Continuous Compliance in the Microsoft Cloud
John Igbokwe John Igbokwe

Continuous Compliance in the Microsoft Cloud

This blog post explores the critical steps organizations in the Defense and Space sectors must take to achieve CMMC compliance within the Microsoft Cloud environment. It outlines practical strategies to navigate regulatory requirements, enhance cybersecurity posture, and streamline the certification process, ensuring readiness for government contracts while safeguarding sensitive data.

Read More
Compliance Is What You Prove. Security Is What You Live.
John Igbokwe John Igbokwe

Compliance Is What You Prove. Security Is What You Live.

Compliance is what you prove. Security is what you live. Continuous Monitoring (ConMon) bridges the gap between the two by providing ongoing visibility into the health, security, and compliance posture of your Microsoft 365 environment. In the article below, I explore how organizations can leverage the Entra ID Security Configuration Analyzer, CISA SCuBA, and Azure Automation to build a practical and effective Continuous Monitoring strategy. These tools do more than validate compliance requirements. They help identify configuration drift, strengthen security controls, and maintain awareness of changes that could impact the organization's risk posture. Because in cybersecurity, visibility is resilience.

Read More
What NIST 800-63B Says About Multi-Factor Authentication
John Igbokwe John Igbokwe

What NIST 800-63B Says About Multi-Factor Authentication

Many organizations assume multi-factor authentication requires a separate code, token, or authentication app. However, NIST 800-63B explicitly recognizes TPM-backed cryptographic authenticators, such as Windows Hello for Business, as valid multi-factor authentication when protected by a PIN or biometric factor. Understanding what the standard actually says can help organizations align identity security practices with both NIST guidance and CMMC requirements.

Read More
Configuring Windows Hello for Business Securely
John Igbokwe John Igbokwe

Configuring Windows Hello for Business Securely

Windows Hello for Business provides a secure, passwordless authentication experience built on TPM-backed cryptographic keys and user verification through a PIN or biometric. Learn how to configure WHfB to align with NIST SP 800-63B guidance, strengthen identity protection, secure privileged access, and support Microsoft 365 and CMMC security best practices.

Read More
CMMC Asset Categories
John Igbokwe John Igbokwe

CMMC Asset Categories

Understanding CMMC asset categories is essential for defining assessment scope, reducing compliance costs, and preparing for a successful C3PAO assessment. Learn how CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets influence your System Security Plan (SSP), assessment boundary, and overall compliance strategy.

Read More