Bobby Guerra
Climbing Mount CMMC
Our podcast is dedicated to supporting MSPs/MSSPs and the companies that engage with them. We aim to maintain transparency throughout our journey, especially as we pursue our level two certification. While only a few MSPs are actively participating, we hope this podcast will inspire more involvement. We have many guests from different branches of the CMMC ecosystem who are professional in their fields. These guests include Brian Hubbard, Joy Beland, Amira Armond and many more!
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Dr. Ron Ross Shares His Story (From the Army to NIST and Beyond) 28.11.2024 1:00:08
We sat down with Dr. Ron Ross about his story and how he got to where he is today. He shares what his first job was out of the Army and his health battle while writing publications for NIST. His journey is incredibly inspiring, and we feel such gratitude to be able to share this with all of you. To hear about the man behind the publications, was something truly special. Website: https://www.axiom....
The Connection Between NIST SP 800-53 and SP 800-171 21.11.2024 34:20
You can't have NIST SP 800-171 without the 800-53 that came before it. In today's episode, Bobby sat down with FedRAMP expert, Karen Stanford, to discuss the connection between the two publications and how you can use this to your advantage when preparing for an assessment. Many of the 800-171 controls can be traced back to 800-53 and it helps give more clarity to the requirements. We ho...
The Purpose Behind SP 800-172 w/ Dr. Ron Ross 14.11.2024 28:05
Today, Bobby and Kaleigh are joined by Dr. Ron Ross from NIST, an author of SP 800-172 and MUCH MORE. He shares the true purpose behind the document and what the new draft brings to the table. The draft was published on 11/13/24 and public comments are now being accepted until January of 2025. Website: https://www.axiom.tech/ YouTube: https://www.youtube.com/channel/UCaJagoDasNG3MqLqw2Af_ZQ Axiom&...
The Implementation of CMMC (4 Phase Rollout) w/ Vince Scott 07.11.2024 48:00
In this podcast episode, Bobby Guerra, Kaleigh Floyd, and Vince Scott discuss the complexities of the Cybersecurity Maturity Model Certification (CMMC) and its phases. Vince shares his extensive background in cybersecurity, transitioning from offense to defense, and the challenges faced by small businesses in achieving compliance. The conversation delves into the realities of implementing CMMC sta...
How the 32 CFR Rule Affects Vendors 31.10.2024 35:07
In this conversation, Kaleigh Floyd, Bobby Guerra, and Adam Evans discuss the distinctions between Cloud Service Providers (CSPs) and other service providers (ESPs), the significance of Controlled Unclassified Information (CUI), and the importance of vendor assessments in the context of the 32 CFR rule. They delve into the necessary audits, risk management strategies, and the implications of secur...
Let's Talk About FedRAMP (What, Why and How?) 24.10.2024 51:15
Karen and Bobby dive into the complexities of cybersecurity audits, particularly focusing on the distinctions between CMMC and FedRAMP. They discuss operational challenges, the assessment processes, and the importance of recommendations in FedRAMP. The conversation also highlights misconceptions about FedRAMP, the implications of equivalency versus accreditation, and the future of cloud services i...
An MSP's Breakdown of 32 CFR (How does this affect MSPs?) 22.10.2024 44:10
Are you an MSP navigating CMMC? Are you a contractor looking for the right MSP for your climb to CMMC? This episode is going to decipher the 32 CFR final rule with those to perspectives front-of-mind. Bobby and Kaleigh discuss the assessment requirements of an ESP, what inheritance is, and how an MSP can prepare to help their clients in the DIB space. Website: https://www.axiom.tech/ YouTube: http...
Navigating the 32 CFR Final Rule Regulations 17.10.2024 48:38
In this conversation, Bobby Guerra and Kaleigh Floyd discuss the recent release of the 32 CFR Final Rule and its implications for organizations. They explore the importance of self-assessments, the complexities involved, and the distinctions between different types of compliance measures such as enduring exceptions, operational plans, and temporary deficiencies. The conversation also delves into...
The 32 CFR Final Rule is out NOW (Let's chat) 11.10.2024 17:29
32 CFR Final Rule! The time has come. We wanted to hop on a quick video, before Kaleigh hops on a plane, to talk about the 32 CFR FINAL RULE. We may or may not have recorded a 2 hour long podcast this week that we now have to cut…but we are back and ready to review the Final Rule. Phase extensions, SPD definitions, ESP requirements and more! Read it Here: https://public-inspection.federalregister....
Let's Get Real About Resources (What you need on your CMMC Climb) 10.10.2024 44:17
Hello Climbers, let's get real about the resources needed on your climb of CMMC. Bobby and Adam discuss the people, tools, and more that it takes to accomplish CMMC Level 2 compliance. They explore the importance of having knowledgeable personnel, the role of Managed Service Providers (MSPs) and consultants, the challenges in finding certified MSPs, and the technology resources required for c...
Raising Boats and Empowering New Voices in Cybersecurity with Jason Sproesser 03.10.2024 45:09
In this engaging conversation, Jason Sproesser shares his journey into the CMMC space and the evolution of the Sum IT Up podcast. The discussion highlights the importance of community, vulnerability, and authenticity in the cybersecurity field, as well as the challenges faced by MSPs. Jason emphasizes the need for collaboration and the value of sharing experiences to help others navigate the compl...
The Country Song of CMMC (What 32 CFR Did to Us) 26.09.2024 23:26
In this podcast episode, Bobby Guerra and Kaleigh Floyd discuss the challenges and implications of the CMMC (Cybersecurity Maturity Model Certification) ruling. They highlight the impact of the 32 CFR (Code of Federal Regulations) on organizations and vendors who need to meet the level two requirements. They emphasize that many companies were not intentionally misleading or non-compliant, but rath...
5 Things We Learned from Our Gap Assessment 19.09.2024 38:09
Fresh off the press! Bobby and Adam just completed a gap assessment done by a C3PAO and they want to share what they've learned with all of you. Here are the top 5 things that made their assessment so difficult. We hope you enjoy. Website: https://www.axiom.tech/ YouTube: https://www.youtube.com/channel/UCaJagoDasNG3MqLqw2Af_ZQ Axiom's LinkedIn: https://www.linkedin.com/company/axiomtech...
Emergency Episode Drop (32 CFR Review Status) 16.09.2024 37:05
Emergency Podcast Episode 🚨 The 32 CFR Final Rule COMPLETED THE REVIEW PROCESS and things are heating up. We couldn't help but hop on the podcast and share this news and what it means for organizations and MSPs in the community. Website: https://www.axiom.tech/ YouTube: https://www.youtube.com/channel/UCaJagoDasNG3MqLqw2Af_ZQ Axiom's LinkedIn: https://www.linkedin.com/company/axiomtech...
Our Journey to CMMC Compliance 12.09.2024 31:34
Let's get personal. Axiom has been on this CMMC journey for about 3 years now and we'd love to share our experience as an MSP and small business in the industry. In this episode, Bobby and Adam share how they got into this space and their fears and challenges going in. Bobby started Axiom over 20 years ago and the transition to a Level 2 Certified MSP has been challenging to say the leas...
What's On the CMMC Menu? (4 Different Approaches to CMMC) 05.09.2024 37:29
Let's talk about the CMMC Menu items. There are multiple ways that a business can tackle CMMC and we wanted to share with you 4 popular ways. In no way are we claiming these to be the only ways, but we do feel like these are the top four ways we've seen companies climb the mountain. Comment below if you have any questions or ideas on another way to climb. We'd love to hear! Websit...
Navigating the Complex Landscape of CMMC Compliance w/Jacob Hill 29.08.2024 31:55
(Season Two Episode 15) Bobby Guerra is joined by Jacob Hill, VP of cybersecurity at Alamo City Engineering Services and founder of GRC Academy. Jacob discusses the importance of education and training in the defense contractor industry. He shares his experience in implementing CMMC compliance and the challenges he faced in finding comprehensive education resources. Jacob explains the focus of his...
Software Development in the CMMC Ecosystem w/Kyle Lai 22.08.2024 42:23
In this conversation, Bobby is joined by Kyle Lai, President and Chief Information Security Officer at KL3. They discuss the challenges and considerations of CMMC compliance for organizations involved in software development. Kyle emphasizes the importance of selecting a C3PAO (CMMC Third-Party Assessor Organization) that understands the unique requirements of software development and can assess t...
Let's Get Real About Cost of CMMC 15.08.2024 34:07
(Season Two Episode 13) In this episode, Bobby and Kaleigh discuss the Cost in their Let's Get Real Miniseries. They breakdown the cost into three categories: Scoping & Design, Implementation, and Maintenance. They are honest about their personal journey and costs of their CMMC track. Bobby explores Option A, which involves hiring and training internal staff, and Option B, which involves...
Are You Ready for A CMMC Assessment? w/Adam Evans 08.08.2024 37:00
In this conversation, Bobby and Adam discuss the importance of being ready for an assessment and share their experiences with self-assessment. They highlight the need to have solid evidence and be able to demonstrate compliance with the controls and assessment objectives. They also emphasize the interconnectedness of controls and the importance of having evidence that covers multiple controls. The...
5 Questions to Ask Your MSP to Gauge Their CMMC Readiness 01.08.2024 22:46
If you're planning to get certified in the next two years and work with an MSP, you should ask them these questions. If you're an MSP/ESP providing services to companies aiming for certification, you should be prepared to answer these questions. It takes a company eight months to a year to become CMMC ready. Through this pointed and hard-hitting podcast episode, we aim to educate and cha...
Things You Should Prepare for BEFORE Your Assessment w/Amira Armond 25.07.2024 38:57
(Season 2 Episode 10) Bobby Guerra and Amira Armond discuss various cybersecurity challenges and solutions. They emphasize the need for strong physical defenses, proper training, and encryption when dealing with external media. They also highlight the importance of securing contractor-managed assets and implementing security measures across the entire network. It is critical for organizations to...
Let's Get Real (Miniseries) 18.07.2024 23:00
(Season 2 Episode 9) Alright Climbers, let's get real. We are ready to share our truth and honest opinions of our CMMC journey. Bobby and Kaleigh will be specifically breaking down the cost, resource, impact, and time. If you're interest in our journey and the things that we've learned along the way, make sure to tune in to this miniseries Website: https://www.axiom.tech/ YouTube: h...
The Importance of Education and Gap Assessments in the CMMC Space w/Koren Wise 11.07.2024 59:51
(Season 2 Episode 8) Koren Marie Wise, CEO of Wise Technical Innovations, and Bobby Guerra emphasize the importance of having a skilled and knowledgeable team, conducting thorough gap assessments, and understanding the flow of Controlled Unclassified Information (CUI). Koren also highlights the need for proper scoping, accurate network diagrams, and the right skill sets to ensure compliance with t...
Can MSPs Participate in Joint Surveillance Assessments? 04.07.2024 34:27
In this conversation, Bobby Guerra, Adam Evans and Brian Hubbard discuss the challenges faced by MSPs in meeting compliance requirements, particularly in relation to the CMMC. They explore the concept of Joint Surveillance Voluntary Assessments (JSVAs) and the benefits they offer in terms of getting a jumpstart on certification. They also discuss the importance of MSPs staying engaged with the Def...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.