By:
Marci Womack
January 19th, 2023
Many organizations want to understand how they can pursue a CMMC certification. They're really interested in the standard or they know it's very important to their line of business. And today we're going to talk about the ways that CMMC certification can happen right now. And what we expect in the future.
By:
Sully Perella
December 1st, 2022
If you are a software developer and you want to be assessed against the PCI-DSS, maybe the secure software lifecycle under the SSF is a better choice for you. Let's talk about why.
By:
Sully Perella
November 4th, 2022
Critical security control failure. It's a whole lot of words. What does this mean? How does this apply to your organization? Well, we here at Schellman are well aware of these requirements. Stay tuned.
By:
Josh Tomkiel
October 11th, 2022
So you're interested in having a penetration test performed and you're wondering, is one enough for five years? Do I have to do it weekly or monthly? In this video, we'll talk about how frequently you should have a test performed.
By:
Douglas Barbin
October 5th, 2022
You're a cloud service provider and you want to do work for the federal government. In order to do that though, you need to be FedRAMP authorized and you've been told by the government agency that you're trying to sell to that, you need to be FedRAMP authorized. In this short video, we're going to walk you through what the process is, what the journey is to get to the point where you have that authorization, you've been approved, and you can go and sell work to your federal agency customers.
By:
Josh Tomkiel
September 29th, 2022
Setting the scope correctly is the number one thing you need to worry about when you're starting the process of choosing a pen test provider. Why does everyone harp on scoping with timing and pricing?? Hi, I'm Josh Tomkiel, I'm a senior manager here at Schellman on the pen test team. I've been in the industry for over 10 years, started off as a penetration tester working on web applications and internal and external networks. And now I'm on the manager side overseeing projects. So you've decided you're going to have a penetration test performed, you're going out talking to vendors, getting estimates. But the first thing that everybody asks you: "what's the scope? What's the scope?" Why is it so important? It's important because the scope dictates: