In this episode, Kaleigh Floyd interviews Kelly Hood from Optic Cyber Solutions, discussing her journey into the CMMC space, the challenges faced in consulting, and the importance of effective documentation.
They explore the significance of the Customer Responsibility Matrix (CRM) and System Security Plan (SSP), as well as the NIST Cybersecurity Framework (CSF) and its connection to CMMC compliance. Kelly shares insights on navigating compliance requirements and the need for clarity in communication, emphasizing that while the journey may be complex, it is achievable with the right approach and mindset.
CMMC can feel like a mountain, and half the challenge is keeping your momentum and not getting lost in the weeds.
I recently joined the Climbing Mount CMMC podcast as part of their CybHER series, where I got to chat with Kaleigh Floyd about what it takes to navigate CMMC.
We talked about everything from the value of good documentation to helping teams actually make sense of the requirements …without getting lost in the weeds. (And yes, we even touched on the NIST Cybersecurity Framework …because of course we did!)
Preparing for CMMC is about building a program that *actually* works for you and giving the assessors confidence in what you’re doing.
Big thanks to Kaleigh for a great conversation! If you haven’t checked out the Climbing Mount CMMC podcast yet, it’s definitely worth a listen. There’s a whole backlog of episodes diving into the real challenges of preparing for CMMC, including insights from Axiom’s own journey of getting Level 2 certified.
Connect with our team to gain the insight and guidance needed to move forward with confidence.