-

Avoid Pitfalls in CMMC Compliance
KLC Consulting’s Powerpoint Presentation at the 03/26/2021 ISACA-Houston Webinar The MS Powerpoint presentation used by DoD cybersecurity expert Kyle Lai at the 03/26/2021 ISACA Houston webinar. Kyle explains how to avoid pitfalls in CMMC compliance, the process of becoming certified in U.S. Department of Defense Cybersecurity Maturity Model Certification (CMMC), and the relationship between CMMC… Read More »
-

The Solarwinds Cyber Attack Explained
About the solarwinds cyber attack Kyle LaiPresident and CISOKLC Consulting, Inc.CISSP, CSSLP, CISA, CDPSE, CIPP/US, CIPP/G, ISO 27001 Lead Auditor The Solarwinds cyber attack affects cybersecurity within government agencies like DHS, State Department, DoJ, DoD, and Defense Contractors Experts estimate 18,000 customers are affected The Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive 21-01 to… Read More »
-

The 6 largest CMMC Level 3 Domains
While there are 17 CMMC domains, you might be wondering which domains have the most number of practices? Which might be the areas an assessor will spend most of his/her time during an assessment? In this video, we will explore the top 6 CMMC Level 3 domains based on the number of practices. These 6… Read More »
-

Interim DFARS Rules for CMMC Level 3
Maturity Level 3 highlights in the interim DFARS rules for CMMC go into effect on November 30, 2020. These DFARS rules cover changes to both NIST 800-171 and CMMC requirements. CMMC Section: To handle CUI you must get Level 3 or above Considering removing the 20 additional CMMC practices (on top of 110 NIST 800-171… Read More »
Feeling Overwhelmed by CMMC?
Download our essential guide to gain a clear roadmap through every phase of a CMMC Assessment. From foundational preparation and scope definition to navigating the assessment day and understanding post-audit requirements. Don’t leave your CMMC Level 2 success to chance.


Don’t Let Your Security Posture Drift
The Phase II suspension changed the third-party assessment timeline, not the underlying obligation to protect CUI. Use this period to verify your scope, close known gaps, align documentation with implementation, and ensure your SPRS submission accurately reflects your environment.



