GRC Is Changing | What You MUST Learn to Stay Competitive (SCA-R Explains)
Tech Woke19 Marras 2025

GRC Is Changing | What You MUST Learn to Stay Competitive (SCA-R Explains)

RMF Academy: https://www.rmfacademy.io/


Please Rate the Podcast: https://ratethispodcast.com/techwoke


Time stamps:


00:00 "Prime Time, Giving, and Growth"


04:06 Security Control Assessor Role


07:27 System Validation and Risk Assessment


11:07 "Understanding ATO Packages"


14:57 "Navigating Stakeholder-Driven Decision Making"


18:08 Cloud Service Models & FedRAMP Overview


19:01 FedRAMP Cloud Service Process


24:52 "Izzo Navy Certification Path"


26:48 Staying Relevant in Tech Industry


30:28 "Leadership and RMF Trends"


33:09 “SBOM, DevSecOps, and Cloud”


36:51 "AI: Amplifier, Not Replacer"


39:42 "Zero Trust Overview Simplified"


44:41 "Struggling to Give Back"


45:06 Gratitude for Shared Wisdom


Video Decription:


Welcome back to the Tech Woke Podcast. In this episode, host Christopher Okpala sits down with Dominique Richardson, a Security Control Assessor Representative (SCA-R), to break down one of the most misunderstood roles in the Risk Management Framework (RMF) ecosystem.


If you’ve ever worked with federal information systems, struggled through a security authorization package, or tried to understand what really happens during the validation phase, this conversation will give you clarity you won’t find in certification books.


Dominique walks through what SCA-Rs actually do during control assessments, including:


• Validating system security plans (SSPs), POA&Ms, and security assessment reports

• Reviewing control families across NIST SP 800-53

• Interpreting CCIs, STIG findings, and vulnerability scan outputs

• Evaluating system boundaries and cloud inheritances

• Identifying major changes that trigger reauthorization

• Advising AOs and ISSOs during the authorization decision


We also dig into the real politics behind RMF—how programs push for ATO with Conditions, why clean ATOs are rare, and why continuous monitoring is where the real work happens.


Dominique breaks down why the future of cyber compliance is shifting quickly:


• Cloud migrations often require full ATO reauthorization

• SBOMs and software supply chain oversight are becoming essential

• GRC analysts must understand architecture, not just documentation

• AI is amplifying top performers

• DevSecOps pipelines are redefining compliance evidence


Whether you're transitioning into cybersecurity, already supporting government systems, or preparing for roles like ISSO, Validator, Assessor, or System Owner, this episode provides real-world insights you won’t hear in certification training.


This conversation also includes a segment from RMF Academy, where Christopher shares how his own journey inspired him to teach the practical execution side of compliance.


If you want to understand RMF categorization, selection, implementation, assessment, authorization, and continuous monitoring this episode is a must-watch.


Watch now and take notes. GRC is changing fast.


#RMF #Cybersecurity #GRC

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(82)

How to Become a Senior ISSO in 12 Months (Complete Roadmap)

How to Become a Senior ISSO in 12 Months (Complete Roadmap)

🚨 Want to break into DoD cybersecurity but don't have eMASS experience? Gain hands on experience with RMF Academy eMASS Lab Access and build the confidence employers are looking for. Link below 👇htt...

29 Heinä 55min

This Cybersecurity Career Path Is About to Explode (Here's Why)

This Cybersecurity Career Path Is About to Explode (Here's Why)

🚨 Want to break into DoD cybersecurity but don't have eMASS experience? Gain hands on experience with RMF Academy eMASS Lab Access and build the confidence employers are looking for. Link below 👇htt...

22 Heinä 48min

The Only Place to Practice Real RMF Before You Get the Job

The Only Place to Practice Real RMF Before You Get the Job

Check out RMF Lab: https://rmfpro.ai/🚨 Want to break into DoD cybersecurity but don't have eMASS experience? Gain hands on experience with RMF Academy eMASS Lab Access and build the confidence employ...

10 Heinä 55min

How to Get Hired as a Cloud Engineer in 2026 (Step-by-Step Roadmap)

How to Get Hired as a Cloud Engineer in 2026 (Step-by-Step Roadmap)

RMF Academy: https://www.rmfacademy.io/Free Break into cybersecurity guide: https://www.rmfacademy.io/products/digital_downloads/breaking-into-cybersecurityDecription:In this episode of the Tech Woke ...

17 Kesä 53min

How to Break Into FedRAMP & Cloud Compliance in 2026

How to Break Into FedRAMP & Cloud Compliance in 2026

RMF Academy: https://www.rmfacademy.io/Timestamps:00:00 Intro01:18 From NSA Engineer to Cybersecurity Entrepreneur02:12 How Ajay Got Started in RMF03:30 Building a FedRAMP Business04:06 Starting a Cyb...

10 Kesä 54min

How to Build a Successful Business in Tech Without a Huge Team

How to Build a Successful Business in Tech Without a Huge Team

RMF Academy: https://www.rmfacademy.io/Timestamps:00:00 Introduction & Meet Richard Tarity00:53 From Warehouse Worker to Tech Entrepreneur02:30 Breaking Into the Technology Industry03:21 Why Companies...

3 Kesä 46min

GRC vs RMF Explained: Which Cybersecurity Path Should You Learn?

GRC vs RMF Explained: Which Cybersecurity Path Should You Learn?

RMF Academy: https://www.rmfacademy.io/Trying to break into cybersecurity but confused about GRC vs RMF?Everybody online says “get into GRC,” but most people never explain how different these paths ac...

23 Touko 58min

The Future of Cybersecurity Compliance (RMF Explained)

The Future of Cybersecurity Compliance (RMF Explained)

RMF Academy: https://www.rmfacademy.io/Video Description:Cybersecurity compliance is changing fast.AI, cloud computing, automation, DevSecOps, and continuous monitoring are reshaping what RMF and comp...

17 Touko 1h 46min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
aikalisa
politiikan-puskaradio
ootsa-kuullut-tasta-2
rss-ootsa-kuullut-tasta
otetaan-yhdet
rss-vaalirankkurit-podcast
rss-podme-livebox
rss-seksicast
tervo-halme
aihe
rss-raha-talous-ja-politiikka
rss-asiastudio
rikosmyytit
the-ulkopolitist
rss-vain-talouselamaa
rss-voi-venaja
rss-ulkopoditiikkaa
rss-50100-podcast
rss-diet-woke