In-House Risk Based Security Control Assessments (SCA) Process

This video is about implementing and managing technology security control assessments in large organizations primarily involved in federal and/or healthcare contracts, portions of which can be useful for organizations of any size that are faced with responsibility for their own risk or compliance regiments. Dr. Jerry Craig reviews a new process in which Security Controls Assessments (SCA) are managed and operated by in-house assessor teams—which allow the federal government to reduce engagement periods and costs; perform continuous monitoring and risk-based system vulnerabilities analysis; develop deeper knowledge into control families and individual controls; gain greater visibility into systems, perform and most importantly result in the ability to stand in a defensible position in the event of a data breach. The event occurred during the October 7th meeting of the Southwest CyberSec Forum at University of Advancing Technology in Tempe, AZ. Table of Contents: Introduction 0:11 Major Experience 1:28 Core Questions 3:00 What is an SCA? 4:23 What Do Restaurants & SCAs Have in Common? 5:42 What is Adaptive Capabilities Testing? 7:17 ACT Snapshot Analogy (Goal) 7:44 SCA/ACT Information Source Comparison 8:24 Failed Controls vs. Mapping Example 14:18 Alignment of Controls & Testing 17:49 Control Family Test Plans 18:32 Benefits of Aligned Test Plans 19:19 Funding Approaches 20:55 System of Record vs. Piecemeal 23:09 Conflict of Interest 24:50 Staffing for Success 25:42 Mowing the Lawn 31:05 DHS CDM Phases & Approach 32:46 Continuous Monitoring 33:51 Individual Control Family Deep Dives 36:38 Cost Savings 39:42 Bringing on Contractor Labor vs. In-House Labor (FTEs) 40:44 Lessons Learned 41:47 About Ventech Solutions 44:51 Our Core Strengths Key HIDS Program Achievements Full Security Suite

Lunch and Learn - ''Modern Data Center Technologies'' with Arista Networks - phoenixNAP
▶︎

Lunch and Learn - ''Modern Data Center Technologies'' with Arista Networks - phoenixNAP

NIST Cybersecurity Framework Explained
▶︎

NIST Cybersecurity Framework Explained

Cyber Threat Update + Review of the December 2020 Solarwinds Hack with Erik Graham and the Forum
▶︎

Cyber Threat Update + Review of the December 2020 Solarwinds Hack with Erik Graham and the Forum

Systems Thinking for Leaders: Designing Solutions That Work
▶︎

Systems Thinking for Leaders: Designing Solutions That Work

Inconceivable!  Nightmares in Data Center physical management and risks involved with availability
▶︎

Inconceivable!  Nightmares in Data Center physical management and risks involved with availability

Something is jamming GPS over Europe. Here's what we found
▶︎

Something is jamming GPS over Europe. Here's what we found

How to make 3D Games in Godot
▶︎

How to make 3D Games in Godot

I turned an old van into a 2-STORY tiny house
▶︎

I turned an old van into a 2-STORY tiny house

Leading in the Age of AI: A Conversation with NVIDIA CEO Jensen Huang | Global Conference 2026
▶︎

Leading in the Age of AI: A Conversation with NVIDIA CEO Jensen Huang | Global Conference 2026

Surprise Topics on the New CCNA 200-301 Exam
▶︎

Surprise Topics on the New CCNA 200-301 Exam

Cybersecurity Challenges for Community Banks by Scott Edwards
▶︎

Cybersecurity Challenges for Community Banks by Scott Edwards

Which country has the best education in the world? - The Global Story podcast, BBC World Service
▶︎

Which country has the best education in the world? - The Global Story podcast, BBC World Service

Programable Logic Controller Basics Explained - automation engineering
▶︎

Programable Logic Controller Basics Explained - automation engineering

Why Multiplayer Games Are Just Distributed Systems | Ellyse Cedeno on BEAM & the Actor Model
▶︎

Why Multiplayer Games Are Just Distributed Systems | Ellyse Cedeno on BEAM & the Actor Model

Solarwinds Breach - 2020, Discussion with the SWCSF.org Part 2 of 2.
▶︎

Solarwinds Breach - 2020, Discussion with the SWCSF.org Part 2 of 2.

World's Deadliest Computer Virus: WannaCry
▶︎

World's Deadliest Computer Virus: WannaCry

How To Manage Security Risks & Threats | Google Cybersecurity Certificate
▶︎

How To Manage Security Risks & Threats | Google Cybersecurity Certificate

Merging Security and Compliance: Perspectives on Emerging Regulations and Best Practices
▶︎

Merging Security and Compliance: Perspectives on Emerging Regulations and Best Practices

What You Need to Know for the MS-102: Microsoft 365 Administrator Exam
▶︎

What You Need to Know for the MS-102: Microsoft 365 Administrator Exam

ISO IEC 27701:2019  Security Techniques - Overview and Implementation
▶︎

ISO IEC 27701:2019 Security Techniques - Overview and Implementation