Podcast

Federal Credit Fridays: Information Security Compliance (part 3 of 3)

Written by Anthony Curcio | 8/7/26, 3:30 PM

Welcome to Federal Credit Fridays! The U.S. government is one of the largest lenders and credit guarantors on earth. Its portfolio is estimated at over $3.6 trillion, as measured by loan assets and the face value of loan guarantees. The government uses credit for a wide variety of policy missions, including housing, higher education, small businesses, rural and urban economic development, infrastructure, and export promotion, among others. This podcast will familiarize you with the vast world of federal credit, the similarities and differences between these programs, and the importance of their work to achieving policy missions within the framework of public-private collaboration.

Federal Credit Fridays: Information Security Compliance (part 3 of 3) 

In this episode of Federal Credit Fridays, Anthony Curcio resumes his conversation with Summit IT Manager Josh Baker about information security compliance. This session focuses on what happens when compliance challenges intersect with national security priorities, especially for organizations supporting federal programs and agencies

Compliance Landscape Changes 

“The stakes are too high for the government, and specifically the Department of War,” Josh explains when discussing why information security compliance must continue to evolve. His point is that agencies cannot rely on verbal assurances or informal claims that a contractor is compliant. When organizations handle sensitive government data, support critical systems, or participate in federal programs, they must be able to prove their security practices meet required standards.

Implementing Change

In the final episode of the Information Security Compliance segment, Josh and Anthony discuss how the process of maintaining information security is changing for contractors and organizations that work with federal clients. Josh explains that “the shift is really coming from a third party,” meaning contractors may increasingly need to work with independent assessors who review whether their systems, policies, and procedures meet required compliance standards. As Josh notes, contractors will have to “actually go in and have some assessors” verify they are compliant. This creates a more evidence-based approach to compliance, where organizations must prepare to demonstrate what they are doing, how they are doing it, and whether their practices are consistent over time.

* Accessibility note: Click here for a text transcript of this conversation.