<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>baseline security controls &#8211; SteelCloud</title>
	<atom:link href="https://www.steelcloud.com/tag/baseline-security-controls/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.steelcloud.com</link>
	<description></description>
	<lastBuildDate>Mon, 25 Aug 2025 19:49:00 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://www.steelcloud.com/wp-content/uploads/favicon.png</url>
	<title>baseline security controls &#8211; SteelCloud</title>
	<link>https://www.steelcloud.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Interview: Making Policy Compliance Work for You &#8211; CIS Benchmarks</title>
		<link>https://www.steelcloud.com/interview-making-policy-compliance-work-for-you-cis-benchmarks/</link>
		
		<dc:creator><![CDATA[Becky Brown]]></dc:creator>
		<pubDate>Mon, 27 Jun 2022 16:57:34 +0000</pubDate>
				<category><![CDATA[All Resources]]></category>
		<category><![CDATA[Videos]]></category>
		<category><![CDATA[Asset Security]]></category>
		<category><![CDATA[ATO]]></category>
		<category><![CDATA[Authority To Operate]]></category>
		<category><![CDATA[baseline security controls]]></category>
		<category><![CDATA[CIS Benchmarks]]></category>
		<category><![CDATA[cis controls]]></category>
		<category><![CDATA[disa]]></category>
		<category><![CDATA[Disa STIG]]></category>
		<category><![CDATA[FedRAMP]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[NIST 800]]></category>
		<category><![CDATA[Risk Management Frame]]></category>
		<category><![CDATA[RMF]]></category>
		<category><![CDATA[Secure baseline]]></category>
		<category><![CDATA[Security Technical Implementation Guide STIG]]></category>
		<guid isPermaLink="false">https://www.steelcloud.com/?p=86890</guid>

					<description><![CDATA[How the CIS Benchmarks and the DISA STIGs come together to form the bedrock principle for policy compliance. What is the best way to manage and configure for best security affect to support the mission and operation? In this CyberSecurity TV episode, Tony Sager, Sr VP Center for Internet Security (CIS), and Brian Hajost, SteelCloud ...]]></description>
		
		
		
		<media:content url="https://www.youtube.com/embed/3aE5JjKUVIs" medium="video" width="1280" height="720">
			<media:player url="https://www.youtube.com/embed/3aE5JjKUVIs" />
			<media:title type="plain">Making Policy Compliance Work for You - CIS Benchmarks &amp; DISA STIGs</media:title>
			<media:description type="html"><![CDATA[In this CyberSecurity TV episode, Tony Sager, Sr VP  Center for Internet Security (CIS),  and Brian Hajost, SteelCloud Founder and COO, discuss making policy...]]></media:description>
			<media:thumbnail url="https://www.steelcloud.com/wp-content/uploads/making-policy-compliance-work-fo.jpg" />
			<media:rating scheme="urn:simple">nonadult</media:rating>
		</media:content>
	</item>
		<item>
		<title>Interview: Cloud Migration &#8211; Preparing to Move to the Commercial Cloud</title>
		<link>https://www.steelcloud.com/interview-cloud-migration-preparing-to-move-to-the-commercial-cloud/</link>
		
		<dc:creator><![CDATA[Becky Brown]]></dc:creator>
		<pubDate>Mon, 23 May 2022 14:41:13 +0000</pubDate>
				<category><![CDATA[All Resources]]></category>
		<category><![CDATA[Videos]]></category>
		<category><![CDATA[Asset Security]]></category>
		<category><![CDATA[ATO]]></category>
		<category><![CDATA[Authority To Operate]]></category>
		<category><![CDATA[baseline security controls]]></category>
		<category><![CDATA[cloud migration]]></category>
		<category><![CDATA[CMMC 2.0]]></category>
		<category><![CDATA[commercial cloud]]></category>
		<category><![CDATA[Disa STIG]]></category>
		<category><![CDATA[NIST 800]]></category>
		<category><![CDATA[nist 800-53]]></category>
		<category><![CDATA[Risk Management Frame]]></category>
		<category><![CDATA[RMF]]></category>
		<category><![CDATA[Secure baseline]]></category>
		<category><![CDATA[Security Technical Implementation Guide STIG]]></category>
		<category><![CDATA[system level control]]></category>
		<category><![CDATA[Zero Trust]]></category>
		<guid isPermaLink="false">https://www.steelcloud.com/?p=86752</guid>

					<description><![CDATA[The “how-to” prepare and deliver speed and security for operational capabilities for the commercial cloud explained. In this CyberSecurity TV episode, Maria C. Horton, CISSP-ISSMP, IAM FedRAMP Program Manager/Director, and Brian Hajost, SteelCloud Founder and COO, discuss preparing for migration to the commercial Cloud. Cloud means different things to different people. Cloud is a force ...]]></description>
		
		
		
			</item>
		<item>
		<title>Interview: Zero Trust and How to Protect the Crown Jewels</title>
		<link>https://www.steelcloud.com/interview-zero-trust-and-how-to-protect-the-crown-jewels/</link>
		
		<dc:creator><![CDATA[Becky Brown]]></dc:creator>
		<pubDate>Mon, 14 Feb 2022 15:19:24 +0000</pubDate>
				<category><![CDATA[All Resources]]></category>
		<category><![CDATA[Videos]]></category>
		<category><![CDATA[Asset Security]]></category>
		<category><![CDATA[ATO]]></category>
		<category><![CDATA[Authority To Operate]]></category>
		<category><![CDATA[baseline security controls]]></category>
		<category><![CDATA[CMMC 2.0]]></category>
		<category><![CDATA[disa]]></category>
		<category><![CDATA[Disa STIG]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[NIST 800]]></category>
		<category><![CDATA[nist 800-53]]></category>
		<category><![CDATA[Risk Management Frame]]></category>
		<category><![CDATA[RMF]]></category>
		<category><![CDATA[Secure baseline]]></category>
		<category><![CDATA[Security Technical Implementation Guide STIG]]></category>
		<category><![CDATA[system level control]]></category>
		<category><![CDATA[Zero Trust]]></category>
		<guid isPermaLink="false">https://www.steelcloud.com/?p=83019</guid>

					<description><![CDATA[Zero Trust: Do you build a higher fence or wider moat? In this CyberSecurity TV episode, Glen Hernandez, Captain, U.S. Coast Guard (Retired), Former U.S. Coast Guard CISO Chair, AFCEA Zero Trust Strategies Subcommittee, and Brian Hajost, SteelCloud Founder and COO, discuss Zero Trust and how it differs from the traditional cybersecurity practices. Zero Trust ...]]></description>
		
		
		
			</item>
		<item>
		<title>Interview: Compliance Risk Mitigation and Risk Optimization at Scale</title>
		<link>https://www.steelcloud.com/interview-compliance-risk-mitigation-and-risk-optimization-at-scale/</link>
		
		<dc:creator><![CDATA[Becky Brown]]></dc:creator>
		<pubDate>Wed, 26 Jan 2022 16:52:56 +0000</pubDate>
				<category><![CDATA[All Resources]]></category>
		<category><![CDATA[Videos]]></category>
		<category><![CDATA[Asset Security]]></category>
		<category><![CDATA[ATO]]></category>
		<category><![CDATA[Authority To Operate]]></category>
		<category><![CDATA[baseline security controls]]></category>
		<category><![CDATA[CMMC 2.0]]></category>
		<category><![CDATA[disa]]></category>
		<category><![CDATA[Disa STIG]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[NIST 800]]></category>
		<category><![CDATA[nist 800-53]]></category>
		<category><![CDATA[Risk Management Frame]]></category>
		<category><![CDATA[RMF]]></category>
		<category><![CDATA[Secure baseline]]></category>
		<category><![CDATA[Security Technical Implementation Guide STIG]]></category>
		<category><![CDATA[system level control]]></category>
		<guid isPermaLink="false">https://www.steelcloud.com/?p=82948</guid>

					<description><![CDATA[Keep your inbox empty (compliance) while managing compliance risk mitigation and risk optimization to scale effectively with automation. In this CyberSecurity TV episode, Terry Roberts Founder and  CEO, White Hawk Inc. and Brian Hajost, SteelCloud Founder and COO, discuss risk mitigation and risk optimization with automation to scale effectiveness. Cybersecurity for computer networks and systems ...]]></description>
		
		
		
			</item>
		<item>
		<title>Interview: Anchors Away: Maritime Cybersecurity Voyage</title>
		<link>https://www.steelcloud.com/interview-anchors-away-maritime-cybersecurity-voyage/</link>
		
		<dc:creator><![CDATA[Becky Brown]]></dc:creator>
		<pubDate>Fri, 17 Dec 2021 18:08:05 +0000</pubDate>
				<category><![CDATA[All Resources]]></category>
		<category><![CDATA[Videos]]></category>
		<category><![CDATA[Asset Security]]></category>
		<category><![CDATA[ATO]]></category>
		<category><![CDATA[Authority To Operate]]></category>
		<category><![CDATA[baseline security controls]]></category>
		<category><![CDATA[CMMC 2.0]]></category>
		<category><![CDATA[disa]]></category>
		<category><![CDATA[Disa STIG]]></category>
		<category><![CDATA[Maritime cybersecurity]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[NIST 800]]></category>
		<category><![CDATA[nist 800-53]]></category>
		<category><![CDATA[Risk Management Frame]]></category>
		<category><![CDATA[RMF]]></category>
		<category><![CDATA[Secure baseline]]></category>
		<category><![CDATA[Security Technical Implementation Guide STIG]]></category>
		<category><![CDATA[system level control]]></category>
		<guid isPermaLink="false">https://www.steelcloud.com/?p=82825</guid>

					<description><![CDATA[The Maritime Cybersecurity  voyage starts with best system level practices In this CyberSecurity TV interview, Brian Hajost, SteelCloud COO, and guest Dan Turissini (CMMC Registered Practitioner)  and Dave Gardy focuses on  the Maritime industry and what steps they are taking to adopt a cybersecurity structure regiment. Did you know that currently ,there are no mandates ...]]></description>
		
		
		
			</item>
		<item>
		<title>Interview: CMMC 2.0—This Changes Everything!</title>
		<link>https://www.steelcloud.com/interview-cmmc-2-0-this-changes-everything/</link>
		
		<dc:creator><![CDATA[Becky Brown]]></dc:creator>
		<pubDate>Fri, 17 Dec 2021 16:55:23 +0000</pubDate>
				<category><![CDATA[All Resources]]></category>
		<category><![CDATA[Videos]]></category>
		<category><![CDATA[Asset Security]]></category>
		<category><![CDATA[ATO]]></category>
		<category><![CDATA[Authority To Operate]]></category>
		<category><![CDATA[baseline security controls]]></category>
		<category><![CDATA[CMMC 2.0]]></category>
		<category><![CDATA[cmmc 2.0 changes]]></category>
		<category><![CDATA[disa]]></category>
		<category><![CDATA[Disa STIG]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[FedRAMP]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[NIST 800]]></category>
		<category><![CDATA[Risk Management Frame]]></category>
		<category><![CDATA[RMF]]></category>
		<category><![CDATA[Secure baseline]]></category>
		<category><![CDATA[Security Technical Implementation Guide STIG]]></category>
		<guid isPermaLink="false">https://www.steelcloud.com/?p=82822</guid>

					<description><![CDATA[As the world turns so does CMMC 2.0 &#8211; This changes everything! In this CyberSecurity TV episode, Brian Hajost, SteelCloud COO, and guest Dan Turissini (CMMC-AB Instructor and Registered Practitioner) and Dave Gardy focuses on STIG compliance and how they help both federal and commercial. Panel: Dave Gardy/Brian Hajost discuss CMMC 2.0—This Changes Everything! Go ...]]></description>
		
		
		
			</item>
		<item>
		<title>Seven ways automation seals your CMMC certification with a KISS</title>
		<link>https://www.steelcloud.com/seven-ways-automation-seals-your-cmmc-certification-with-a-kiss/</link>
		
		<dc:creator><![CDATA[Becky Brown]]></dc:creator>
		<pubDate>Mon, 22 Nov 2021 14:59:11 +0000</pubDate>
				<category><![CDATA[All Resources]]></category>
		<category><![CDATA[Articles]]></category>
		<category><![CDATA[Automated STIG Compliance]]></category>
		<category><![CDATA[baseline security controls]]></category>
		<category><![CDATA[CIS security benchmarks]]></category>
		<category><![CDATA[CMMC]]></category>
		<category><![CDATA[CMMC certification with a KISS]]></category>
		<category><![CDATA[CMMC compliance in the DIB]]></category>
		<category><![CDATA[contractor information systems]]></category>
		<category><![CDATA[cyber hardening]]></category>
		<category><![CDATA[Defense Industrial Base]]></category>
		<category><![CDATA[DIB]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[DoD STIGS]]></category>
		<category><![CDATA[FERPA]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[NIST 800 - 128]]></category>
		<category><![CDATA[NIST 800-53 CMMC]]></category>
		<category><![CDATA[NIST SP 800-171]]></category>
		<category><![CDATA[NIST SP 800-53]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[Risk Management Framework]]></category>
		<category><![CDATA[STIG compliance]]></category>
		<guid isPermaLink="false">https://www.steelcloud.com/?p=82669</guid>

					<description><![CDATA[CMMC certification with a KISS in seven steps KISS—Keep It Simple, Stupid—is a design principle noted by the U.S. Navy in 1960. The KISS principle states that most systems work best if they are kept simple rather than made complicated. In other words, simplicity should be a key goal in design and unnecessary complexity should ...]]></description>
		
		
		
			</item>
		<item>
		<title>CMMC 2.0 Opportunities and Challenges</title>
		<link>https://www.steelcloud.com/cmmc-2-0-opportunities-and-challenges/</link>
		
		<dc:creator><![CDATA[Becky Brown]]></dc:creator>
		<pubDate>Mon, 15 Nov 2021 20:53:34 +0000</pubDate>
				<category><![CDATA[All Resources]]></category>
		<category><![CDATA[Articles]]></category>
		<category><![CDATA[Automated STIG Compliance]]></category>
		<category><![CDATA[baseline security controls]]></category>
		<category><![CDATA[CIS security benchmarks]]></category>
		<category><![CDATA[CMMC]]></category>
		<category><![CDATA[CMMC compliance in the DIB]]></category>
		<category><![CDATA[contractor information systems]]></category>
		<category><![CDATA[cyber hardening]]></category>
		<category><![CDATA[Defense Industrial Base]]></category>
		<category><![CDATA[DIB]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[DoD STIGS]]></category>
		<category><![CDATA[FERPA]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[NIST 800 - 128]]></category>
		<category><![CDATA[NIST 800-53 CMMC]]></category>
		<category><![CDATA[NIST SP 800-171]]></category>
		<category><![CDATA[NIST SP 800-53]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[Risk Management Framework]]></category>
		<category><![CDATA[STIG compliance]]></category>
		<guid isPermaLink="false">https://www.steelcloud.com/?p=82630</guid>

					<description><![CDATA[CMMC 2.0 framework offers up a more transparent pathway.  Just when we were all finally wrapping our brains around the Cybersecurity Maturity Model Certification (CMMC) mandate for the defense industrial base (DIB), they went and changed it on us—for the better! In the early morning of November 4, 2021, “Cybersecurity Maturity Model Certification (CMMC) 2.0 Updates and Way ...]]></description>
		
		
		
			</item>
		<item>
		<title>Navigating the CMMC Certification Process</title>
		<link>https://www.steelcloud.com/navigating-the-cmmc-certification-process/</link>
		
		<dc:creator><![CDATA[Becky Brown]]></dc:creator>
		<pubDate>Sat, 06 Nov 2021 17:15:40 +0000</pubDate>
				<category><![CDATA[All Resources]]></category>
		<category><![CDATA[Articles]]></category>
		<category><![CDATA[Automated STIG Compliance]]></category>
		<category><![CDATA[baseline security controls]]></category>
		<category><![CDATA[CIS security benchmarks]]></category>
		<category><![CDATA[CMMC]]></category>
		<category><![CDATA[CMMC compliance in the DIB]]></category>
		<category><![CDATA[contractor information systems]]></category>
		<category><![CDATA[cyber hardening]]></category>
		<category><![CDATA[Defense Industrial Base]]></category>
		<category><![CDATA[DIB]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[DoD STIGS]]></category>
		<category><![CDATA[FERPA]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[NIST 800 - 128]]></category>
		<category><![CDATA[NIST 800-53 CMMC]]></category>
		<category><![CDATA[NIST SP 800-171]]></category>
		<category><![CDATA[NIST SP 800-53]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[Risk Management Framework]]></category>
		<category><![CDATA[STIG compliance]]></category>
		<guid isPermaLink="false">https://www.steelcloud.com/?p=82617</guid>

					<description><![CDATA[Navigating the CMMC Certification Process In 2020, the DoD rolled out its Cybersecurity Maturity Model Certification (CMMC) program. The CMMC certification process requires the defense industrial base (DIB) to attain third-party certification to ensure government contractors practice one of three cybersecurity levels, depending on the kind of data they touch. Although the deadline for CMMC ...]]></description>
		
		
		
			</item>
		<item>
		<title>Tackling the challenges of CMMC compliance in the DIB</title>
		<link>https://www.steelcloud.com/tackling-the-challenges-of-cmmc-compliance-in-the-dib/</link>
		
		<dc:creator><![CDATA[Becky Brown]]></dc:creator>
		<pubDate>Mon, 01 Nov 2021 17:28:52 +0000</pubDate>
				<category><![CDATA[All Resources]]></category>
		<category><![CDATA[Articles]]></category>
		<category><![CDATA[Automated STIG Compliance]]></category>
		<category><![CDATA[baseline security controls]]></category>
		<category><![CDATA[CIS security benchmarks]]></category>
		<category><![CDATA[CMMC]]></category>
		<category><![CDATA[CMMC compliance in the DIB]]></category>
		<category><![CDATA[contractor information systems]]></category>
		<category><![CDATA[cyber hardening]]></category>
		<category><![CDATA[Defense Industrial Base]]></category>
		<category><![CDATA[DIB]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[DoD STIGS]]></category>
		<category><![CDATA[FERPA]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[NIST 800 - 128]]></category>
		<category><![CDATA[NIST 800-53 CMMC]]></category>
		<category><![CDATA[NIST SP 800-171]]></category>
		<category><![CDATA[NIST SP 800-53]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[Risk Management Framework]]></category>
		<category><![CDATA[STIG compliance]]></category>
		<guid isPermaLink="false">https://www.steelcloud.com/?p=82607</guid>

					<description><![CDATA[Tackling the challenges of CMMC compliance in the DIB Trying to wrap your arms around CMMC compliance in the DIB? When it comes to cybersecurity and CMMC compliance in the DIB (defense industrial base), the government means business. And the more sensitive the data is that you handle, the more secure you need to be.  ...]]></description>
		
		
		
			</item>
	</channel>
</rss>
