SlideShare a Scribd company logo
Mission Critical Global
Technology Group
Managed	Security	Compliance	Program	
(MSCP)
About	Us
MCGlobalTech
– Mission	Critical	Global	Technology	Group	(MCGlobalTech)	is	
a	minority	owned,	small	business	founded	by	industry	
leaders	to	provide	strategic	advisory	and	security	consulting	
services	to	public	and	private	sector	business	managers	to	
better	align	technology	and	security	programs	with	
organizational	mission	and	security	compliance	goals.
– The	Principals	at	MCGlobalTech	have	provided	Information	
Security	services	to	the	Federal	Government	and	private	
sector	for	over	25	years
Our	Values
At	MCGlobalTech,	we	believe	strong	values	create	long	
term	relationships	with	our	customers,	employees,	
partners	and	the	communities	we	serve.		At	the	heart	
of	everything	we	do	are	our	corporate	values:
– Providing customer satisfaction
– Delivering innovative solutions
– Empowering staff for success
– Promoting Entrepreneurial spirit
– Maintaining technical excellence
Staff
Skills
Success
What	we	offer
MCGlobalTech builds	and	manages	efficient,	cost-effective		
information	security	programs	to	protect	client	systems,	
network	and	data	against	cyber	threats,	meet	regulatory	
compliance	requirements	and	improve	organizational	IT	
governance. We	continually	demonstrate	excellence	in	the	
following	core	competencies:
– Security	Program	Development		
– Enterprise	Risk	Management
– Governance	and	Compliance
– Systems	Security	Monitoring	
– Security	Engineering
– Vulnerability	and	Penetration	Testing
– Network	and	Systems	Security
Combating	Cyber	Threats
The Federal government is making a concerted effort combat
growing threats to our national security from both internal
and external cyber threat actors including nation-state,
terrorists, malicious insiders, etc..
Cybersecurity requirements are increasingly being introduced
through the FAR and DFARS to the companies providing
services to US government entities.
The DFARS Clause 252.204-7012 is aimed at protecting
contractor information and systems used to deliver services
to the US Department of Defense.
REQUIREMENTS FOR CONTRACTORS
The	DFARS	Clause	252.204-7012	established	a	requirement	for	
“adequate	security”	for	the	information(differs	based	on	the	
type	of	data)
– Covered	Defense	Information	(CDI)
– Controlled	Technical	Information
– Critical	Information
– Export	Control	Information
– Other	information	identified	in	the	contract
The	DFARS	clause	also	grants	DoD	personnel	access	to	the
contractor’s	system	to	investigate	the	incident
REQUIREMENTS FOR CONTRACTORS
Under	the	DFARS	provisions,	contractors	were	directed	to	
implement	NIST	800-171	standards	“as	soon	as	practical,	but	
not	later	than	December	31,	2017.”
Compliance	Requirements
• Assess	against	110	controls	defined	in	NIST	SP	800-171
• Document	compliance	status	with	respect	to	each	control	(SSP)
• Document	areas	of	non-compliance	and	remediation	plans	(POA&M)
• Be	prepared	for	audits	and/or	requests	for	compliance	attestation
• Implement	breach	reporting	requirements	(within	72	hours)
REQUIREMENTS FOR CONTRACTORS
Compliance is not a one-time activity – It requires building an
enterprise information security program that continuously
assesses and manages risks, protects covered information and
systems used for processing, storage and transmission, and
monitors and detects threats with the ability to report incidents
with 72 hours.
Organization Size is not a consideration – All companies must
comply. It only takes one user, one system to cause a cyber breach.
Not just IT – The requirements covers your People, Policies,
Processes, Technologies, Physical and Environmental, Supply Chain,
etc..
You can’t outsource your compliance responsibility. You have be
able to document how your service providers/cloud services meet
the control requirements.
CONSEQUENCES FOR CONTRACTORS
Companies	unable	to	demonstrate	NIST	800-171	compliance	
will	be	severely	impacted	as	Contracting	Officers	and	Prime	
Contractors	will	require	DFARS	compliance	as	a	pre-requisite	
to	[continue]	doing	business	with	the	DOD.	
For	companies	currently	doing	business	with	the	DOD,	
consequences	of	non-compliance	may	include	contract	
termination	for	default	or	convenience,	suspension	or	
debarment,	breach	of	contract	damages,	liquidated	damages,	
and	False	Claims	Act	damages.
Managed	Security	Compliance	Program
Our	Managed	Security	Compliance	Program	(MSCP)	
provides	full	life-cycle	security	compliance	support	to	help	
fellow	small	businesses	meet	regulatory	and	business	
security	goals.
Regardless	of	company	size	or	service	offering,	the	MSCP	
helps	you	build	and	mature	an	enterprise	information	
security	program	that	protects	your	mission-critical	People,	
Processes	and	Technologies	necessary	to	protect	you	and	
your	customers	from	growing	cyber	threats	and	
increasingly	complex	regulatory	requirements.
Full	Life-Cycle	Security
Security	
Requirements	
Definition
Security	Design	
and	Engineering
Security	Test,	
Validation	and	
Reporting
Security	
Documentation	
and	Response
Full	Life-Cycle	Security
Security	Requirements	Definition
– The	initial	phase	of	the	life	cycle	defines	the	
security	management,	operational	and	technical	
requirements	for	the	security	program.
– The	MCGlobalTech	Compliance	Team	defines	the	
requirements	of	the	program	in	accordance	with	
the	applicable	regulatory	framework	(FISMA/NIST,	
ISO,	CoBit,	PCI	DSS,	etc.).		We	also	take	into	
account	business	goals	and	structure,	leadership	
risk	tolerance	and	organizational	culture.
Full	Life-Cycle	Security
Security	Design	and	Engineering
– To	be	effective	,	security	goals	and	requirements	
must	be	“built”	into	organization	policies,	
processes,	operations	and	technical	environments.	
– The	MCGlobalTech	Security	Engineering	Team	
provides	expert	support	to	include	security	
architecture	design,	security	control	identification	
and	implementation	and	security	risk	analysis	and	
assessment.
Full	Life-Cycle	Security
Security	Test,	Validation	and	Reporting
– MCGlobalTech	offers	a	full	range	of	application,	
system	and	network	testing	to	include	security	
controls	testing,	risk	assessments,	vulnerability	
assessments	and	penetration	testing.		
– The	MCGlobalTech	Security	Assessment	Team	
provides	Independent	Validation	and	Verification	
(IV&V)	testing	to	ensure	that	the	security	program	
meets	the	defined	security	and	compliance	
requirements.
Full	Life-Cycle	Security
Security	Documentation	and	Response
– During	the	operational	phase	of	the	program,	the	
MCGlobalTech	Compliance	Team	creates	and/or	
maintains	the	security	compliance	program	
documentation	to	include	security	policies,	
security	plans,	risk	assessments,	plan	of	action	
and	milestones,		etc.
– MCGlobalTech	implements	our	Managed	
Compliance	Service	(MCS) and	Managed	Security	
Service	(MSS)	to	ensure	regulatory	compliance,	
system	confidentiality,	reliability	and	security.
MCGlobalTech	MSCP	Goals
Security	and	Compliance	Goals
qMaintain	compliance	documentation
qBuild	security	policy	framework
qPerform	vulnerability	management
qPerform	security	controls	testing
qTrack	and	manage	security	risks
qEducate	and	train	users	and	system	administrators
qProvide	security	monitoring	throughout	environment
Managed	Compliance	Service
The MCS provides a NIST 800-171 baseline compliance audit against all 110
required controls and generates the required compliance documentation i.e.
System Security Plan (SSP) which documents state of compliance and Plan of Action
and Milestones (POAM) which documents identified gaps and remediation plans
and timelines.
POAM remediation is then tracked, validated and documented with quarterly
assessments thus improving compliance posture and mature security program.
Required on-going security controls assessments, vulnerability and risk assessments
continuous monitoring, and penetration tests are scheduled as appropriate
intervals.
Baseline
Assessment
Monthly/Quarterly
Checks
Full
Compliance
Managed	Compliance	Service
MCS	Compliance	Schedule	(Annual)
Quarter 1 q Conduct Compliance Audit
q Findings tracking and reporting (eg. POAM)
q Create/Update Policies and Procedures
q Generate Compliance Artifacts (eg. SSP, Letter of Attestation)
q Vulnerability Assessment
q Security Awareness Training
Quarter 2 q Plan of Action & Milestone (POAM) Review/Update
q System Security Plan (SSP) Review/Update
q Vulnerability Assessment
q Security Controls Assessment
Quarter 3 q Plan of Action & Milestone (POAM) Review/Update
q System Security Plan (SSP) Review/Update
q Vulnerability Assessment
q Security Controls Assessment
Quarter	4 q Plan of Action & Milestone (POAM) Review/Update
q System Security Plan (SSP) Review/Update
q Enterprise Security Risk Assessment
q Network Penetration Test
Managed	Security	Service
The MCGlobalTech Managed Security Service (MSS) provides 24/7
monitoring of all end user systems (laptops, desktops, mobile
devices, servers) and Internet-facing devices (routers, firewalls,
webservers) for near real-time detect and response to cyber threats
and vulnerabilities.
Our MSS also helps small business clients meet security audit,
monitoring and incident reporting compliance requirements of the
DFARS 7012/NIST 800-171.
MSS
Internal	&	
External	Audits
Federal	
Guidelines	and	
Directives
Threats	and	
Vulnerabilities
Past	Performance
MCGlobalTech’s Principals have worked for and with large
and small contracting and consulting firms. We have provided
security expertise throughout the federal government
including the Department of Defense, Intelligence and
Federal Civilian Agencies. We have also provided security
services to financial, healthcare and various commercial
sector organizations throughout the country.
A list of some of our clients we’ve helped meet the DOD
DFARS/NIST 800-171 compliance requirements is listed in the
following table.
Some	of	our	DOD	Contractor	Clients
Contact	Us
Mission	Critical	Global	Technology	Group
1325	G	Street,	NW
Suite	500
Washington,	District	of	Columbia	20005
Phone:	202.355.9448
Email:	Info@mcglobaltech.com
Wiliam	J	McBorrough Regine	Bonneau
Co-Founder/CEO Director,	Risk	&	Compliance	
wjm4@mcglobaltech.com rbonneau@mcglobaltech.com
(202)	355-9448	x101 (202)	355-9448	x104

More Related Content

PPTX
MCGlobalTech CMMC Managed Compliance Service
PDF
CMMC 2.0 I L1 & L2 Scoping Guidance Explained
PPTX
CMMC DFARS/NIST SP 800-171
PPTX
PPTX
How I Woke Up from the CMMC Compliance Nightmare
PPTX
DFARS & CMMC Overview
PDF
The CMMC Has Arrived. Are You Ready?
PPTX
Corporate Cyber Program
MCGlobalTech CMMC Managed Compliance Service
CMMC 2.0 I L1 & L2 Scoping Guidance Explained
CMMC DFARS/NIST SP 800-171
How I Woke Up from the CMMC Compliance Nightmare
DFARS & CMMC Overview
The CMMC Has Arrived. Are You Ready?
Corporate Cyber Program

What's hot (20)

DOC
Iso 9000 iso 9001
PDF
Cybersecurity Maturity Model Certification
PPT
Educause+V4
PDF
Gpc case study_eng_0221
PPTX
CMMC Certification
PDF
IT & the Auditor
PPT
Security Management Practices
PPTX
Project Forecasting from the Perspective of an EVMA and EIA-748
PDF
Profile_Kishore Sundar
PDF
Evolution of Security Management
PDF
Agiliance Wp Key Steps
PDF
Nist.sp.800 37r2
PDF
CMMC case study: Inside a CMMC assessment
PPTX
PCI DSS Business as Usual (BAU)
PDF
The optimization method of the integrated management systems audit program v2+
PDF
FedRAMP - Federal Agencies & Cloud Service Providers meet FISMA 2.0
PPT
Fisma FedRAMP Drupal
PDF
Soc 2 vs iso 27001 certification withh links converted-converted
PDF
Powering SOX, NERC, FERC Compliance -Energy Industry
PPTX
IT Audit For Non-IT Auditors
Iso 9000 iso 9001
Cybersecurity Maturity Model Certification
Educause+V4
Gpc case study_eng_0221
CMMC Certification
IT & the Auditor
Security Management Practices
Project Forecasting from the Perspective of an EVMA and EIA-748
Profile_Kishore Sundar
Evolution of Security Management
Agiliance Wp Key Steps
Nist.sp.800 37r2
CMMC case study: Inside a CMMC assessment
PCI DSS Business as Usual (BAU)
The optimization method of the integrated management systems audit program v2+
FedRAMP - Federal Agencies & Cloud Service Providers meet FISMA 2.0
Fisma FedRAMP Drupal
Soc 2 vs iso 27001 certification withh links converted-converted
Powering SOX, NERC, FERC Compliance -Energy Industry
IT Audit For Non-IT Auditors
Ad

Similar to MCGlobalTech Managed Security Compliance Program (20)

PPTX
MCGlobalTech Enterprise Risk Management Program
PDF
MCGlobalTech Cyber Capability Statement_Final
PDF
MCGlobalTech Cyber Capability Statement
PPTX
QM & PM in TT
PPTX
Insight into Security Leader Success Part 2
PDF
RCMG Corporate Profile
PPTX
Demystifying CMMC: Real-World Insights from ControlCase Experts
PPT
Abidance Cip Presentation
DOC
Venkatesh M S - Security Audit and Compliance
PPTX
Certified Banking Security C-Suite - CTO and CIO Lane.pptx
PDF
RCMG Company Profile
PPTX
Certified Banking Security C-Suite - CEO Lane.pptx
PPTX
Certified Banking Security C-Suite - COO Lane.pptx
PPT
EUCI Mapping Cybersecurity to CIP
PDF
Zindzi Fire Capability Statement
DOC
Quality and Information Security Assurance
PDF
678177833-KPIs-and-Performance-Helmut-Salsland-BRCE2016.pdf
PDF
The Demystification of successful cybersecurity initiatives.
PDF
TheDemystification_of_SuccessfulCyberSecurity_VIMRO_LB_VH_MHF_10_11_15
PDF
RCN - Company Profile
MCGlobalTech Enterprise Risk Management Program
MCGlobalTech Cyber Capability Statement_Final
MCGlobalTech Cyber Capability Statement
QM & PM in TT
Insight into Security Leader Success Part 2
RCMG Corporate Profile
Demystifying CMMC: Real-World Insights from ControlCase Experts
Abidance Cip Presentation
Venkatesh M S - Security Audit and Compliance
Certified Banking Security C-Suite - CTO and CIO Lane.pptx
RCMG Company Profile
Certified Banking Security C-Suite - CEO Lane.pptx
Certified Banking Security C-Suite - COO Lane.pptx
EUCI Mapping Cybersecurity to CIP
Zindzi Fire Capability Statement
Quality and Information Security Assurance
678177833-KPIs-and-Performance-Helmut-Salsland-BRCE2016.pdf
The Demystification of successful cybersecurity initiatives.
TheDemystification_of_SuccessfulCyberSecurity_VIMRO_LB_VH_MHF_10_11_15
RCN - Company Profile
Ad

More from William McBorrough (18)

PPTX
Cybersecurity Career Information by Next Gen Cyber
PDF
Improving Cyber Readiness with the NIST Cybersecurity Framework
PPTX
MCG Cybersecurity Webinar Series - Risk Management
PPTX
MCG Cybersecurity Webinar Series - Risk Management
PDF
MCGlobalTech Commercial Cybersecurity Capability Statement
PPTX
MCGlobalTech Consulting Service Presentation
PDF
MCG_OnePageBrochure_Final
PPTX
MCGlobalTech Service Presentation
PDF
Information Security Continuous Monitoring within a Risk Management Framework
PDF
MCGlobalTech Capability Statement
PPTX
Managing Security Risks in Manufacturing
PPTX
Cyber Crime Threat Landscape - A Focus on the Financial Industry
PPT
Protecting Customer Confidential Information
PPTX
Need for Improved Critical Industrial Infrastructure Protection
PDF
Need for Improved Critical Industrial Infrastructure Protection
PDF
No National 'Stand Your Cyberground' Law Please
PDF
FCC Report on Google Street View Wi-Fi Data Snooping
PPT
Cloud Computing - Security Benefits and Risks
Cybersecurity Career Information by Next Gen Cyber
Improving Cyber Readiness with the NIST Cybersecurity Framework
MCG Cybersecurity Webinar Series - Risk Management
MCG Cybersecurity Webinar Series - Risk Management
MCGlobalTech Commercial Cybersecurity Capability Statement
MCGlobalTech Consulting Service Presentation
MCG_OnePageBrochure_Final
MCGlobalTech Service Presentation
Information Security Continuous Monitoring within a Risk Management Framework
MCGlobalTech Capability Statement
Managing Security Risks in Manufacturing
Cyber Crime Threat Landscape - A Focus on the Financial Industry
Protecting Customer Confidential Information
Need for Improved Critical Industrial Infrastructure Protection
Need for Improved Critical Industrial Infrastructure Protection
No National 'Stand Your Cyberground' Law Please
FCC Report on Google Street View Wi-Fi Data Snooping
Cloud Computing - Security Benefits and Risks

Recently uploaded (20)

PDF
20250805_A. Stotz All Weather Strategy - Performance review July 2025.pdf
PDF
Laughter Yoga Basic Learning Workshop Manual
PDF
Unit 1 Cost Accounting - Cost sheet
PDF
Katrina Stoneking: Shaking Up the Alcohol Beverage Industry
PDF
WRN_Investor_Presentation_August 2025.pdf
PDF
IFRS Notes in your pocket for study all the time
PDF
Dr. Enrique Segura Ense Group - A Self-Made Entrepreneur And Executive
PPTX
Dragon_Fruit_Cultivation_in Nepal ppt.pptx
PPTX
job Avenue by vinith.pptxvnbvnvnvbnvbnbmnbmbh
PPTX
AI-assistance in Knowledge Collection and Curation supporting Safe and Sustai...
PDF
Traveri Digital Marketing Seminar 2025 by Corey and Jessica Perlman
PPTX
ICG2025_ICG 6th steering committee 30-8-24.pptx
DOCX
unit 1 COST ACCOUNTING AND COST SHEET
PDF
Deliverable file - Regulatory guideline analysis.pdf
PPTX
HR Introduction Slide (1).pptx on hr intro
PDF
BsN 7th Sem Course GridNNNNNNNN CCN.pdf
PDF
Reconciliation AND MEMORANDUM RECONCILATION
PDF
MSPs in 10 Words - Created by US MSP Network
PPTX
The Marketing Journey - Tracey Phillips - Marketing Matters 7-2025.pptx
PPTX
New Microsoft PowerPoint Presentation - Copy.pptx
20250805_A. Stotz All Weather Strategy - Performance review July 2025.pdf
Laughter Yoga Basic Learning Workshop Manual
Unit 1 Cost Accounting - Cost sheet
Katrina Stoneking: Shaking Up the Alcohol Beverage Industry
WRN_Investor_Presentation_August 2025.pdf
IFRS Notes in your pocket for study all the time
Dr. Enrique Segura Ense Group - A Self-Made Entrepreneur And Executive
Dragon_Fruit_Cultivation_in Nepal ppt.pptx
job Avenue by vinith.pptxvnbvnvnvbnvbnbmnbmbh
AI-assistance in Knowledge Collection and Curation supporting Safe and Sustai...
Traveri Digital Marketing Seminar 2025 by Corey and Jessica Perlman
ICG2025_ICG 6th steering committee 30-8-24.pptx
unit 1 COST ACCOUNTING AND COST SHEET
Deliverable file - Regulatory guideline analysis.pdf
HR Introduction Slide (1).pptx on hr intro
BsN 7th Sem Course GridNNNNNNNN CCN.pdf
Reconciliation AND MEMORANDUM RECONCILATION
MSPs in 10 Words - Created by US MSP Network
The Marketing Journey - Tracey Phillips - Marketing Matters 7-2025.pptx
New Microsoft PowerPoint Presentation - Copy.pptx

MCGlobalTech Managed Security Compliance Program