May 27, 2026
CISM vs CISSP: Which Certification Fits Your Career Path?
Comparing CISM and CISSP to help IT and security professionals choose the right certification for their career goals in 2026.
Read ArticleMay 27, 2026
Comparing CISM and CISSP to help IT and security professionals choose the right certification for their career goals in 2026.
Read ArticleMay 26, 2026
Ten real-world email scenarios, one question each: legitimate or phishing? See how well you and your team spot the attacks behind most breaches.
Read ArticleMay 26, 2026
IT Dojo's free Job Match Tool shows which certifications hiring managers want for your target role, based on real job postings, not guesswork.
Read ArticleMay 26, 2026
IT Dojo's free Exam Study Plan Generator builds a personalized, week-by-week study schedule for 20 IT certifications based on your exam date and hours.
Read ArticleMay 17, 2026
The DoD 8140 compliance deadlines have arrived. Here is a practical step-by-step guide to identifying your DCWF work role and choosing the right certifications …
Read ArticleMay 16, 2026
CISSP and CISM both satisfy DoD 8140 IAM Level II and III requirements, but they are built for different roles. Here is how to choose the right one for your …
Read ArticleMay 15, 2026
A complete guide to the CompTIA certification pathway for DoD and federal IT professionals, from Network+ through SecurityX, with DoD 8140 mapping and guidance …
Read ArticleMay 11, 2026
Confused about the DoD 8570 to 8140 transition? Learn what changed, which certifications are required, and how to stay compliant in your federal IT role.
Read ArticleFebruary 23, 2026
The landscape of cyber threats targeting the Department of Defense (DoD) is constantly evolving, demanding a paradigm shift in how we secure critical…
Read ArticleApril 17, 2024
In the realm of cybersecurity, adherence to rigorous standards and best practices is paramount to safeguarding sensitive information and maintaining the…
Read ArticleApril 17, 2024
In an era of ever-evolving cyber threats, traditional security models are proving to be inadequate in safeguarding sensitive data and systems.
Read ArticleApril 17, 2024
In an era marked by evolving cyber threats and stringent security requirements, the Department of Defense (DoD) plays a pivotal role in safeguarding…
Read ArticleMay 25, 2021
Recently our regional grocery store chain notified their employees and customers that they had a data breach involving some HR data and pharmacy records.
Read ArticleNovember 12, 2019
Just when folks were beginning to get somewhat comfortable … or, at least, familiar … with the Risk Management Framework (RMF), along come our friends at…
Read ArticleApril 15, 2019
CNSSI 4009 defines Security Control Inheritance as “a situation in which an information system or application receives protection from security controls (or…
Read ArticleApril 5, 2019
"How much information is in a message?" Huh??? That sentence, in the context of typical use of those words (information & message), doesn't immediately make…
Read ArticleJuly 13, 2017
This article was written by Lon Berman, CISSP, RDRP of BAI Information Security Step 6 of the Risk Management Framework (RMF) is entitled “Monitor Security…
Read ArticleFebruary 24, 2017
We knew this day was coming. On a long enough timeline, the survival rate for every algorithm drops to zero. Yes, I'm paraphrasing Tyler Durden.
Read ArticleJanuary 24, 2017
My time in the IT world is closer to three decades than two. And anyone else who has been around half as long can testify to the amount of change that has…
Read ArticleSeptember 16, 2016
In this issue we will shine the spotlight on the Contingency Planning (CP) family of security controls.
Read ArticleJune 7, 2016
Let’s take a look at some strategies for reviewing the Security Control Baseline and creating “action plans” for implementation.
Read ArticleJune 1, 2016
Security Control Inheritance is one of the most powerful tools available to facilitate the RMF process.
Read ArticleApril 27, 2016
Apple uses a variety of scans for wireless LAN/physical location information. There are Preferred Network Offload (PNO) Scans, Enhanced Preferred Network…
Read ArticleMarch 11, 2016
I recently had a client who had a Security+ certification that was about to expire and he asked me a question that I wanted to share with our readers.
Read ArticleFebruary 18, 2016
With all the renewed furor over the government attempting to force Apple to backdoor iOS devices so the FBI can inspect the phone of the San Bernardino…
Read ArticleJanuary 19, 2016
In this post Colin explores password entropy and what it means in terms of password strength.
Read ArticleNovember 23, 2015
Imagine this dialog between Edward, a System Owner, and Christine, his Information System Security Manager (ISSM): Edward (System Owner):“Now that we’ve…
Read ArticleNovember 16, 2015
I just finished reading Bruce Schneier’s blog entry, titled "The Doxing Trend". Let me start by writing that I am usually a big fan of Mr. Schneier.
Read ArticleJuly 15, 2015
Many information security incidents are newsworthy, especially when they involve compromise of personal, financial and/or medical information.
Read ArticleMarch 13, 2015
The Beatles were comprised of how many musicians? Easy, right? They were called the “Fab Four”, so there were definitely 4.
Read ArticleFebruary 1, 2015
In this post Colin walks you through getting Nvidia CUDA support enabled on your OS X device and illustrates the basics of how to use it with pyrit and cpyrit.
Read ArticleJanuary 27, 2015
No longer just a technical issue, instead a strategic program to manage cybersecurity risk. Targeted cyber attacks are a strategic organizational problem.
Read ArticleNovember 13, 2014
In this issue’s “Spotlight”, we’re not going to focus on any specific controls or families, but rather on a comparison of RMF controls and DIACAP controls.
Read ArticleJuly 21, 2014
Under RMF, NIST SP 800-53 is the primary source for security controls. If we compare these controls to the DoDI 8500.2 IA controls used in DIACAP, several…
Read ArticleMay 9, 2014
We are getting excited about our upcoming Offensive Wifi and Mitigation Techniques class. Gear has started to arrive!
Read ArticleApril 16, 2014
A deadline for federal agencies to adhere to the government’s baseline cloud security standards and changes to the standards themselves are coming up very…
Read ArticleApril 7, 2014
by Annette Leonard BAI Consulting Continuous Monitoring has long been recognized as a critical element in maintaining a strong security posture for any IT…
Read ArticleOctober 2, 2012
In this post Colin discusses issues the Path MTU discovery (PMTUD) and its implications on networking with IPv6.
Read ArticleDecember 30, 2011
The effectiveness of Security through Obscurity is closely related to the knowledge (or lack thereof) of the attacker.
Read ArticleMay 20, 2011
I wrote this post several years ago. By writing it I was trying to get people to begin to think about how the size of the IPv6 address space, when combined…
Read ArticleMay 9, 2011
Exploring the practical feasibility of ping sweeping IPv6 networks. Includes a spreadsheet for determining how long it will take to sweep your own network.
Read Article