shift in…
Read full blog hereIntroductionOn November 10, 2025, the Cybersecurity Maturity Model Certification (CMMC) officially went live. For defense contractors, this is more than a policy update—it’s a…
Read full blog hereDefining an External Service ProviderIn pursuit of CMMC Certification, External Service Providers (ESPs) are third parties that provide services that affect DoD-controlled…
Read full blog hereThe Shift from Restriction to ProtectionFor years, cloud service providers (CSPs) endured lengthy compliance efforts that slowed innovation. Audits shackled engineering.…
Read full blog hereOn November 18, 2025, the FedRAMP Program Management Office (PMO) published a blog detailing key updates to FedRAMP Revision 5 documentation, signaling the tran
Read full blog hereThe federal landscape is shifting again—and this time, the clock is ticking much faster than most Cloud Service Providers realize. FedRAMP Rev 5 introduces a ne
Read full blog hereIntroduction With the ever-growing global security landscape, security authorization programs such as FedRAMP and IRAP have become increasingly more important,
Read full blog hereTL;DR : I used to approach new tools (think Jenkins) with fixed expectations—only to discover they are often open frameworks that still have to be shaped approp
Read full blog hereFedRAMP 20x
Read full blog hereThe Paradox of Building in an Age That Moves Too FastWe live in a moment that feels like history in real time.AI, automation, and instant information have made speed the…
Read full blog hereWhy Innovation, Not Infrastructure, Is the Only True DefenseFor over a thousand years, the walls and moats of Constantinople stood as the ultimate defense.No army could breach…
Read full blog hereIn government cybersecurity, compliance has become the floor, but readiness is the goal. Too often, agencies and cloud providers conflate the two, mistaking checklists and…
Read full blog hereAs organizations modernize their security architectures, identity has become the critical control point for verifying trust, enforcing access, and reducing risk across digital…
Read full blog hereThe old model of static compliance and perimeter-based trust no longer suffices. In its place, we must evolve toward continuous, evidence-driven verification of trust across…
Read full blog hereThe federal government has taken another decisive step toward modernizing cloud authorization with the launch of FedRAMP 20X Phase Two. This initiative builds on the lessons of…
Read full blog hereWOW! If you haven’t heard, FedRAMP released a new Vulnerability Detection and Response (VDR) standard on September 11, 2025. This new standard is poised to really change the…
Read full blog hereThe Overlooked Role in Federal CybersecurityCybersecurity in the federal government often gets framed around tools: firewalls, encryption, cloud platforms, and threat detection…
Read full blog hereThe days of static SSPs, screenshot-based audits, and year-long ATO cycles are numbered. FedRAMP 20X is changing the game, trading PDFs for real-time dashboards, replacing…
Read full blog hereOn July 4th, 1776, a handful of bold visionaries put pen to parchment and declared that the old way of doing business no longer served a new nation’s needs. Today, FedRAMP 20X…
Read full blog hereHow InfusionPoints Helps Cloud Service Providers Accelerate and Sustain Federal Compliance
Read full blog hereThe recent FedRAMP 20x Community Working Group meeting brought together early adopters and innovators to reflect on lessons learned and progress made during the pilot. Among…
Read full blog hereIn the age of FedRAMP 20x, the old ways of proving compliance- manual screenshots, inconsistent documentation, point-in-time audits- are no longer enough. Agencies, assessors,…
Read full blog hereIn today’s rapidly evolving threat landscape, enterprise hardware must do more than deliver performance—it must protect it. Our team at InfusionPoints recently completed an…
Read full blog hereAt InfusionPoints, we’ve always believed that compliance shouldn't be a one-time event—it should be a continuous, actionable process. That belief is what drove us to develop…
Read full blog hereBuild, Buy, or Rent? The FedRAMP or DoD Platform Dilemma in 2025Why Platform-as-a-Service is the Prerequisite for Mission Outcomes in the Federal MarketsIn the federal and DoD…
Read full blog hereStaying True to the Mission in a Rapidly Evolving Compliance WorldEvery day in 2025 feels like a sprint. For those of us running FedRAMP platforms on AWS—especially those…
Read full blog hereAt InfusionPoints, we are deeply aligned with the transformative goals outlined in FedRAMP 20x—a bold modernization initiative designed to bring federal cloud security…
Read full blog hereDelivering on the Promise of FedRAMP 20x and DoD SWFT with InfusionPoints’ Build | Manage | Defend Framework At InfusionPoints, our mission has always been bigger than just…
Read full blog hereAt the recent FedRAMP 20x event in DC, Pete Waterman, Director of the FedRAMP Program Management Office (PMO), delivered a landmark address outlining a bold, transparent, and…
Read full blog hereYour Guide to FedRAMP Diagrams2025 Major Update:
Read full blog hereThe Spartan Shield: A Symbol of Strength and ProtectionIn ancient Greece, the Spartan warriors were known for their discipline, resilience, and unmatched ability to defend…
Read full blog hereLong before the Government Efficiency program began transforming the way federal agencies operate, InfusionPoints embraced a philosophy of efficiency, innovation, and…
Read full blog hereEver feel like FedRAMP is a never-ending maze? Like no matter how hard you push, there’s always another obstacle? That’s because FedRAMP pushes back—it’s called "compensative…
Read full blog hereEmbracing change and innovation in cloud systems with system thinking Why don’t people want to try something new? Change can be scary, overwhelming, and intimidating.…
Read full blog hereCollaboration and innovation were at the forefront of our experience at AWS re:Invent 2024. For InfusionPoints, it was a chance to reaffirm our commitment to AWS as our cloud…
Read full blog hereUpdate March 7, 2025:Since my original post, the authorizations continue to come in at a sustained rate adding another 10 authorizations since February 12th. This is great news…
Read full blog hereFedRAMP’s draft Boundary Policy introduces a targeted approach to defining, managing, and assessing authorization boundaries for cloud service offerings. By focusing on…
Read full blog hereAmazon Web Services (AWS) recently launched its Security Incident Response service, designed to help organizations prepare for, respond to, and recover from security events.…
Read full blog hereFedRAMP (Federal Risk and Authorization Management Program) compliance is a critical step for companies providing cloud services to U.S. federal agencies. It ensures your…
Read full blog hereIf you’ve worked with services in AWS GovCloud, you know about the unique challenges that come with it. Not every AWS service is authorized in GovCloud, which reduces your…
Read full blog hereIntroductionAchieving and maintaining FedRAMP compliance is crucial for Cloud Service Providers (CSPs) seeking to serve federal agencies. A key component of maintaining…
Read full blog hereIntroductionCreating a comprehensive inventory for FedRAMP compliance is a significant undertaking. The inventory plays a crucial role in the Plan of Action and Milestones…
Read full blog hereWelcome to another episode of FedRAMP in five – where we discuss all things FedRAMP in about five minutes. I'm Jason Shropshire and joining in with me is Ryan Adcock. Today,…
Read full blog hereWhere do I even begin? The last 10 weeks as an intern with InfusionPoints have been an absolute whirlwind. As an enrolled computer information systems senior at the University…
Read full blog hereThe internship experience at InfusionPoints has been an amazing experience filled with lots of learning opportunities, amazing people and new connections. Throughout my 10…
Read full blog hereFor the past ten weeks, I have worked alongside industry professionals at InfusionPoints in a dynamic remote environment. This experience has allowed me to find my niche and…
Read full blog hereWelcome back to "FedRAMP in Five," where we talk about all things FedRAMP in about 5 minutes. In our latest episode, Jackson Gorman and I delve into a topic that's capturing…
Read full blog hereUpdate 8/8/2024 - For more info on Phishing Resistant MFA, checkout our latest FedRAMP in 5 episode.
Read full blog hereDISA Releases Rev 5 Cloud Computing Security Requirements GuideUpdated August 18, 2024: Latest DoD SSP Addendum Insights for IL4/5/6. See the impact in 'What Changed?' below.
Read full blog hereIn today's digital landscape, cloud solutions have become the cornerstone of modern businesses, especially within government sectors. The Federal Risk and Authorization…
Read full blog hereNote: This is episode 5 of a five-part series on the Future of FedRAMP. See the links below for other episodes.
Read full blog hereNote: This is episode 4 of a five-part series on the Future of FedRAMP. See the links below for other episodes.
Read full blog hereToday, we're going to delve into some recent and significant developments within the FedRAMP space.Background: FedRAMP Authorization Act
Read full blog hereWhat is M-21-31?M-21-31, Improving the Federal Government’s Investigative and Remediation Capabilities Related to Cybersecurity Incidents, is a memorandum published by the US…
Read full blog hereNote: This is episode 3 of a five-part series on the Future of FedRAMP. See the links below for other episodes.
Read full blog hereNote: This is episode 2 of a five-part series on the Future of FedRAMP. See the links below for other episodes.
Read full blog hereNote: This is episode 1 of a five-part series on the Future of FedRAMP. See the links below for other episodes.
Read full blog hereTake Command of your Cloud ComplianceIntroduction:Cloud Service Providers (CSPs) targeting cloud compliance face daunting challenges, from grasping Continuous Monitoring…
Read full blog hereOverview of InfusionPoints XccelerATOr Cyber Security Framework Multi-account Strategy based on Defense in depth, Least Privilege and least Functionality Concept. Built to meet…
Read full blog hereCISA has released the SSDF Attestation Form on March 11 and Publishes the Repository for Software Attestation and Artifacts on March 18.In Effort to Bolster Government…
Read full blog hereFedRAMP’s transition to NIST 800-53 Revision 5 marks a major shift in the federal cloud landscape, bringing in a new era of security and compliance for Cloud Service Providers…
Read full blog hereYears ago, the DoD introduced the concept of FedRAMP Equivalency in DFARS 7012, but the term was left open to interpretation. With CMMC rulemaking imminent, DoD released a memo…
Read full blog hereThe cybersecurity landscape has been rapidly evolving over the past few years, and organizations are facing many new challenges as a result. One of the most significant…
Read full blog hereSoftware bills of materials (SBOMs) are one of the hottest topics in cybersecurity. An SBOM contains information about all of the software components of a computing product or…
Read full blog hereThe BasicsOn May 12, 2021, the Executive Branch of the Federal Government issued Executive Order (EO) 14028 in an attempt to improve the nation’s overall cybersecurity. Section…
Read full blog hereGenerating and Safeguarding Artifacts for SSDF AttestationFederal agencies are increasingly requiring CSPs to follow the practices in the NIST Secure Software Development…
Read full blog hereIn the intricate fabric of our nation’s cyber defenses, safeguarding sensitive government data has become a critical imperative. As federal agencies grapple with the…
Read full blog hereWhat an electrifying experience at re:Invent 2023 where the InfusionPoints crew and I navigated the landscape of innovation, inspiration, and after-hours excitement. The…
Read full blog hereA Crisis Level Threat Ransomware has made itself known as one of the most dangerous and prevalent cyberthreats for the new decade. As society becomes more and more dependent on…
Read full blog hereXBU40 is a fully managed and compliant Platform-as-a-Service (PaaS) hosted on Amazon Web Services (AWS) GovCloud and built using InfusionPoints’ XccelerATOr Cybersecurity…
Read full blog hereBreaking Analysis: How HPE is Leading the Industry in Supply Chain Security The state of the supply chain and the ability of the United States to secure it is being tested like…
Read full blog hereThe recent update to the FedRAMP baselines, aligning them with the NIST SP 800-53 Rev. 5 Catalog of Security and Privacy Controls, has transformed the federal cloud landscape.…
Read full blog hereOn May 30, 2023, the FedRAMP PMO released the long awaited FedRAMP baselines for FedRAMP High, Moderate, Low, and Li-SaaS based on NIST 800-53 rev5. Now, it's time for cloud…
Read full blog hereIntroduction We live in a world where new technological strides are made every day. It can be difficult to keep up with these rapidly evolving technologies, especially when…
Read full blog hereIntroduction Passwords have been an integral part of our digital lives for many years, providing a layer of security for our online accounts and sensitive information. However,…
Read full blog hereIntroduction It is a challenging task staying up to date in the ever evolving realm of cybersecurity compliance. There is a sea of documentation that needs to b
Read full blog hereIntroduction Cybersecurity has become one of the fastest-growing fields in the world due to our ever-increasing reliance on technology. With the rapid expansion of digital…
Read full blog hereIntroduction Why did the encryption algorithm go to see the doctor? Because it had a bad case of ciphertext! Jokes aside, we are living in an ever increasingly digitized world…
Read full blog hereIntroduction SCRM, or Supply Chain Risk Management, has become a crucial aspect of modern cybersecurity, particularly as organizations rely on complex supply chains to deliver…
Read full blog hereFedRAMP Signed into Law, So What? The Federal Risk and Authorization Management Program, better known as FedRAMP, is a government-wide program that provides a standardized…
Read full blog hereFive common challenges of FedRAMP Continuous Monitoring Understanding FedRAMP ConMon Requirements Cross-
Read full blog hereImplementing Zero Trust Architecture for FedRAMP Solutions As Government data and resources are distributed across multiple clouds and on-premises environments, protecting them…
Read full blog hereMaximizing the Potential of Your Small Business Innovation: How FedRAMP Can Help SBIR Grant Recipient Companies Read Time: Approximately 2.5 minutes.
Read full blog hereInfusionPoints’ XccelerATOr uses a dedicated AWS account, labelled “Transit”, as a boundary cloud access point (BCAP).
Read full blog hereAmazon Web Services offers many useful tools to achieve FedRAMP compliance. Amazon WorkSpaces is just one of them. Used to complete day-to-day business tasks from a cloud…
Read full blog hereHow does InfusionPoints define ‘consulting’? Consulting, and what it is, can be confusing. There are two main models: staff-augmentation, project-based, or advisory consulting.…
Read full blog hereIntelligence Diversification Why your organization should use a wide range of threat and vulnerability intelligence tools As our dependence on technology continues to grow, so…
Read full blog hereLet's Get Started! Visit Our Contact Page to Meet Your New Cybersecurity & Compliance Partner! Contact us
Read full blog hereFedRAMP Revision 5 Preparation Strategically plan for the upcoming baseline shift Are you a Cloud Service Provider (CSP’s) considering FedRAMP authorization or an authorized…
Read full blog hereDeep Dive into the new Supply Chain Risk Management Family in FedRAMP Revision 5 The FedRAMP Program Management Office (PMO) has released new proposed baselines based on NIST…
Read full blog hereDeep Dive into Changes to the Security Assessment and Authorization Family in FedRAMP Revision 5 The FedRAMP Program Management Office (PMO) has released new proposed baselines…
Read full blog hereDeep Dive into Changes to the System and Information Integrity Family in FedRAMP Revision 5 The FedRAMP Program Management Office (PMO) has released new proposed baselines…
Read full blog hereDeep Dive into Changes to the Physical and Environmental Protection Family in FedRAMP Revision 5 The FedRAMP Program Management Office (PMO) has released new proposed baselines…
Read full blog hereDeep Dive into Changes to the Configuration Management Family in FedRAMP Revision 5 The FedRAMP Program Management Office (PMO) has released new proposed baselines based on…
Read full blog hereDeep Dive into Changes to the Planning Family in FedRAMP Revision 5 The FedRAMP Program Management Office (PMO) has released new proposed baselines based on NIST Special…
Read full blog hereDeep Dive into Changes to the Contingency Planning Family in FedRAMP Revision 5 The FedRAMP Program Management Office (PMO) has released new proposed baselines based on NIST…
Read full blog hereDeep Dive into Changes to the Personnel Security Family in FedRAMP Revision 5 The FedRAMP Program Management Office (PMO) has released new proposed baselines based on NIST…
Read full blog hereDeep Dive into Changes to the Identification and Authentication Family in FedRAMP Revision 5 The FedRAMP Program Management Office (PMO) has released new proposed baselines…
Read full blog hereDeep Dive into Changes to the Access Control Family in FedRAMP Revision 5 The FedRAMP Program Management Office (PMO) has released new proposed baselines based on NIST Special…
Read full blog hereDeep Dive into Changes to the Risk Assessment Family in FedRAMP Revision 5 The FedRAMP Program Management Office (PMO) has released new proposed baselines based on NIST Special…
Read full blog hereDeep Dive into Changes to the Incident Response Family in FedRAMP Revision 5 The FedRAMP Program Management Office (PMO) has released new proposed baselines based on NIST…
Read full blog hereDeep Dive into Changes to the Awareness and Training Family in FedRAMP Revision 5 The FedRAMP Program Management Office (PMO) has released new proposed baselines based on NIST…
Read full blog hereDeep Dive into Changes to the System and Services Acquisition Family in FedRAMP Revision 5 The FedRAMP Program Management Office (PMO) has released new proposed baselines based…
Read full blog hereDeep Dive into Changes to the Maintenance Family in FedRAMP Revision 5 The FedRAMP Program Management Office (PMO) has released new proposed baselines based on NIST Special…
Read full blog hereDeep Dive into Changes to the Audit and Accountability Family in FedRAMP Revision 5 The FedRAMP Program Management Office (PMO) has released new proposed baselines based on…
Read full blog hereDeep Dive into Changes to the System and Communications Protection Family in FedRAMP Revision 5 The FedRAMP Program Management Office (PMO) has released new proposed baselines…
Read full blog hereDeep Dive into Changes to the Media Protection Family in FedRAMP Revision 5 The FedRAMP Program Management Office (PMO) has released new proposed baselines based on NIST…
Read full blog hereFedRAMP Releases Proposed Updated Baselines Following the release of NIST Special Publication 800-53, Security and Privacy Controls for Information Systems and Organizations,…
Read full blog hereThe world of cybersecurity can manifest complex problems, obfuscated puzzles, and skilled bad actors that you will inevitably encounter during your journey within the industry.…
Read full blog hereInfusionPoints' XccelerATOr Infrastructure as code (IAC) leverages a set of detection mechanisms in each account. This base set of mechanisms is aimed at detecting a wide range…
Read full blog hereLet's Get Started! Visit Our Contact Page to Meet Your New Cybersecurity & Compliance Partner! Contact us
Read full blog hereLet's Get Started! Visit Our Contact Page to Meet Your New Cybersecurity & Compliance Partner! Contact us
Read full blog hereYour Guide to FedRAMP Diagrams (UPDATED) What is the purpose of this guidance? The FedRAMP Authorization Boundary guidance provides a roadmap for developing, maintaining, and…
Read full blog hereCheck out our newest FedRAMP in 5 episode!
Read full blog hereInfusionPoints began our advisory work in FedRAMP just when the FedRAMP program was being formed. Our first FedRAMP project was with Dell Services where we helped develop the…
Read full blog hereFedRAMP in 5 Where we talk all things FedRAMP, in about 5 minutes or less. Todays Topic: Staffing and Training. What is InfusionPoints doing about staffing? InfusionPoints does…
Read full blog here“Supply chain attacks are real and here to stay.” This is the lesson learned as we watched a global pandemic, the SolarWinds attack, and Ransomware attacks on critical…
Read full blog hereSupply chain and cyber-attacks are dominating headlines in 2021. The need for assurance of the provenance, security, and trustworthiness of hardware, firmware, and software…
Read full blog hereAs an AWS Advanced Consulting Partner and Public Sector Partner, InfusionPoints makes use of the highly innovative features of the AWS platform to deliver a highly available…
Read full blog hereHere Today, Gone Tomorrow. New IOC Trends
Read full blog hereThe New Interim Rule & What it Means for You The Office of Information and Regulatory Affairs at the Office of Management and Budget have released a new interim rule that…
Read full blog hereBreaking Analysis: How HPE is Leading the Industry in Supply Chain Security The state of the supply chain and the ability of the United States to secure it is being tested like…
Read full blog hereMalicious Coronavirus COVID-19 Link Hackers are taking advantage of fears surrounding the Coronavirus/COVID-19 outbreak by luring people into clicking links that download…
Read full blog hereDatabase Vulnerability Scanning Vulnerability scanning is a very important part of obtaining and keeping a FedRAMP ATO, and generally scanning is a well understood topic.…
Read full blog hereCMMC Overview The purpose of the new Cybersecurity Maturity Model Certification (CMMC) is to measure the level of cybersecurity maturity of prime contractors and their supply…
Read full blog hereEncryption of Data In Transit Recently, the Project Management Office (PMO) has been enforcing a very strict interpretation of what needs to be encrypted in-transit (SC-8).…
Read full blog hereHas the use of the Plan of Actions and Milestones (POA&M) changed based on CMMC? CMMC v1.0 has officially been released as of Friday, January 31, 2020. One topic that has…
Read full blog here8/16/2020 - CMMC Accreditation Body Announced The board members are self-nominated, non-felon US citizens. The Board Chairman will select the Directors, who are then approved…
Read full blog hereWhy Privacy is Important From NIST: Privacy Framework - Privacy is challenging because not only is it an all-encompassing concept that helps to safeguard important values such…
Read full blog hereInfusionPoints is providing this cybersecurity advisory to our customers and contacts as a community service. The Cybersecurity and Infrastructure Security Agency (CISA) within…
Read full blog hereOSCAL and FedRAMP Automated compliance is a constantly evolving topic, especially when it comes to large and complex cloud services. The demand for automated compliance for…
Read full blog hereWhat is it? Prowler is an open source Amazon Web Services (AWS) “Security Best Practices Assessment, Auditing, Hardening, and Forensics Readiness tool” developed by Toni de la…
Read full blog hereA California U.S. district court ruled last week that allegations against Aerojet Rocketdyne could progress following Brian Markus’ complaint that the company terminated his…
Read full blog here“Our entire AWS account is gone. The call center is down, we can’t log in - it’s like it never existed! How do we get it back?” A multimillion-dollar services provider…
Read full blog hereAs some things from our childhood, things aren’t always as they appear. With what we thought was a vigilante that stole from the rich to give to the poor is now shooting arrows…
Read full blog hereAn Intro To Email Bombs You’re working quietly at your desk and suddenly start getting emails. Lots, and lots, and lots of emails! You easily received 40-50 emails in just one…
Read full blog hereDepartment of Defense (DoD) may seek to outsource it’s supply chain cybersecurity audits by allowing organizations to verify DFARS 7012/NIST SP 800-171 compliance. During a…
Read full blog hereWhen the countdown has finalized and its now time to become DFARS compliant, who do you turn to?
Read full blog hereRight on Schedule, on November 6th, 2018, DoD’s Acting Principal Director for Defense Pricing and Contracting (DPC) issued a memorandum titled, “Guidance for Assessing…
Read full blog hereOn October 18, 2018, the National Institutes for Standards and Technology (NIST) hosted a day-long workshop that featured experts from across the government brought in to…
Read full blog hereAt InfusionPoints, we have just gone through the onsite portion of our audit for ISO 27001 and SOC 2, and should have those certifications along with our ISO 9001:2015…
Read full blog hereRunning is a passion for us...and InfusionPoints sees the benefit too! Great benefits…check. Work-life balance…check. Excellent coworkers to work alongside…double check.…
Read full blog hereOn August 30th, the FedRAMP PMO dropped a new round of changes that they had warned about since the updated boundary guidance came out in May. These changes included updates to…
Read full blog hereMITRE Corporation recently released a report recommending significant changes to cybersecurity for the DoD supply chain, including changes in the role of cybersecurity in the…
Read full blog hereThis is Part 2 of a 2-part InfusionPoints’ Series based on MITRE’s report that recommended critical changes to the Department of Defense’s (DoD) strategic approach to supply…
Read full blog hereOn August 30th, the FedRAMP PMO dropped a new round of changes that they had warned about since the updated boundary guidance came out in May. These changes included updates to…
Read full blog hereYesterday, the FedRAMP PMO dropped a new round of changes that they had warned about since the updated boundary guidance came out in May. These changes included updates to the…
Read full blog hereDFARS/NIST compliance is hard We are hearing more and more from our customers every day that they are being required to attest to their DFARS compliance status and all…
Read full blog hereOn April 24, 2018, the Department of Defense (DoD) issued a Notice and Request for Comment on draft guidance for procurements that require contractors to meet security…
Read full blog hereWho is allowed to work on the system or access SSP documentation? Note: This is part 4 of a multi-part series. See the links below for other topics in the series. Today we will…
Read full blog hereNote: This is part 3 of a multi-part series. See the links below for other topics in the series. Today we will address questions around handling and classification of the…
Read full blog hereIn part 1 of this series, we addressed the question “Is an NDA with FedRAMP needed to protect my company’s trade secrets?” In today’s topic we address the question “If I follow…
Read full blog hereWhile providing FedRAMP consulting for our customers, we’ve have had to address a variety of questions that have come to us varying from the strategic to specific questions on…
Read full blog hereThe scope of ransomware victims continues to rapidly expand beyond individual consumers and into business and Government organizations. This was recently evidenced in early…
Read full blog hereWe talk with many organizations every day, and the most common issue we see in cyber security today is culture, even though we see the threats everywhere in the news, on TV, in…
Read full blog hereA new wireless vulnerability affecting WPA2 protected wireless networks was published by security researchers on Monday as first reported by ArsTechnica.
Read full blog hereI was talking to my colleague, Nicole White, the other day about the need for DoD contractors to implement NIST 800-171 controls before the end of 2017 to comply with DFARS…
Read full blog hereIt’s hard to believe Plan B has turned into ten of the best years of my life. Who said starting a business in the middle of the great recession was a bad idea? Through the…
Read full blog hereI am not a fear monger. I don’t try to use Fear, Uncertainty, and Doubt to influence people. Regardless, today, I am writing to raise up warning flags. If you sell products or…
Read full blog hereIf you have been in IT or Security Operations long enough, you’ve come across that environment or product that you have to deal with on a day-to-day basis that has you pulling…
Read full blog hereSecurity becomes an adversary to your organization when it hinders the operation of key business functions. And the smooth operation of revenue-producing business processes…
Read full blog hereFor covered contractor information systems that are not part of an IT service or system operated on behalf of the Government . . . the following security requirements apply:
Read full blog hereGoogling around for a solution to this one and you'll find many. Over time these have changed based on the boot code and FTOS version so many will no longer work. We ran into…
Read full blog hereThere are two types of Small to Midsize Businesses (SMB) in today’s world: those who know they have been breached, and those who do not. The difference between these types of…
Read full blog hereIf you are connected to the internet, you are under attack right now…Are you monitoring or watching your IT ecosystem, if you are not how would you know? Most small to midsize…
Read full blog hereAs a small business owner myself, I truly understand the everyday challenges we face, Payroll, Human Resources, Service Delivery, New Business, Equipment Maintenance… Cyber…
Read full blog hereFor several decades now, business have been transformed by technology. However, small to midsize businesses (SMB) were at a disadvantage competing against a bevy of larger,…
Read full blog hereRural telecommunications organizations are moving fast to deliver high-quality and reliable communications services, as well as provide additional services such as video on…
Read full blog hereTraditionally, an organization’s systems were developed, acquired and deployed inside of the corporate security boundaries for use by employees, partners and contractors in an…
Read full blog hereIn the opening of part 3 of the Washington Post series “Net of Insecurity”, WaPo posits that L0pht warned congress early on in 1998 of the inherent security flaws of the…
Read full blog hereNote: This post is about an ongoing issue and is based on available information. Updates will be amended, and corrections made as new information becomes available.
Read full blog hereA Rogue Access Point is an unauthorized wireless device that acts as a gateway to your internal network. They are typically attached to an open network port in an empty office…
Read full blog hereI was recently interviewed for an upcoming article, and thought the questions and answers would make for a good blog post. Interview on Identity Management Services in the…
Read full blog here