CMMC Compliance: Passing the Assessment Is Not Enough | William McBorrough
The Briefing with Dr. Tuboise Floyd
0:00 / 0:00
CMMC Compliance: Passing the Assessment Is Not Enough | William McBorrough
41 просмотр · 12 дней назад
The Briefing with Dr. Tuboise Floyd
77 подписчиков
41 просмотр · 12 дней назад
Passing a CMMC assessment and staying compliant are two different jobs.
A defense contractor can spend a year preparing for an assessment, pass, and then watch the program begin to come apart. The people who built it return to their regular jobs. The paperwork stops matching the work. The next assessor may find a company that was compliant once.
In this episode of The Briefing, Dr. Tuboise Floyd sits down with William McBorrough, CISO and Lead CMMC Assessor at MCGlobalTech, to examine the compliance sustainability gap—and why CMMC is ultimately a governance problem, not simply an assessment problem.
William brings a rare perspective to the conversation: he builds cybersecurity compliance programs and assesses the programs other organizations have built.
The conversation gets underneath CMMC to examine what happens after assessment day.
What does an assessor actually want to see?
Why is audit readiness different from sustainable compliance?
What happens when policies and procedures no longer match operations?
Where is the evidence that required activities are actually being performed?
Who owns governance inside a small defense contractor that does not have the staff or expertise to operate a mature compliance program?
And what happens when the same policy-versus-practice gap appears around artificial intelligence?
William explains why he views CMMC as a governance requirement centered on controlling the flow of Controlled Unclassified Information, and why organizations need the capability to repeatedly perform—and demonstrate—the activities they committed to.
For an assessor, documentation alone is not enough.
If a policy says access is reviewed every month, where are the records?
What process was followed?
Who performed it?
Can the organization demonstrate that the compliance program is actually operating?
The conversation then moves from CMMC into AI governance.
William explains why security leaders are increasingly becoming de facto AI leaders inside their organizations, why the traditional security role must move beyond simply saying “no,” and why CISOs need to help organizations find secure ways to accomplish legitimate business objectives.
The connection between CMMC and AI is bigger than either technology or regulation:
Policy on paper is not practice on the floor.
The distance between the two is where the trouble lives.
Passing the assessment is one moment.
Operating the program is every day after.
GUEST
William McBorrough
CISO, Lead CMMC Assessor
MCGlobalTech
HOST
Dr. Tuboise Floyd
Founder and Principal, Decision Assurance
Human Signal
CREATIVE DIRECTOR
Jeremy Jarvis
IN THIS EPISODE
CMMC compliance and assessment readiness
The compliance sustainability gap
Why passing CMMC is not the same as staying compliant
CMMC as a governance requirement
Governance, risk management and compliance
GRC as a service
Small defense contractors and the Defense Industrial Base
NIST SP 800-171
Building sustainable cybersecurity compliance programs
What CMMC assessors actually look for
Documentation versus operational evidence
Policies, procedures and repeatable processes
CMMC Level 2
Continuous compliance
Controlled Unclassified Information
Cybersecurity governance
AI governance
The CISO as a de facto AI leader
Managing AI risk
Security leadership and business enablement
Policy on paper versus practice on the floor
Leadership and accountability
CHAPTERS
00:00 Passing the Test vs. Staying Compliant
01:00 Meet William McBorrough
02:00 Why William Wrote Beyond Compliance
04:00 When Compliance Programs Stop Operating
05:00 The Compliance Sustainability Gap
06:00 Audit Readiness vs. Sustainable Compliance
07:00 Why CMMC Is a Governance Problem
08:00 GRC as a Service
09:00 Governance Requires Capability
10:00 Mandates vs. Operating Discipline
15:00 Building and Validating CMMC Level 2
17:00 What a CMMC Assessor Actually Looks For
18:00 Documentation vs. Evidence
19:00 From CMMC to AI Governance
20:00 Security Governance and Responsible AI
21:00 Who Should Govern AI?
22:00 The CISO as De Facto Chief AI Officer
23:00 From the Voice of No to the Voice of Yes
24:00 How MCGlobalTech Approaches AI Governance
ABOUT THE BRIEFING
The Briefing with Dr. Tuboise Floyd is independent media examining the decisions underneath consequential technology.
AI. Quantum. Cyber.
Find the decision.
Follow the evidence.
Name who owns it.
Real conversations. Higher stakes.
A Human Signal Production.
WATCH AND LISTEN
https://humansignal.io/thebriefing
EDITORIAL DISCLOSURE
MCGlobalTech is a founding partner of Human Signal, and Dr. Tuboise Floyd has performed contract advisory work with the firm. The questions and editorial direction are independently determined by Human Signal.
HASHTAGS
#CMMC #CMMCCompliance #Cybersecurity #DefenseIndustrialBase #NIST800171 #CybersecurityGovernance #AIGovernance #GRC #TheBriefing #DecisionAssurance