Kelly Hood

826 posts

Kelly Hood banner
Kelly Hood

Kelly Hood

@KellyHood_

CISSP, CDPSE, CMMC RP, EVP & Cybersecurity Engineer @OpticCyber_ helping organizations #ManageTheRisk

Maryland, USA Katılım Mart 2019
163 Takip Edilen123 Takipçiler
Kelly Hood
Kelly Hood@KellyHood_·
Give everyone access to everything… and suddenly nothing feels important. A little friction keeps your data from ending up everywhere. Everyone *probably* doesn't need access to everything. #OpticCyber
Kelly Hood tweet media
English
0
0
1
5
Kelly Hood retweetledi
Cybersecurity @ NIST
Cybersecurity @ NIST@NISTcyber·
📢NEW @NIST Blog: Celebrating 2⃣ Years of #CSF 2.0! The CSF 2.0 has been widely embraced by millions of orgs of all sizes & sectors around the globe & continues to be the most downloaded NIST technical publication... nist.gov/blogs/cybersec…
Cybersecurity @ NIST tweet media
English
5
11
30
7.2K
Kelly Hood retweetledi
Tom Conkle
Tom Conkle@TomConkle·
New DoD CIO #CMMC FAQ update! If #CUI is handled only in hardcopy and never processed, stored, or transmitted on your systems, a CMMC L2 assessment is not required. If you are the one printing it, the system printing CUI requires CMMC. FAQs: dowcio.war.gov/Portals/0/Docu…
Tom Conkle tweet media
English
0
1
0
28
Kelly Hood
Kelly Hood@KellyHood_·
Most people don’t wake up and decide to become an insider threat. They make a quick decision. They move too fast. And sometimes that’s all it takes.... If you need a starting point, DCSA offers free Insider Threat Awareness training 👇 securityawareness.dcsa.mil/itawareness/in… #OpticCyber
Kelly Hood tweet media
English
0
1
0
20
Kelly Hood retweetledi
Tom Conkle
Tom Conkle@TomConkle·
An SSP isn’t just a compliance document. It’s a management tool for governing security. It ties together people, processes, and technology, enabling risk decisions and stronger cybersecurity long after the assessment is over. Reach out if you want to get more from your SSP.
Tom Conkle tweet media
English
2
2
0
25
Kelly Hood retweetledi
Optic Cyber Solutions
Optic Cyber Solutions@OpticCyber_·
Incident response is more than just a plan on paper. It needs to be something you can put into action. Check out this video to learn how to weave incident response throughout the entire cybersecurity program 👇 youtu.be/aA2ldOeqycA
YouTube video
YouTube
Optic Cyber Solutions tweet media
English
0
1
1
9
Kelly Hood
Kelly Hood@KellyHood_·
Last week @TomConkle & I had a conversation on a #ShadowTrace webinar about #CMMC (surprise, surprise). One theme came up again and again: It’s not enough to do the right things. You have to be able to PROVE it too! #OpticCyber
Kelly Hood tweet media
English
0
1
0
15
Kelly Hood retweetledi
Tom Conkle
Tom Conkle@TomConkle·
Can encryption alone create logical separation for #CMMC? Short answer: No. Per DoD C-Q11, separation between #CUI and non-CUI must be physical or logical. Encryption protects data, but it does not create scope separation. FAQs: dowcio.war.gov/Portals/0/Docu…
Tom Conkle tweet media
English
0
1
0
15
Kelly Hood retweetledi
Optic Cyber Solutions
Optic Cyber Solutions@OpticCyber_·
Progress in cybersecurity rarely comes from tools alone. It comes from conversations, collaboration, & a willingness to ask hard questions. We’re grateful for the leaders, partners, & practitioners who leaned into the complexity instead of avoiding it! Thanks for a great 2025!
Optic Cyber Solutions tweet media
English
0
1
1
12
Kelly Hood retweetledi
Tom Conkle
Tom Conkle@TomConkle·
New #CMMC FAQ C-Q12 clarifies enclave scoping: Enterprise network components are not automatically in scope if a CUI enclave has no direct internet connection. With proper logical separation and encryption, the corporate network can be used. FAQs: dowcio.war.gov/Portals/0/Docu…
Tom Conkle tweet media
English
0
1
0
13
Kelly Hood
Kelly Hood@KellyHood_·
Incident response is more than just a plan on paper. It needs to be something you can put into action. For an overview, check out this video sharing how to weave incident response throughout your program using NIST SP 800-61! Linked here 👇 youtu.be/aA2ldOeqycA #OpticCyber
YouTube video
YouTube
Kelly Hood tweet media
English
0
0
1
10
Kelly Hood
Kelly Hood@KellyHood_·
New #CMMC FAQs dropped! ◾ Hardcopy-only CUI does NOT require a CMMC Level 2 assessment ◾ Encryption alone does NOT create logical separation ◾ Properly designed enclaves do NOT automatically pull the enterprise network into scope FAQs linked here 👇 dowcio.war.gov/Portals/0/Docu…
Kelly Hood tweet media
English
0
1
0
18
Kelly Hood
Kelly Hood@KellyHood_·
Did you see that last month #NIST released a draft of the Cyber AI Profile? Instead of creating a whole new framework, NIST mapped AI risks to familiar #CSF outcomes making it easier to talk about AI. Cyber AI Profile 👇 nvlpubs.nist.gov/nistpubs/ir/20… Be sure to check it out!
Kelly Hood tweet media
English
0
0
0
12
Kelly Hood
Kelly Hood@KellyHood_·
As the year wraps up, I’ve been thinking about how grateful I am for the people I’ve had the chance to work with. Thank you to everyone who trusted us, challenged us, and collaborated with us this year! 😊
Kelly Hood tweet media
English
0
0
0
10
Kelly Hood
Kelly Hood@KellyHood_·
“We’ll circle back after the holidays.” Sound familiar? This time of year makes it obvious how much security work only happens when someone remembers to do it. Check out #OpticCyber's CMMC Progress Tracker to organize your thoughts! 👇 43828014.hs-sites.com/cmmc-l2-progre…
Kelly Hood tweet media
English
0
0
0
0
Kelly Hood
Kelly Hood@KellyHood_·
It’s hard to know who does what in #CMMC when you're just starting out. If you’ve ever wished for a simple way to sort out the players, you’re not alone. If you’re staring at acronyms wondering what they mean, this video is for you! 👇 youtu.be/szZeUzVizXU #OpticCyber
YouTube video
YouTube
Kelly Hood tweet media
English
0
0
0
13