DoctorMac
DoctorMac

Allison Giddens on Signal versus Noise : Understanding Common CMMC Vendor Tactics

|
Embed
Progress spinner
DoctorMac
DoctorMac

Allison starts off by reading the really bad apple emails. Bad mail merge, bad copy, and unconnected sales teams

|
Embed
Progress spinner
DoctorMac
DoctorMac

We don't know what we don't know

|
Embed
Progress spinner
DoctorMac
DoctorMac

We may not have a realistic idea of what your services cost

|
Embed
Progress spinner
DoctorMac
DoctorMac

It can be tough to get management buy-in

|
Embed
Progress spinner
DoctorMac
DoctorMac

Limited resources...people

|
Embed
Progress spinner
In reply to
DoctorMac
DoctorMac

@DoctorMac We may be worried about this new services will affect the business process

|
Embed
Progress spinner
DoctorMac
DoctorMac

Step One: Spell my name correctly, spell your name correctly, do not use absolutes, reference from someone good, keep it concise, avoid doomsday jargon

|
Embed
Progress spinner
DoctorMac
DoctorMac

Step Two: HTTPS and have a web presence for person signing email

|
Embed
Progress spinner
DoctorMac
DoctorMac

Step Three: Give me a pricing structure and have two references ready

|
Embed
Progress spinner
DoctorMac
DoctorMac

Step Four: Answer questions: Will you share your shared responsibility matrix, do you keep all data in US, do you outsource any work to contractors, if you start using offshore services or getting bought do you give me three months notice, and get out of contract.

|
Embed
Progress spinner
DoctorMac
DoctorMac

Step Five: Do you do an SBOM or certification for anything that touches my systems, do you have a cyber insurance policy

|
Embed
Progress spinner
DoctorMac
DoctorMac

Step Five: Ask about their hiring and HR policies so you know we can trust the people

|
Embed
Progress spinner