38North Security
The 38North Security Podcast
Join us as we discuss news and current events, trends, and controversies in the world of cybersecurity. We have strong feelings and they're not limited to FedRAMP, CMMC, FISMA, IRAP, security engineering, or documentation. Anything goes -- some of the things we say are probably even helpful! Interested in having words? Email us at info@38northsecurity.com.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
FedRAMP 20x Is Here: The Six Changes That Matter Most 02.07.2026 0:07
With FedRAMP's Consolidated Rules for 2026 being final, FedRAMP 20x is officially here. That changes how cloud service providers enter FedRAMP, define scope, prove security, maintain certification, and work with federal agencies. In this episode, Ingrid Velasquez-Woodley speaks with Sam Leestma, Vice President of Solutions Engineering, and Spence Witten, Principal Consultant at 38North Security,...
GovRAMP: Navigating the Path to Authorization 28.05.2025 10:52
Welcome to Part 3, the final episode of our GovRAMP Mini-Series . Over the last two episodes, we’ve covered what GovRAMP is and why companies are pursuing it. Today, we’re closing things out by getting tactical—what does the GovRAMP process actually look like from start to finish? To walk us through it, we’re joined by Matt Strasburg, manager of our Cloud Security Advisory practice. Matt has guide...
GovRAMP: Why It’s a Smart Growth Move for Cloud Providers 16.05.2025 7:37
This is Part 2 of the GovRAMP Mini-Series . In this episode, we’re digging into the big question: Why would a cloud provider pursue GovRAMP in the first place? We’re joined by Jeremiah Thompson , 38North Security's VP of IT and Cloud Solutions. We also have Matt Strasburg , Manager of our Cloud Security Advisory practice. Jeremiah’s been in the compliance world for years and brings a pragmatic,...
GovRAMP: What Is It, Anyway? 14.05.2025 6:09
Welcome to Part 1 of our GovRAMP Mini-Series —a quick, focused look at what GovRAMP is, why it matters, and how cloud service providers can use it to unlock the public sector. In this episode, we tackle the basics: What exactly is GovRAMP? Why the rebrand from StateRAMP? And is this more than just a name change? Elizabeth Lopez helps us break it down. Liz, one of our cloud security technical wri...
FedRAMP: Goodbye FedRAMP JAB! Hello TAG, Board, and FSCAC! 10.06.2024 32:06
FedRAMP just came out with *three* new bodies governing the program going forward: the TAG, the Board, and the FSCAC. There's a lot of uncertainty right now, not to mention confusion and misinformation. Why are these changes happening? What does it mean for CSPs, 3PAOs, and agencies? Is the JAB gone?!! Matt Strasburg and Jeremiah Thompson shed light on these massive changes and discuss their wide-...
Refresher: What's in The FedRAMP Modernization Memo? 30.01.2024 24:58
We're about to see significant changes in the way FedRAMP is managed: automation, more pathways to authorization, and no more JAB. It's all in the name of modernization, baby! Well, that and the undeniable fact that the process to get more offerings in the FedRAMP marketplace needs to be much, much faster. But what does it all mean? How will it affect CSPs' efforts to get ATO? Matt Strasburg answe...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.