cropped-Artboard-1.png

Part 1 – The DoD NIST SP800-171 Assessment Process and Your Supplier Performance Risk System (SPRS) Score.

Part 1 – The DoD NIST SP800-171 Assessment Process and Your Supplier Performance Risk System (SPRS) Score. This 2- hour course is the first part in a two-part series and provides a review of the DoD Assessment Methodology (DAM) based on NIST SP800-171, the scoring of practices, how to obtain your Supplier Performance Risk System (SPRS) score, and what’s required to enter your SPRS score.

$499.00

Description

Part 1 – The DoD NIST SP800-171 Assessment Process and Your Supplier Performance Risk System (SPRS) Score. This 2- hour course is the first part in a two-part series and provides a review of the DoD Assessment Methodology (DAM) based on NIST SP800-171, the scoring of practices, how to obtain your Supplier Performance Risk System (SPRS) score, and what’s required to enter your SPRS score.

Nullam quis risus eget urna mollis ornare vel eu leo. Aenean lacinia bibendum nulla sed 

Level 1

An organization must demonstrate basic cyber hygiene practices, such as ensuring employees change passwords regularly to protect Federal Contract Information (FCI). FCI is “information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government.”

Level 2

An organization must have an institutionalized management plan to implement good cyber hygiene practices to safeguard CUI, including all the NIST 800-171 r2 security requirements and processes

Level 3 – Expert.

An organization must have standardized and optimized processes in place and additional enhanced practices that detect and respond to changing tactics, techniques and procedures (TTPs) of advanced persistent threats (APTs).

An APT is an adversary that possesses sophisticated levels of cyber expertise and significant resources to conduct attacks from multiple vectors. Capabilities include having resources to monitor, scan, and process data forensics.