by ganesh.nakhawa@qmulos.com | Aug 31, 2026 | Blogs
An assessor stops at a control marked as met and asks what evidence supports that call. Two years ago you’d answer from memory. You’d name the system and walk the assessor through the evidence behind it. These days there’s a reasonable chance a...
by ganesh.nakhawa@qmulos.com | Jul 13, 2026 | Blogs, Article, Compliance Therapy, Knowledge Hub
Compliance Has Two Very Different JobsThe Agentic Model: Draft, Verify, Decide What Must Not Change Three principles should hold regardless of how the technology evolves: The Bottom Line Agentic Compliance doesn’t end when the audit is over. Systems change...
by ganesh.nakhawa@qmulos.com | Jun 8, 2026 | Blogs, Article, Compliance Therapy
Introduction CMMC POA&M requirements determine which controls must be fully implemented before a Level 2 assessment under 32 CFR 170.21. The reason: only controls valued at 1 point under the CMMC scoring methodology are POA&M-eligible. Every 3-point and...
by ganesh.nakhawa@qmulos.com | Mar 16, 2026 | Blogs, Compliance Therapy
Understanding CMMC assessment objectives is essential for defense contractors. The defense supply chain handles vast amounts of Controlled Unclassified Information (CUI), making it an attractive target for cyber adversaries. To strengthen security across the Defense...
by qmulosadmin | Jan 5, 2026 | Blogs, Article, Compliance Therapy
Practical Tools and Automation Resources for Hardening Systems to Your BaselineIndustry Standard Baselines (CIS, STIGs, and Vendor Guides)Automated Hardening Frameworks (Ansible, Chef, Puppet, SaltStack)Cloud Policy and Infrastructure as Code (IaC) Tools for Automated...
by qmulosadmin | Dec 5, 2025 | Blogs, Article, Compliance Therapy
Step-by-Step Blueprint for Implementing Secure Configuration ManagementBringing It All Together Why Secure Configuration Management Has Become a Top Priority “Security Misconfiguration” has climbed from #5 in 2021 to #2 in the release candidate...