In this episode of Federal Credit Fridays, Anthony Curcio resumes his conversation with Summit IT Manager Josh Baker about information security compliance. This session focuses on what happens when compliance challenges intersect with national security priorities, especially for organizations supporting federal programs and agencies
Compliance Landscape Changes
“The stakes are too high for the government, and specifically the Department of War,” Josh explains when discussing why information security compliance must continue to evolve. His point is that agencies cannot rely on verbal assurances or informal claims that a contractor is compliant. When organizations handle sensitive government data, support critical systems, or participate in federal programs, they must be able to prove their security practices meet required standards.
Implementing Change
In the final episode of the Information Security Compliance segment, Josh and Anthony discuss how the process of maintaining information security is changing for contractors and organizations that work with federal clients. Josh explains that “the shift is really coming from a third party,” meaning contractors may increasingly need to work with independent assessors who review whether their systems, policies, and procedures meet required compliance standards. As Josh notes, contractors will have to “actually go in and have some assessors” verify they are compliant. This creates a more evidence-based approach to compliance, where organizations must prepare to demonstrate what they are doing, how they are doing it, and whether their practices are consistent over time.
