Перейти к содержимому

CMMC Compliance: Passing the Assessment Is Not Enough | William McBorrough

The Briefing with Dr. Tuboise Floyd

0:00 / 0:00

CMMC Compliance: Passing the Assessment Is Not Enough | William McBorrough

41 просмотр · 12 дней назад
The Briefing with Dr. Tuboise Floyd
77 подписчиков
41 просмотр · 12 дней назад
Passing a CMMC assessment and staying compliant are two different jobs. A defense contractor can spend a year preparing for an assessment, pass, and then watch the program begin to come apart. The people who built it return to their regular jobs. The paperwork stops matching the work. The next assessor may find a company that was compliant once. In this episode of The Briefing, Dr. Tuboise Floyd sits down with William McBorrough, CISO and Lead CMMC Assessor at MCGlobalTech, to examine the compliance sustainability gap—and why CMMC is ultimately a governance problem, not simply an assessment problem. William brings a rare perspective to the conversation: he builds cybersecurity compliance programs and assesses the programs other organizations have built. The conversation gets underneath CMMC to examine what happens after assessment day. What does an assessor actually want to see? Why is audit readiness different from sustainable compliance? What happens when policies and procedures no longer match operations? Where is the evidence that required activities are actually being performed? Who owns governance inside a small defense contractor that does not have the staff or expertise to operate a mature compliance program? And what happens when the same policy-versus-practice gap appears around artificial intelligence? William explains why he views CMMC as a governance requirement centered on controlling the flow of Controlled Unclassified Information, and why organizations need the capability to repeatedly perform—and demonstrate—the activities they committed to. For an assessor, documentation alone is not enough. If a policy says access is reviewed every month, where are the records? What process was followed? Who performed it? Can the organization demonstrate that the compliance program is actually operating? The conversation then moves from CMMC into AI governance. William explains why security leaders are increasingly becoming de facto AI leaders inside their organizations, why the traditional security role must move beyond simply saying “no,” and why CISOs need to help organizations find secure ways to accomplish legitimate business objectives. The connection between CMMC and AI is bigger than either technology or regulation: Policy on paper is not practice on the floor. The distance between the two is where the trouble lives. Passing the assessment is one moment. Operating the program is every day after. GUEST William McBorrough CISO, Lead CMMC Assessor MCGlobalTech HOST Dr. Tuboise Floyd Founder and Principal, Decision Assurance Human Signal CREATIVE DIRECTOR Jeremy Jarvis IN THIS EPISODE CMMC compliance and assessment readiness The compliance sustainability gap Why passing CMMC is not the same as staying compliant CMMC as a governance requirement Governance, risk management and compliance GRC as a service Small defense contractors and the Defense Industrial Base NIST SP 800-171 Building sustainable cybersecurity compliance programs What CMMC assessors actually look for Documentation versus operational evidence Policies, procedures and repeatable processes CMMC Level 2 Continuous compliance Controlled Unclassified Information Cybersecurity governance AI governance The CISO as a de facto AI leader Managing AI risk Security leadership and business enablement Policy on paper versus practice on the floor Leadership and accountability CHAPTERS 00:00 Passing the Test vs. Staying Compliant 01:00 Meet William McBorrough 02:00 Why William Wrote Beyond Compliance 04:00 When Compliance Programs Stop Operating 05:00 The Compliance Sustainability Gap 06:00 Audit Readiness vs. Sustainable Compliance 07:00 Why CMMC Is a Governance Problem 08:00 GRC as a Service 09:00 Governance Requires Capability 10:00 Mandates vs. Operating Discipline 15:00 Building and Validating CMMC Level 2 17:00 What a CMMC Assessor Actually Looks For 18:00 Documentation vs. Evidence 19:00 From CMMC to AI Governance 20:00 Security Governance and Responsible AI 21:00 Who Should Govern AI? 22:00 The CISO as De Facto Chief AI Officer 23:00 From the Voice of No to the Voice of Yes 24:00 How MCGlobalTech Approaches AI Governance ABOUT THE BRIEFING The Briefing with Dr. Tuboise Floyd is independent media examining the decisions underneath consequential technology. AI. Quantum. Cyber. Find the decision. Follow the evidence. Name who owns it. Real conversations. Higher stakes. A Human Signal Production. WATCH AND LISTEN https://humansignal.io/thebriefing EDITORIAL DISCLOSURE MCGlobalTech is a founding partner of Human Signal, and Dr. Tuboise Floyd has performed contract advisory work with the firm. The questions and editorial direction are independently determined by Human Signal. HASHTAGS #CMMC #CMMCCompliance #Cybersecurity #DefenseIndustrialBase #NIST800171 #CybersecurityGovernance #AIGovernance #GRC #TheBriefing #DecisionAssurance