Drafting Compliance: Recent Episodes

Hyperproof

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

FedRAMP compliance is one of the toughest challenges facing SaaS companies working with the federal government, and in this episode we explore the most common readiness gaps, misconceptions, and cultural shifts organizations must overcome to succeed. Drawing from extensive experience advising technology companies, we discuss why small SaaS firms often struggle with operational maturity, why FedRAMP compliance timelines frequently extend far beyond initial expectations, and how federal updates such as FedRAMP 20x and NIST 800-171 adoption are reshaping requirements across the supply chain. We cover strategies for managing executive accountability, building sustainable compliance programs, preventing compliance drift, and avoiding costly project delays. Whether you are a startup or a large enterprise seeking FedRAMP authorization, this conversation offers practical insights into achieving and maintaining compliance while adapting to evolving federal requirements.▬ Contents of this episode ▬▬▬▬▬▬▬▬▬▬ 0:00 - Introduction0:18 - Beer3:20 - Pre-C3PAO Readiness Challenges for Small SaaS Companies21:45 - FedRAMP Timeline and Project Management Failures25:10 - Management Accountability and Program Ownership29:40 - Maintaining Long-term Compliance and FCA Risk Management36:00 - Beer Reviews

View Details

Join Kayne and Tom live from San Diego, CA, home of the CCPA, as they sit down with Rob Carson, Founder and CEO of Semper Sec, to unpack what the California Consumer Privacy Act (CCPA) really means for businesses, even outside the Golden State. From Article 9's evolving cybersecurity audit requirements to the tension between ISO standards and California’s growing preference for NIST CSF 2.0, this episode dives deep into what compliance professionals need to know now, and how to prepare before deadlines hit in 2028. Plus, we're cracking open some beers and talking shop: privacy audits, regulatory agility, framework conflicts, and how companies can avoid audit fatigue while still staying secure. Whether you're a CISO, risk pro, or compliance nerd, this is the practical, unfiltered discussion you've been waiting for.

View Details

Kayne and Tom talk about an article on the future of auditing with consideration for AI and it’s uses. Along the way, they uncover where organizations should be considering strategic shifts around AI and where they need to exercise caution. Of course we all get to enjoy another face of disgust from an otherwise truly enjoyable beer.

Reference documents: https://hyperproof.io/resource/the-future-of-auditing-2025/

Beer: Cadence (Belgian-Style Ale) by Reformation Brewery

▬ Contents of this episode ▬▬▬▬▬▬▬▬▬▬ 0:00 - Intro

0:16 - Beer background

4:05 - We’re facing new regulatory requirements like NIS2 and DORA in the EU, along with potential state-by-state regulations in the US, and the challenges of FedRAMP. How should companies be adjusting audit readiness strategies to handle this increasing complexity?

10:45 - Something that I mentioned in the article was that in our IT benchmark survey, we found that 59% of organizations now test all controls rather than just the most important ones. What's your perspective on this shift, and have we made similar changes?

14:45 - How has the integration of AI and cloud technology changed your thinking about auditing and compliance in the past year?

20:30 - What role do you see for external consultants in the audit preparation process?

26:15 - How are we handling the challenge of managing multiple audits simultaneously while avoiding duplication of work across departments?

28:55 - What specific inefficiencies have we identified in our current audit processes, and which technologies have been most helpful in addressing them?

33:40 - The article emphasizes the value of continuous controls monitoring. What measurable benefits have you seen from implementing real-time monitoring of your controls?

39:18 - Beer reviews

View Details

Kayne and Tom talk about AI and regulatory consequences with a Special guest, and Tom’s brother, Dustin Wilcox, a Fortune 20 CISO with a Global Healthcare company. They knock back a delicious Porter beer and uncover the secrets of AI and regulatory management. A blockbuster of a good time.

▬ Contents of this episode ▬▬▬▬▬▬▬▬▬▬

0:00 - Intro 0:28 - Beer background

4:40 - The balance between AI usage and privacy laws

9:10 - Deepseek and data breaches

15:30 - How do the “right to be forgotten” provisions under GDPR and CCPA impact the development and deployment of AI systems?

22:00 - What are the potential risks and implications for organizations if they fail to identify users interacting with their AI systems in the context of GDPR and CCPA compliance?

25:18 - What are the potential security and privacy risks associated with deploying a GPT LLM using proprietary data without a centralized IT team managing access controls?

35:30 - Can you share best practices for ensuring AI systems are designed to respect user privacy rights?

46:05 - Beer reviews

The Drafting Compliance series: To lighten the dark corners of compliance, hosts Kayne and Tom share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom talk with Adam Brennick, Director of Security, Risk, and Compliance at Cockroach Labs. Adam dives into the risk assessment process and some of the best practices for building and maturing the risk management lifecycle. Kayne has a surprising score for the beer today and it is marked for future celebrations.

Beer: No-Li Squatch Pirate Juicy Haze IPAReference Documents:https://hyperproof.io/resource/iso-27001-statement-of-applicability/https://hyperproof.io/iso-27001/https://youtu.be/PdYu6_m42Ek▬ Contents of this episode ▬▬▬▬▬▬▬▬▬▬ 0:00 - Intro 0:23 - Beer background 4:40 - Intro Questions9:40 - Risk Assessment Supporting Compliance Audits17:00 - Engaging Business Owners in Risk Management23:45 - Risk Treatment and Risk Acceptance Education31:55 - Strengthening Trust in Compliance Reports37:40 - Compliance Reports and Go-to-Market Strategy42:30 - Beer reviews The Drafting Compliance series: To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom talk about DORA and its applicability. Learn where DORA applies, how you may need to be concerned about DORA even if you think you don’t and why DORA is causing confusion in US companies. Kayne and Tom try an unusual option to drink and we come close on the scoring.Reference Documents:https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022R2554 https://hyperproof.io/resource/comprehensive-guide-dora/

Beer: Excelsior Imperial Apple by Schilling Cider House▬ Contents of this episode ▬▬▬▬▬▬▬▬▬▬ 0:00 - Intro 0:17 - Beer background 3:39 - What is DORA?4:10 - Does DORA affect US-based businesses?6:53 - Why are US-based businesses confused about DORA?9:43 - What are the key compliance requirements under DORA?17:40 - How should US companies prepare for DORA's resilience testing requirements? 21:00 - Does DORA pose unique challenges compared to existing US cybersecurity regulations? 25:50 - Does DORA affect third-party risk management?34:44 - What steps should US companies take to ensure compliance by the 2025 deadline? 38:03 - How does DORA interact with other EU regulations like NIS2, and what does this mean for US companies?40:18 - Beer reviews The Drafting Compliance series: To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

On this episode, we're expanding the show to talk about more than FedRAMP. But before we get to that, I want to mention: we're sitting in the same room in San Diego, in front of a live audience at HyperConnect 2024 , with our special guest Eric Hammersley of Nutanix, and we have some beers.

▬ Contents of this episode ▬▬▬▬▬▬▬▬▬▬ 0:00 - Intro 0:35 - Beer background 3:57 - Frameworks / controls14:25 - Contractual obligations23:25 - Security questionnaires31:45 - Risks33:00 - Beer reviews

The Drafting Compliance series: To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom talk with Lisa Hall, CISO at Safebase. Recorded from Austin, Texas, they try a flight of local beer! They also take time to discuss Lisa's FedRAMP journey, talking with auditors, and the implications of the CrowdStrike disaster. ▬ Contents of this episode ▬▬▬▬▬▬▬▬▬▬ 0:00 - Intro 0:55 - Beer background 7:00 - Implementing FedRAMP at a Company with an Agency Sponsor13:07 - Comparing FedRAMP with Other Cybersecurity Frameworks18:50 - How Frameworks Should Demonstrate Existing Practices23:51 - Being Comfortable with Controls When Talking to Auditors29:11 - July 2024 CrowdStrike IT Disaster and Its Implications33:00 - Beer reviews The Drafting Compliance series: To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom talk with Alexander Neff, Lecturer at ASU and Senior Director of InfoSec at Faro Health. Great conversation was had on both Alexander’s FedRAMP experience and his beer choice. Come see Kayne’s highest rated beer!

Beer: Lindemans FramboiseReference documents: https://www.fedramp.gov/documents-templates/The Drafting Compliance series: To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom talk with Victoria Southall, the Director of Cybersecurity, Governance, Risk, and Compliance (GRC) at Everfox. Kayne learns the art of double fisting… or should I say triple fisting, as we try 3 beers in this episode. Results vary, but as always, the tasting brings out the best in Kayne’s facial expressions.

Beer: Shock Top Brewing Co. Shock Top, Samuel Adams Summer Ale, Blue Moon Brewing, Blue Moon Belgian WhiteReference documents: https://www.fedramp.gov/documents-templates/

The Drafting Compliance series: To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom talk with Eric Holtzclaw, Field CISO, with Blackcat Security. Eric shepherded the first company through FedRAMP Tailored Li-SaaS. We learn how the very first effort went, and what Eric learned along the way. Dare we say, Eric was a Guinea Pig for the FedRAMP. Of course, we subject Kayne to new beer, and fun was had!

Reference documents:

https://www.fedramp.gov/documents-templates/

Beer: Stella Artois, Liberte

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom talk with James Leach, A Principal with Fortreum, a 3PAO. James pulls the covers back on the role 3PAOs plays in the FedRAMP journey. From advice, then assessment and working with the larger FedRAMP ecosystem, James helps us understand where 3PAOs provide value. We try New Belgium, Fat Tire and stand back and watch Kayne react. Good Times!

View Details

Special Guest Matthew Feldman joins Kayne and Tom to pull the curtain back on his FedRAMP experiences. Matthew has a wealth of experience and understands the nuances of FedRAMP. Mathew helps understand the importance of best practice when looking through the lens of compliance. Of course, as always, we have beer to review and Kayne has a reaction. Come see the fun!

View Details

Tom provides an update on the status of the Hyperproof FedRAMP project. Along the way, Kayne uncovers some of the challenges associated with the project and suggests solutions for others going through the same process. And straight out of left field, Kayne actually likes a beer more than Tom. Come find out what caused this seismic disturbance in the force.

Reference documents:

  • https://www.fedramp.gov/documents-templates/

  • https://www.youtube.com/watch?v=g9oSeHOvFv8&list=PLOeoNoF0Web1t5LRya99nQyQSaDKYdhB7&index=30 (Configuration Management Episode) (Configuration Management Episode)

Beer: Firestone Walker Pivo Pils

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Tom and Kayne uncover the intricacies of the Planning family of requirements in FedRAMP Moderate. Learn about the SSP, Rules of Behavior and Architecture in the planning process. Also, of course, learn about Cigar City Brewing’s Jai Alai IPA, one of Tom’s favorites and Kayne’s… well Kayne is Kayne.

Reference documents:

https://www.fedramp.gov/documents-templates/

Beer: Cigar City Brewing, Jai Alai

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Come and see how Boulevard Brewing rebounds after a poor showing and shines with its Tank 7 American Saison beer. Kayne and Tom talk about the Audit and Accountability family of controls in FedRAMP Moderate. Learn the challenges and technologies leveraged to cope with the many requirements. Maybe you will also learn a little about Saison beer!

Reference documents:

https://www.fedramp.gov/documents-templates/

M-21-31: https://www.whitehouse.gov/wp-content/uploads/2021/08/M-21-31-Improving-the-Federal-Governments-Investigative-and-Remediation-Capabilities-Related-to-Cybersecurity-Incidents.pdf

Beer: Boulevard Brewing Co. American Saison

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom choke down the very sweet and sticky Boulevard Brewing Co.’s Cinnamon Bun Ale. Along the way they discuss the intricacies of the Risk Assessment family of FedRAMP controls and what challenges it might present. The episode ends with a surprising agreement on the beer and equally surprising desire to cleanse the palate.

Reference documents: https://www.fedramp.gov/documents-templates/

Beer: Boulevard Brewing Co. Cinnamon Bun Ale

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom uncover the nuance of the System and Services Acquisition family of FedRAMP controls. Tune in to hear how FedRAMP has matured how organizations should think about supply chain providers. Tom has a definitive belief on how this family of controls will evolve over time. Of course, a tasty beer is enjoyed by Tom, but you will need to watch to the end to see Kayne’s take on Fresh Squeezed IPA.

Beer: Deschutes Fresh Squeezed IPA

Reference documents: https://www.fedramp.gov/documents-templates/

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom dive into the System and Information Integrity family of FedRAMP Moderate controls. Find out what challenges Hyperproof has faced with this family of controls and learn some tips to help you in your own FedRAMP journey. A clear outlier shows up in this show’s beer reviews, tune in and hear for yourself.

Beer: PFriem Brewery Japanese Lager

Reference documents:

https://www.fedramp.gov/documents-templates/

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom are joined by special guest Michael Chaoui, the Founder of Atlas One Security. Michael pulls the covers back on some of the challenges of companies going through the ATO process. We also discuss recent legislation and draft memos intended to modernize the FedRAMP process, all while enjoying one of Michael’s favorite stout beers.

Beer: North Coast Brewing’s Old Rasputin

Reference Documents:

https://www.whitehouse.gov/omb/briefing-room/2023/10/27/office-of-management-and-budget-releases-draft-memorandum-for-modernizing-the-federal-risk-and-authorization-management-program-fedramp/

https://www.meritalk.com/articles/omb-unveiling-new-fedramp-guidance-on-friday/

https://www.fedramp.gov/documents-templates/

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom talk about the System and Communications Protection family of FedRAMP Rev5 controls. Learn about the “catch all” approach to this control family and some challenges faced to implementation. Tom and Kayne try a stout for the first time on the show, and Kayne seems to group it with all the other beers. As always, the faces he makes are impressive.

Beer: Correspondent Foreign Export Stout by Wander Brewing

Reference documents:

https://www.fedramp.gov/documents-templates/

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom talk with Steve Gentry about his FedRAMP experience and the lessons learned. Costs to consider, how to build controls thoughtfully and where you should consider FedRAMP control initiatives in the context of a business discussion. Of course we threw another drink in Kayne’s hands for review. This time it's a fermented drink, not a brewed drink. Welcome to the world of ciders Kayne, a short leap from wine.

Beer: Incline Cider Company’s Marion Berry and Cider Boys, Peach Country

Reference documents:

https://www.fedramp.gov/documents-templates/

Refer to your GRC Tool and Vendor Documentation

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Live from Austin, Texas, Kayne and Tom discuss supply chain risk under FedRAMP. They also try a local beer, live on stage, from HyperConnect 2023.

Beer: Austin Beerworks Fire Eagle American IPA

Reference documents:

  • Find Answers to FedRAMP FAQs: https://www.fedramp.gov/faqs/

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom talk with Matt Fryer about the cost structures and strategies associated with a Cloud Service Provider (CSP) FedRAMP project. Matt brings a well established perspective and helps understand the challenges of the increased controls focus apparent with FedRAMP. Plus, they try Modelo Especial, a Mexican lager.

Beer: Modelo Especial

Reference documents:

https://www.fedramp.gov/documents-templates/

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom talk about the FedRAMP Rev4 to Rev5 transition. Learn about key control changes, the shell game that is Rev5 and obviously, the unique flavor profile of a new beer.

Beer: Structures Brewing Raspberry Juice on Juice

Reference documents:

https://fedramp.gov/assets/resources/documents/FedRAMP_Security_Controls_Baseline_Rev5_Rev4_comparison_Summary.xlsx

https://www.anitian.com/revving-up-for-rev5-part-3-recommendations-and-timelines/

https://www.schellman.com/blog/federal-compliance/fedramp-revision-5-explained

https://quzara.com/blog/fedramp-revision-5-transition-plan-everything-you-need-to-know

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom talk with Joe Evangelisto from Tango Analytics about an interesting and stressful scenario where his 3PAO lost its accreditation. Of course, Kayne tackles yet another beer that elicited a memorable response.

Beer: Fuller’s London Pride and Boddingtons Pub Ale

Reference documents:

https://www.fedramp.gov/faqs/

https://marketplace.fedramp.gov/assessors

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom talk about personnel security, background checks, what FedRAMP requires for onboarding and terminating employees as well as a host of tips and tricks for meeting this control family. Of course, they also try a new beer and maybe, just maybe, agree on the score.

Beer: Kulshan Brewing Company Raspberry Gose

Reference documents: https://www.fedramp.gov/faqs/

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom talk about Media Protection while sipping a new pale ale. Learn the challenges of removable media, both digital and non-digital, along with a few tips and tricks for getting started with your Media Protection journey.

Beer: ODD13 Brewing n00b Hazy Pale Ale

Reference notes:

Becoming FedRAMP Authorized: What It Takes - Hyperproof: https://hyperproof.io/fedramp/

FedRAMP Controls Baseline: https://www.fedramp.gov/assets/resources/documents/FedRAMP_Security_Controls_Baseline.xlsx

NIST Guidelines for Classification of Data: https://csrc.nist.gov/pubs/sp/800/60/v2/r1/final

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne, Tom, and special guest Jacob Berry (Field CISO at Clumio) talk about the challenges in pursuing FedRAMP. Costs, hidden challenges and go-to market are rounded out with two drinkable, but not memorable, non-alchoholic beers. Listen for the knowledge, stay for the beer ratings.

Kayne and Tom share Athletic Brewing Co’s Cerveza Athletica, while our guest enjoys Athletic Brewing Co’s Lite beer.

Reference documents:

Becoming FedRAMP Authorized: What It Takes: https://hyperproof.io/fedramp/

FedRAMP Controls Baseline: https://www.fedramp.gov/assets/resources/documents/FedRAMP_Security_Controls_Baseline.xlsx

Follow and listen to more from Jacob:

www.linkedin.com/in/jacobiberry

Podcast: Onthehookpodcast.com

YouTube.com/@onthehookpodcast

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom talk about the domain under FedRAMP moderate, providing both an overview of the domain as well as specific examples of controls, and real-world scenarios for the use of those controls.

They also come close to agreeing about “Color Cloud Pink”, a Berliner Weisse with “Pink Guava, Dragon Fruit, and Passion Fruit” by Equilibrium Brewery of Middletown, New York.

Reference documents:

NIST 800-63B https://pages.nist.gov/800-63-3/sp800-63b.html

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom talk about the Contingency Planning domain under FedRAMP moderate, comparing it against the best practice of Business Continuity Planning, and providing specific guidance for key elements of a successful contingency plan. They also find what amounts to near common ground on this episodes beer tasting, Laughing Lab Scottish Ale.

Reference documents:

NIST 800-12 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-12r1.pdf

NIST 800-34 https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final

NIST 800-100 https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-100.pdf

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom talk about the Maintenance domain under FedRAMP moderate, including how it is related to the Configuration Management domain. They also nearly agree on Rogue’s Hazelnut Brown Nectar, although Kayne still likens it to old hotel coffee while Tom will drink a free one.

Reference documents:

NIST 800-12 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-12r1.pdf

NIST 800-100 https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-100.pdf

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom talk about the requirements of continuous compliance under the Security Assessment and Authorization family of controls, including key considerations for continuous monitoring and reauthorization. During the episode, they explore yet another fruit-forward beer, Deschutes’ Farmstand Fresh Mango IPA.

Reference documents:

https://www.fedramp.gov/blog/2021-05-20-SA-4_IR-3_Updates/

https://www.fedramp.gov/assets/resources/templates/FedRAMP-SSP-Moderate-Baseline-Template.docx

https://csrc.nist.gov/publications/detail/sp/800-137/final

https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom talk about the major pillars of Configuration Management. While digging into inventory management, baseline configurations, configuration drift, and risk, they tackle Bell’s Two Hearted American IPA.

Reference documents:

-https://www.fedramp.gov/assets/resources/documents/FedRAMP_Security_Controls_Baseline.xlsx

  • https://www.gsa.gov/cdnstatic/FedRAMP_Control_Quick_Guide_V12_%281%29.pdf

  • https://stateramp.org/wp-content/uploads/2021/05/CM_POL_V1.0_20210406.docx

  • https://learn.microsoft.com/en-us/azure/governance/policy/samples/fedramp-moderate#configuration-management

▬ Contents ▬▬▬▬▬▬▬▬▬▬

0:00 - Intro

1:09 - Beer background

4:36 - What is configuration management under FedRAMP?

5:37 - Why is it important to establish baseline configurations, and how does that contribute to the security of FedRAMP Moderate cloud systems?

6:41 - What is a recommended approach for cloud service providers to maintain an inventory of all hardware and software components?

7:57 - How does the configuration management control domain address vulnerability management for cloud systems?

8:37 - When implementing system changes, how can organizations ensure that they do not inadvertently reduce security or create vulnerabilities?

10:42 - And does that mean that we need to create and maintain change logs with all approved changes to the system, including modifications to hardware, software, and firmware?

11:39 - How do organizations periodically assess the effectiveness of their configuration management processes in maintaining the security of their cloud systems?

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom uncover the different approach to the Physical and Environmental controls, with a discussion of all-cloud, on prem and hybrid scenarios. Of course, they tackle a new beer as well, maybe Kayne will like this one, and maybe Tom will not… I think you already know!

Reference documents:

https://www.fedramp.gov/assets/resources/documents/FedRAMP_Security_Controls_Baseline.xlsx

▬ Contents of this video ▬▬▬▬▬▬▬▬▬▬

0:00 - Intro

0:55 - Beer background

1:48 - First beer impressions

3:55 - What is Physical and Environmental Protection in FedRAMP?

5:15 - How does it affect cloud-first organizations?

6:55 - What to do when you have a lack of access to data centers

7:40 - Are remote staff who have access to FedRAMP data covered under physical and environmental policies?

8:30 - what about things printed by printers?

12:00 - Beer ratings

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom talk about the joys of security awareness training, managing training, and the different types of security and privacy training you should consider, and as always, beer. This episode’s beer is Sierra Nevada Hazy Little Thing IPA.

Reference documents:

https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar5.pdf

▬ Contents of this video ▬▬▬▬▬▬▬▬▬▬

0:00 - Intro

0:55 - Beer background

1:48 - First beer impressions

5:05 - The FedRAMP Incident Response Control Family

17:20 - Beer ratings

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

In this episode, Kayne and Tom talk about the nuances of the Incident Response family of FedRAMP controls, some of the required documentation, testing, and beer. This episode’s beer is Woods Boss Brewing Company’s Pulaski Pecan Brown Ale.

Reference documents:

https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-61r2.pdf

▬ Contents of this podcast ▬▬▬▬▬▬▬▬▬▬

0:00 - Intro

0:25 - Beer background

1:20 - First beer impressions

4:30 - The FedRAMP Access Control Family

15:30 - Beer ratings

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom discuss FedRAMP's access control family, language that must be in the access control policy, wireless access control for SaaS companies, and how to prevent creating a paper tiger. Includes beer tasting notes for Epic Brewery's Hopulent.

0:00 - Intro

0:22 - Beer background

1:30 - First beer impressions

5:15 - The FedRAMP Access Control Family

19:30 - Beer ratings

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Kayne and Tom dive into where to begin in your FedRAMP gap analysis. They discuss the efficiencies that Hyperproof found in order to save time, and suggest other approaches. Includes beer tasting notes for Oliphant's Super Squishy.

0:00 - Intro

0:56 - Beer background

2:30 - First beer impressions

4:40 - Beer ratings

5:08 - The FedRAMP gap analysis

12:27 - How to present FedRAMP gap analysis findings

The Drafting Compliance series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.

View Details

Hosts Kayne and Tom talk about how to create the Authorization Boundary, a cornerstone of the System Security Plan (SSP) as part of FedRAMP certification. Includes beer tasting notes for Black Butte Porter.

Episode 2 Useful Links:

https://www.fedramp.gov/assets/resources/documents/CSP_A_FedRAMP_Authorization_Boundary_Guidance_DRAFT.pdf

https://csrc.nist.gov/CSRC/media/Presentations/Cloud-Authorization-Boundary-Guidance-M-Goodrich/images-media/GSA%20Cloud_AuthorizationBoundary%20-%20Matt%20Goodrich.pdf

https://infusionpoints.com/blogs/your-guide-fedramp-diagrams

View Details

Join Hyperproof hosts Kayne McGladrey, CISSP, Field CISO, and Thomas Wilcox, CISSP, Sr. Director of Security and Compliance, as they discuss the intent and overall roadmap to achieve FedRAMP compliance in a year. Includes beer tasting notes for Anchor Steam.

0:00 - Intro

1:50 - Beer background/history

2:58 - First beer impressions

5:39 - What is FedRAMP?

15:43 - Beer ratings

About the series:

To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.