Our interview is with Bruce Schneier, who has coauthored a paper about how to push security back up the Internet-of-things supply chain: The reverse cascade: Enforcing security on the global IoT supply chain. His solution is hard on IOT affordability and hard on big retailers and other middlemen, who will face new
Government Contracts
CMMC in the Age of COVID-19
While attention is necessarily focused on the nation’s response to COVID-19, defense contractors should not put aside the need to prepare to meet DoD’s Cybersecurity Maturity Model Certification (CMMC) requirements. In fact, early this month the CMMC Accreditation Body announced on its website it had signed a Memorandum of Understanding (MOU) with DoD related to…
Episode 235: It’s a Bird, It’s a Plane, It’s … Doug?
Today we interview Doug, the chief legal officer of GCHQ, the British equivalent of NSA. It’s the first time we’ve interviewed someone whose full identify is classified. Out of millions of possible pseudonyms, he’s sticking with “Doug.” Listen in as he explains why. More seriously, Doug covers the now-considerable oversight regime that governs GCHQ’s intercepts and other intelligence collection, Britain’s view of how the law of war applies in cyberspace, the prospects for UN talks on that topic, the value of attribution, and whether a national security agency should be responsible for civilian cybersecurity (the UK says yes, the US says no).…
Continue Reading Episode 235: It’s a Bird, It’s a Plane, It’s … Doug?
The Cyberlaw Podcast — Interview with Shane Harris
Episode 198 — Interview with Shane Harris
It turns out that the most interesting policy story about Kaspersky software isn’t why the administration banned its products from government use. It’s why the last administration didn’t. Shane Harris is our guest for the podcast, delving into the law and politics of the Kaspersky ban. Along the…
Defense Contractors Take Note: NIST’s Compliance Deadline is Almost Here!
Steptoe’s Government Contracts Group recently issued an interesting advisory for defense contractors:
The end of the year approaches and that means Department of Defense (DoD) contractors must make changes to their own unclassified information systems to comply with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, Protecting Controlled Unclassified Information in Nonfederal…