GRC Academy

By: Jacob Hill
  • Summary

  • Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform for GRC professionals, executives, and anyone else who wants to increase their knowledge in the GRC space!
    Copyright GRC Academy
    Show More Show Less
activate_Holiday_promo_in_buybox_DT_T2
Episodes
  • Android Security Masterclass: What Every Cyber GRC Team Must Know
    Nov 19 2024

    Do you use Android at work, but don't really understand it?

    In this episode Hahna Kane Latonick teaches an Android cybersecurity masterclass for cyber GRC teams:

    Here are a few highlights from this episode:

    • How the Android project is managed
    • How Android devices are compromised
    • The many steps to update Android devices
    • Most important steps to secure Android devices
    • Is Apple more secure than Android?

    Hahna is the Director of Security Research at Dark Wolf Solutions. Some of her focuses include Android reverse engineering and exploit development. She has been featured on national media outlets including Fox Business News, ABC News, and many others!

    Too often companies integrate mobile devices at work without truly understanding how they work and the risks involved.

    Hahna explained these concepts so well! And of course, we had some back and forth on what is more secure, Android or Apple.

    I really enjoyed this episode and learned more about Android myself! What were your takeaways?

    Follow Hahna on LinkedIn: https://www.linkedin.com/in/hahnakane/

    Dark Wolf Solutions Website: https://darkwolfsolutions.com/

    Android Security Research Playbook: https://asrp.darkwolf.io/

    -----------

    Thanks to our sponsor Vanta!

    Want to save time filling out security questionnaires?

    Experience questionnaire automation here: https://vanta.com/grcacademy

    -----------

    Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!

    Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e38&utm_campaign=courses

    #android #cybersecurity #informationsecurity

    Show More Show Less
    1 hr and 21 mins
  • Penn State Cybersecurity False Claims Scandal: Meet the Whistleblower
    Nov 11 2024

    Introducing the Penn State Whistleblower.

    In this episode, the whistleblower explains how he tried to stop Penn State from allegedly LYING to the government about their NIST 800-171 compliance and what he has faced since he blew the whistle!

    Whistleblower attorney Julie Bracker also shares what the media got wrong in this case and the latest on the Georgia Tech FCA case!

    Here are a few highlights from this episode:

    - Hear directly from the whistleblower in this False Claims Act case

    - What the media got wrong

    - Recommendations to universities

    - Advice for other whistleblowers

    Matthew Decker was the Chief Information Officer at the Applied Research Laboratory at Penn State from 2015 until 2023 and the interim Vice Provost and CIO responsible for all of Penn State from January 2016 until September 2016. Matthew currently serves as the Chief Data and Information Officer at NASA’s Jet Propulsion Laboratory since 2023.

    It was fascinating to learn that the university assumed compliance with their own AD95 security policy meant they were automatically compliant (at least to some measure) with NIST 800-171. This is a great reminder that the details always matter!

    Special thanks to Matt for sharing his story with us, and to Julie Bracker for coordinating this interview!

    Follow Julie on LinkedIn: https://www.linkedin.com/in/juliekeetonbracker/

    Bracker & Marcus LLC Website: https://www.fcacounsel.com/

    Connect with Matt on LinkedIn: https://www.linkedin.com/in/matt-decker-cio/

    Whistleblower's Handbook: https://www.amazon.com/New-Whistleblowers-Handbook-Step-Step/dp/1493028812/

    -----------

    Thanks to our sponsor Vanta!

    Want to save time filling out security questionnaires?

    Experience questionnaire automation here: https://vanta.com/grcacademy

    -----------

    Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!

    Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e37&utm_campaign=courses

    #whistleblower #cmmc #cybersecurity

    Show More Show Less
    44 mins
  • Microsoft 365 GCC High: The Inside Story with Richard Wakeman
    Nov 5 2024

    Confused about Microsoft 365 and DFARS/CMMC compliance?

    In this episode, I speak with Richard Wakeman, Chief Architect for cybersecurity of Aerospace & Defense @ Microsoft!

    We discuss the history of the government clouds, the need behind GCC and GCC High, and much more!

    Here are some highlights:

    • The origins of the Microsoft clouds
    • Which clouds support DFARS 7012 compliance
    • When will GCC High be FedRAMP authorized?
    • CUI enclave considerations

    Richard is a wealth of knowledge, and I have personally benefited from his compliance blog articles since at least 2020!

    If you are currently operating in the Microsoft cloud or are trying to decide which Microsoft cloud to buy, you won't want to miss this!

    Were you aware that GCC High isn't FedRAMP authorized yet? What about Microsoft 365 commercial not being compliant with DFARS 7012?

    Whatever your thoughts are, let me know!

    Follow Richard on LinkedIn: https://www.linkedin.com/in/wakeman/

    Microsoft Cloud compliance article: https://techcommunity.microsoft.com/t5/public-sector-blog/understanding-compliance-between-commercial-government-dod-amp/ba-p/4225436

    Microsoft 365 Roadmap: https://www.microsoft.com/en-us/microsoft-365/roadmap

    -----------

    Thanks to our sponsor Vanta!

    Want to save time filling out security questionnaires?

    Experience questionnaire automation here: https://vanta.com/grcacademy

    -----------

    Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!

    Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e36&utm_campaign=courses

    Show More Show Less
    1 hr and 2 mins

What listeners say about GRC Academy

Average customer ratings

Reviews - Please select the tabs below to change the source of reviews.