{"id":5736,"date":"2025-02-27T16:19:51","date_gmt":"2025-02-27T20:19:51","guid":{"rendered":"https:\/\/solutionsreview.com\/security-information-event-management\/?p=5736"},"modified":"2025-02-28T16:20:58","modified_gmt":"2025-02-28T20:20:58","slug":"how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/","title":{"rendered":"How Protecting CUI Leads to a More Resilient Defense Industrial Base"},"content":{"rendered":"<p><a href=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2025\/02\/How-Protecting-CUI-Leads-to-a-More-Resilient-Defense-Industrial-Base.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium_large wp-image-5737\" src=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2025\/02\/How-Protecting-CUI-Leads-to-a-More-Resilient-Defense-Industrial-Base-768x384.jpg\" alt=\"How Protecting CUI Leads to a More Resilient Defense Industrial Base\" width=\"768\" height=\"384\" srcset=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2025\/02\/How-Protecting-CUI-Leads-to-a-More-Resilient-Defense-Industrial-Base-768x384.jpg 768w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2025\/02\/How-Protecting-CUI-Leads-to-a-More-Resilient-Defense-Industrial-Base-300x150.jpg 300w, https:\/\/solutionsreview.com\/security-information-event-management\/files\/2025\/02\/How-Protecting-CUI-Leads-to-a-More-Resilient-Defense-Industrial-Base.jpg 800w\" sizes=\"(max-width: 768px) 100vw, 768px\" \/><\/a><\/p>\n<p style=\"text-align: justify;\"><em><strong>Thomas Graham, the VP and CISO at <a href=\"https:\/\/redspin.com\/\" target=\"_blank\" rel=\"noopener\">Redspin<\/a>, explains how protecting CUI will lead to a more resilient defense industrial base. <span class=\"ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak\" dir=\"ltr\">This article originally appeared in\u00a0<a class=\"external\" href=\"https:\/\/insightjam.com\/feed\" target=\"_blank\" rel=\"noopener nofollow\">Insight Jam<\/a>, an enterprise IT community that enables human conversation on AI.<\/span><\/strong><\/em><\/p>\n<p style=\"text-align: justify;\">To fully appreciate the importance of Controlled Unclassified Information (CUI), it&#8217;s essential to understand its origins and significance. Unlike classified information, CUI is a designation of unclassified information used across all federal agencies, not just the Department of Defense (DoD). The objective was to create a standardized system to protect sensitive but unclassified information, ensuring it is handled with the appropriate level of security.<\/p>\n<p style=\"text-align: justify;\">With a foundational understanding of CUI&#8217;s purpose, it&#8217;s essential to explore the types of information classified under this designation. CUI is a broad category that includes a wide variety of information types. As identified by the <a href=\"https:\/\/www.epa.gov\/cui\/controlled-unclassified-information-cui-program-frequently-asked-questions-faqs\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">Environmental Protection Agency (EPA)<\/a>, these can include:<\/p>\n<ul style=\"text-align: justify;\">\n<li>Personally Identifiable Information (PII): Examples include full names, Social Security numbers, and credit card numbers<\/li>\n<li>Sensitive Personally Identifiable Information (SPII): This includes more sensitive details such as bank information, health records, and citizenship or immigration status<\/li>\n<li>Proprietary Business Information (PBI), currently known within the EPA as Confidential Business Information (CBI): Examples of this include financial data, trade secrets, product research and development, and product designs<\/li>\n<li>Unclassified Controlled Technical Information (UCTI): This category covers information such as operational plans, developing technologies, mission-essential equipment, and surveillance methods<\/li>\n<li>Sensitive but Unclassified (SBU):<\/li>\n<li>For Official Use Only (FOUO): This is a document designation, not a classification, used to indicate information or material that, while unclassified, may not be suitable for public release<\/li>\n<li>Law Enforcement Sensitive (LES): This includes information about investigative techniques, operational procedures, and details of ongoing investigations<\/li>\n<\/ul>\n<p style=\"text-align: justify;\">Given the broad scope of CUI, protecting this information becomes a priority\u2014especially as mishandling it can have far-reaching consequences. Managing CUI within contracts can be particularly challenging due to its diverse nature. A complete list of CUI types is available in the <a href=\"https:\/\/www.archives.gov\/cui\/registry\/category-list\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">National Archives and Records Administration (NARA) CUI registry<\/a>. An organization has a DoD contract or a flow-down requirement from a Prime Contractor, and specifics on handling CUI are identified in <a href=\"https:\/\/www.esd.whs.mil\/Portals\/54\/Documents\/DD\/issuances\/dodi\/520048p.PDF\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">DoDI 5200.48<\/a>. Typically, if contracts include a\u00a0<a href=\"https:\/\/www.acquisition.gov\/dfars\/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">DFARS 7012<\/a>\u00a0clause or references NIST SP 800-171, CUI handling requirements apply.<\/p>\n<p style=\"text-align: justify;\">Ensuring CUI is protected isn&#8217;t merely about adding layers of complexity\u2014it&#8217;s a vital measure to protect sensitive information integral to national security. Although CUI is unclassified, it encompasses data that, if mishandled, could expose critical assets or operations to adversaries. In today&#8217;s landscape, where sophisticated nation-state actors and cyber threats constantly evolve, these protections act as essential safeguards. CUI cybersecurity prevents unauthorized entities from exploiting vulnerabilities, helping to secure our defense infrastructure and the broader federal ecosystem against potential threats.<\/p>\n<p style=\"text-align: justify;\">To underscore the risks of mishandling CUI, real-world breaches reveal the impact that lapses in security can have on national security and financial stability. If CUI is mishandled, then this is a breach of information that could seriously affect operations, assets, or individuals from the federal government or those organizations that support the government.<\/p>\n<p style=\"text-align: justify;\">Specifically, mishandling this type of information can directly impact national security. For example, in 2015, due to a breach, <a href=\"https:\/\/www.industrialcybersecuritypulse.com\/networks\/throwback-attack-chinese-hackers-steal-plans-for-the-f-35-fighter-in-a-supply-chain-heist\/\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">China could develop a version of the U.S. F-35 fighter before the U.S.<\/a>The financial and tactical losses from the breach were significant.\u00a0<span style=\"box-sizing: border-box; margin: 0; padding: 0; text-align: left;\">Another example is the\u00a0<a href=\"https:\/\/www.washingtonpost.com\/news\/federal-eye\/wp\/2015\/07\/09\/hack-of-security-clearance-system-affected-21-5-million-people-federal-authorities-say\/\" target=\"_blank\" rel=\"noopener\">2015 OPM breach<\/a>, which exposed the personnel files of over four million government employees and the security investigation background info of over 20 million.<\/span>\u00a0The notification cost alone exceeded $350 million.<\/p>\n<p style=\"text-align: justify;\">Knowing that these breaches are possible and that their effects can be devastating, how can organizations working with the DoD\/government ensure they take the proper steps to protect CUI? The short answer is to implement <a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-171r2.pdf\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">NIST SP 800-171r2<\/a>\u00a0requirements. Start with an honest self-assessment of your scoped environment and objective implementation.<\/p>\n<p style=\"text-align: justify;\">After addressing internal issues, engage a Registered Provider Organization (RPO) or Certified Third-Party Assessor Organization (C3PAO) for a true Gap Assessment to see if your implementation meets CMMC assessment scrutiny. A third-party assessment ensures that the organization&#8217;s Policies and procedures, Training, Enforcement Mechanisms, and Monitoring are adequately in place.<\/p>\n<p style=\"text-align: justify;\">Understanding the type(s) of CUI in your environment is crucial. Basic CUI has different requirements than CUI Specified, such as &#8220;NOFORN&#8221; CUI, which restricts dissemination to non-U.S. persons or locations. Consult the <a href=\"https:\/\/www.archives.gov\/cui\/registry\/category-list\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">NARA CUI Registry<\/a>\u00a0and implement NIST SP 800-171r2 to ensure you follow the proper CUI guidelines.<\/p>\n<p style=\"text-align: justify;\">To identify and understand the information that needs to be protected, consult <a href=\"https:\/\/dodcio.defense.gov\/Portals\/0\/Documents\/CMMC\/Scope_Level2_V2.0_FINAL_20211202_508.pdf\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">the CMMC Level 2 scoping guide<\/a>.\u00a0<a href=\"https:\/\/dodcio.defense.gov\/Portals\/0\/Documents\/CMMC\/AG_Level2_MasterV2.0_FINAL_202112016_508.pdf\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">The CMMC Level 2 assessment guide<\/a> is the most important document for an organization to use when validating its CUI protections. This document outlines objectives for each practice, providing granularity on meeting adequacy and sufficiency requirements.<\/p>\n<p style=\"text-align: justify;\">While many contractors have already implemented these standards, CMMC is a program that validates compliance and ensures ongoing adherence to critical security measures. CMMC isn&#8217;t introducing new requirements; instead, it&#8217;s a validation that contractors adhere to standards they&#8217;ve been accountable to for years under DFARS and NIST 800-171.<\/p>\n<p style=\"text-align: justify;\">Since 2017, contractors have followed these guidelines designed to secure CUI across the defense supply chain. While the full costs of CMMC compliance are still emerging and vary from organization to organization, the shift from self-attestation to third-party validation is already beneficial for many contractors. By addressing CMMC requirements early, organizations avoid potential disruptions and gain a competitive advantage as trusted partners prioritize cybersecurity within the defense industrial base. This proactive approach aligns them with national security standards, positions them favorably for future contracts, and primes them for long-term resilience in a market where compliance is rapidly becoming non-negotiable.<\/p>\n<p style=\"text-align: justify;\">Organizations should use this CMMC L2 Assessment Guide Methodology for self-assessment as it is the &#8220;playbook&#8221; assessors will utilize. The guide&#8217;s Methods and Objects section suggests the specific evidence types assessors might request, using Examine, Interview, and Test modalities.<\/p>\n<p style=\"text-align: justify;\">Ultimately, whoever is responsible for implementation should undergo\u00a0<a href=\"https:\/\/training.redspin.com\/cmmc-ccp-training\/\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">Certified CMMC Professional (CCP) training<\/a>\u00a0to understand the CMMC Ecosystem, code of professional conduct, CMMC Assessment Process (CAP), scoping guide, and each of the 110 practices from an assessor and consultant perspective. They should also prioritize familiarizing themselves with the top 4 actionable steps that help to protect CUI, which include:<\/p>\n<ol>\n<li style=\"text-align: justify;\">Utilize available information: Know the different guides (<a href=\"https:\/\/cyberab.org\/Portals\/0\/Documents\/Process-Documents\/CMMC-Assessment-Process-CAP-v1.0.pdf\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">The CMMC Assessment Process (CAP),<\/a> Level 1, 2, and 3 scoping and assessment guides, etc.) and their contents.<\/li>\n<li style=\"text-align: justify;\">Be honest: Realistically assess your practices and report to leadership. It&#8217;s easier to address issues before failing an assessment.<\/li>\n<li style=\"text-align: justify;\">Recognize that CMMC is not the implementation requirement: DFARS 7012 is, and you&#8217;ve been accountable for it for years. Not realizing this can lead to <a href=\"https:\/\/www.justice.gov\/usao-ndga\/pr\/georgia-tech-and-georgia-tech-research-corporation-pay-90000-resolve-allegations\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">False Claims Act Allegations<\/a>, regardless of your organization&#8217;s size and type.<\/li>\n<li style=\"text-align: justify;\">Identify CUI: Determine where CUI exists in your environment. Correctly identifying CUI helps define dissemination requirements and scope the boundary.<\/li>\n<li style=\"text-align: justify;\">Confine and protect CUI: Ensure that Controlled Unclassified Information (CUI) is confined within designated areas of your organization and that it is safeguarded according to established security protocols.<\/li>\n<\/ol>\n<p style=\"text-align: justify;\">By thoroughly understanding and implementing the guidelines and requirements for protecting CUI, organizations can significantly enhance their security posture and ensure compliance with federal mandates. The importance of CUI protection cannot be overstated, as mishandling this information can lead to severe consequences, including national security threats and substantial financial losses. Ultimately, by embracing best practices and fostering a culture of security, organizations can meet compliance requirements and build trust with their federal partners and stakeholders, contributing to a more secure and resilient defense industrial base.<\/p>\n<hr \/>\n<p style=\"text-align: justify;\">\n","protected":false},"excerpt":{"rendered":"<p>Thomas Graham, the VP and CISO at Redspin, explains how protecting CUI will lead to a more resilient defense industrial base. This article originally appeared in\u00a0Insight Jam, an enterprise IT community that enables human conversation on AI. To fully appreciate the importance of Controlled Unclassified Information (CUI), it&#8217;s essential to understand its origins and significance. [&hellip;]<\/p>\n","protected":false},"author":1245,"featured_media":5737,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[551],"tags":[2183,322,2614,2615,2616],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How Protecting CUI Leads to a More Resilient Defense Industrial Base<\/title>\n<meta name=\"description\" content=\"Thomas Graham, the VP and CISO at Redspin, explains how protecting CUI will lead to a more resilient defense industrial base.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How Protecting CUI Leads to a More Resilient Defense Industrial Base\" \/>\n<meta property=\"og:description\" content=\"Thomas Graham, the VP and CISO at Redspin, explains how protecting CUI will lead to a more resilient defense industrial base.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/\" \/>\n<meta property=\"og:site_name\" content=\"SIEM Tools &amp; Security Event Management | Solutions Review\" \/>\n<meta property=\"article:published_time\" content=\"2025-02-27T20:19:51+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-02-28T20:20:58+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2025\/02\/How-Protecting-CUI-Leads-to-a-More-Resilient-Defense-Industrial-Base.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Thomas Graham\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Thomas Graham\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/\",\"name\":\"How Protecting CUI Leads to a More Resilient Defense Industrial Base\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2025\/02\/How-Protecting-CUI-Leads-to-a-More-Resilient-Defense-Industrial-Base.jpg\",\"datePublished\":\"2025-02-27T20:19:51+00:00\",\"dateModified\":\"2025-02-28T20:20:58+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/0344e439625e3e4c8677f43fd9a4dbe1\"},\"description\":\"Thomas Graham, the VP and CISO at Redspin, explains how protecting CUI will lead to a more resilient defense industrial base.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2025\/02\/How-Protecting-CUI-Leads-to-a-More-Resilient-Defense-Industrial-Base.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2025\/02\/How-Protecting-CUI-Leads-to-a-More-Resilient-Defense-Industrial-Base.jpg\",\"width\":800,\"height\":400,\"caption\":\"How Protecting CUI Leads to a More Resilient Defense Industrial Base\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/security-information-event-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How Protecting CUI Leads to a More Resilient Defense Industrial Base\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/\",\"name\":\"SIEM Tools &amp; Security Event Management | Solutions Review\",\"description\":\"Evaluating Enterprise SIEM Systems, Log Management Analytics &amp; SOAR Platforms.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/security-information-event-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/0344e439625e3e4c8677f43fd9a4dbe1\",\"name\":\"Thomas Graham\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2025\/02\/thomas-graham-headshot-scaled.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2025\/02\/thomas-graham-headshot-scaled.jpg\",\"caption\":\"Thomas Graham\"},\"description\":\"With more than 15 years of experience in the Information Technology (IT) and Information Security (IS) professions with strong expertise in building IT Management and IT Security Management functions, Thomas has demonstrated his expertise in establishing, developing, and implementing IT Security programs and compliance initiatives. He's designed, implemented, and oversaw automated tool-based security implementations for continuous monitoring and zero-trust initiatives, and performed evaluation and selection of multiple tool suites to include compensating controls to address risk-based mitigation decisions.\u00a0\",\"sameAs\":[\"https:\/\/redspin.com\/\"],\"url\":\"https:\/\/solutionsreview.com\/security-information-event-management\/author\/tgraham\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How Protecting CUI Leads to a More Resilient Defense Industrial Base","description":"Thomas Graham, the VP and CISO at Redspin, explains how protecting CUI will lead to a more resilient defense industrial base.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/","og_locale":"en_US","og_type":"article","og_title":"How Protecting CUI Leads to a More Resilient Defense Industrial Base","og_description":"Thomas Graham, the VP and CISO at Redspin, explains how protecting CUI will lead to a more resilient defense industrial base.","og_url":"https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/","og_site_name":"SIEM Tools &amp; Security Event Management | Solutions Review","article_published_time":"2025-02-27T20:19:51+00:00","article_modified_time":"2025-02-28T20:20:58+00:00","og_image":[{"width":800,"height":400,"url":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2025\/02\/How-Protecting-CUI-Leads-to-a-More-Resilient-Defense-Industrial-Base.jpg","type":"image\/jpeg"}],"author":"Thomas Graham","twitter_misc":{"Written by":"Thomas Graham","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/","url":"https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/","name":"How Protecting CUI Leads to a More Resilient Defense Industrial Base","isPartOf":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2025\/02\/How-Protecting-CUI-Leads-to-a-More-Resilient-Defense-Industrial-Base.jpg","datePublished":"2025-02-27T20:19:51+00:00","dateModified":"2025-02-28T20:20:58+00:00","author":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/0344e439625e3e4c8677f43fd9a4dbe1"},"description":"Thomas Graham, the VP and CISO at Redspin, explains how protecting CUI will lead to a more resilient defense industrial base.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/#primaryimage","url":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2025\/02\/How-Protecting-CUI-Leads-to-a-More-Resilient-Defense-Industrial-Base.jpg","contentUrl":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2025\/02\/How-Protecting-CUI-Leads-to-a-More-Resilient-Defense-Industrial-Base.jpg","width":800,"height":400,"caption":"How Protecting CUI Leads to a More Resilient Defense Industrial Base"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/how-protecting-cui-leads-to-a-more-resilient-defense-industrial-base\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/security-information-event-management\/"},{"@type":"ListItem","position":2,"name":"How Protecting CUI Leads to a More Resilient Defense Industrial Base"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#website","url":"https:\/\/solutionsreview.com\/security-information-event-management\/","name":"SIEM Tools &amp; Security Event Management | Solutions Review","description":"Evaluating Enterprise SIEM Systems, Log Management Analytics &amp; SOAR Platforms.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/security-information-event-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/0344e439625e3e4c8677f43fd9a4dbe1","name":"Thomas Graham","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/security-information-event-management\/#\/schema\/person\/image\/","url":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2025\/02\/thomas-graham-headshot-scaled.jpg","contentUrl":"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2025\/02\/thomas-graham-headshot-scaled.jpg","caption":"Thomas Graham"},"description":"With more than 15 years of experience in the Information Technology (IT) and Information Security (IS) professions with strong expertise in building IT Management and IT Security Management functions, Thomas has demonstrated his expertise in establishing, developing, and implementing IT Security programs and compliance initiatives. He's designed, implemented, and oversaw automated tool-based security implementations for continuous monitoring and zero-trust initiatives, and performed evaluation and selection of multiple tool suites to include compensating controls to address risk-based mitigation decisions.\u00a0","sameAs":["https:\/\/redspin.com\/"],"url":"https:\/\/solutionsreview.com\/security-information-event-management\/author\/tgraham\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts\/5736"}],"collection":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/users\/1245"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/comments?post=5736"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/posts\/5736\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/media\/5737"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/media?parent=5736"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/categories?post=5736"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/security-information-event-management\/wp-json\/wp\/v2\/tags?post=5736"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}