Blog
IT Dojo blog: expert insights on cybersecurity, RMF, DoD compliance, certifications, networking, and federal IT. Updated regularly by our instructors.
January 24, 2017
In the World I See…
My time in the IT world is closer to three decades than two. And anyone else who has been around half as long can testify to the amount of change that has…
Read ArticleJanuary 13, 2017
Certification Suckers
Who benefits the most when you get certified? You? Or is it the vendor?
Read ArticleSeptember 16, 2016
Security Control Spotlight: Contingency Planning
In this issue we will shine the spotlight on the Contingency Planning (CP) family of security controls.
Read ArticleSeptember 16, 2016
Top Ten RMF Pitfalls Revisited
Like any complex process, RMF is not without its share of potential pitfalls. Now that we have the benefit of some more RMF projects under our belt, we…
Read ArticleSeptember 16, 2016
Understanding the Authorization Decision
Most system owners expect an Authorization to Operate from their RMF efforts. Here is what the AO decision really involves.
Read ArticleJune 8, 2016
Top Ten: RMF “Lessons Learned”
I recently had the pleasure of consulting for a DoD program that successfully navigated the RMF process and received a full three year Authorization to…
Read ArticleJune 7, 2016
Security Control Baseline “Tabletop Review”
Let’s take a look at some strategies for reviewing the Security Control Baseline and creating “action plans” for implementation.
Read ArticleJune 1, 2016
Security Control Spotlight: Inheritance
Security Control Inheritance is one of the most powerful tools available to facilitate the RMF process.
Read ArticleApril 27, 2016
Learning More About Apple iOS9 MAC Address Randomization
Apple uses a variety of scans for wireless LAN/physical location information. There are Preferred Network Offload (PNO) Scans, Enhanced Preferred Network…
Read Article