Register:Academy3 recordsSHA3-256 chainedhead
sha3:d4eddf0846408d6001ad4b3e80273541769fbfb244e3942f3eede09229a5fb6cIntactREC 0000HEADsha3-256
656c30224805d664297c543f9e3ba3df48e1b0e20b1386b50ac10567fc7f5c2cprev:05670038851cRegisterAcademy
The academy: long-form guides to CMMC and NIST 800-171
The academy holds the long-form guides: CMMC 2.0, NIST 800-171, cloud security for defense contractors, and why an alert is not a record. Each guide covers one subject end to end and is sealed on the date shown. Start here if the requirements are new to you; the blog carries the dated updates.
5 entries
REC 0001ENTRIESsha3-256
65a6274063460275066a7a9770d512d0cc906894ef9eb30c5d6b2837d757b1c2prev:656c30224805Guides, newest first
- What Is Autonomous Cloud Governance: The Complete GuideAutonomous cloud governance is the discipline of continuously detecting, deciding, and remediating cloud configuration, compliance, and cost issues without manual intervention.
- What Is Autonomous Remediation and Why Alerting Is Not EnoughAutonomous remediation is the capability to automatically detect, decide, and fix cloud infrastructure issues without human intervention for each event.
- Cloud Security for Defense Contractors: The Definitive GuideDefense contractors face unique cloud security requirements (CMMC, DFARS, ITAR, FedRAMP, and classified program constraints) that commercial cloud security tools weren't designed to address.
- The Complete Guide to CMMC 2.0 Compliance in 2026CMMC 2.0 is now enforced in DoD contracts.
- NIST 800-171 Compliance: From Manual Checklists to Autonomous EnforcementNIST SP 800-171 defines 110 security requirements for protecting Controlled Unclassified Information in non-federal systems.
REC 0002RELATED RECORDSsha3-256
d4eddf0846408d6001ad4b3e80273541769fbfb244e3942f3eede09229a5fb6cprev:65a627406346Related records
Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.
- proof.state
- Proof of State. What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- proof.change
- Proof of Change. Who or what altered the environment, under what authority, with before and after state hashes.
- proof.agency
- Proof of Agency. What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- architecture
- Architecture. How the chain is built and where it lives: inside your tenant, with no egress of evidence.
When the guide is read, inspect the record it describes.