MacZine
Field copies from the compliance frontier
Practitioner-grade articles on CMMC 2.0, NIST 800-171, RMF, and what it actually takes to operate secure systems in the defense industrial base - written, reviewed and versioned in the open. Published from Git, reviewed like code.
Today's Read
A C3PAO Validates the Evidence Problem Behind Vault-Codex
Posting today · 8:00 AM Eastern
This week
New issue Mon–Fri · 8:00 AM Eastern
Field Report · Cryptography
FIPS 140-3 Is the Control That Fails Quietly
Encryption that is strong is not the same as encryption that is validated. The distinction costs 5 SPRS points and it is invisible until an assessor looks.
Platform Spotlight · Capture
CaptureOS: Finding the Work You Are Still Eligible For
Capture tools tell you what is available. Compliance tools tell you what you can hold. CaptureOS puts both in one system, because the answer moves together.
Platform Spotlight · Enclave Monitoring
EnclaveWatch: Monitoring a CUI Vault Without Draining It
Continuous monitoring usually means shipping logs somewhere central. Inside a CUI boundary that is the one thing you should not do. EnclaveWatch inverts it.
Explainer · Workforce
Your Training Records Are Compliance Evidence. Are They?
Three CMMC controls turn security awareness training into an evidence problem. Most organizations do the training and fail the control anyway.
From the field · RMF / ATO
A C3PAO Validates the Evidence Problem Behind Vault-Codex
Posting Friday · 8:00 AM Eastern
Last week
Aug 3 – Aug 7
The System Security Plan an Assessor Actually Reads
Enclave or Whole Network? The Scoping Decision, Priced
The 72-Hour Clock in DFARS 252.204-7012, Hour by Hour
RMF and CMMC Are Not the Same Program. Run Them as One.
Who Signs Your Self-Attestation, and What They Are Signing
Every issue, 18 articles and counting→
Suggest a topic
Working through a CMMC, NIST 800-171, or RMF problem we haven’t covered? Tell us what you’re stuck on - it goes straight into the queue.