Understanding Threats and Vulnerabilities in Government Cybersecurity
In cybersecurity, especially in the public sector, clarity matters. Terms like “threat” and “vulnerability” are often used interchangeably, but they...
In Committee Corner, we spotlight the dedicated individuals driving GovRAMP's mission. This month, we’re featuring Josh Kadrmas, a Cyber Risk Analyst Team Lead for North Dakota Information Technology (NDIT) and a member of the GovRAMP Approvals Committee. With over 18 years of experience in the State of North Dakota, including roles as an Information Security Officer and now leading NDIT’s cyber risk management team, Josh brings a wealth of knowledge and expertise to the table. His work ensures that service providers meet stringent security and privacy controls, bolstering the integrity of the GovRAMP authorization process. In this interview, Josh shares what motivated him to join the Approvals Committee, the rewarding moments he’s experienced, and his passion for advancing cybersecurity in the public sector.
____________________________________________________________________________________________________________________
I have been a committee member for over a year and our state has been associated with GovRAMP for nearly two years.
As an Approvals committee member, the journey has been enlightening to experience the great responsibility we have to properly vet security and privacy controls before a service provider is granted authorization. I’m thrilled to see all of us working together to bolster our nation’s cyber defenses – after all, cybersecurity is a shared responsibility!
I was curious to see first-hand the process of approving service providers and knowing our committee’s work and review is the last stop in the process for the service organization before they are approved.
It’s rewarding to know the service providers we approve are making technological advances for so many people and doing so in a secure way with privacy principles embedded within their products. For any providers we haven’t approved, they have been mostly minor items that needed clarification with quick remediation, which is a testament they are more than a service provider: they are a partner that government entities can trust to ensure data security and availability is paramount.
In cybersecurity, especially in the public sector, clarity matters. Terms like “threat” and “vulnerability” are often used interchangeably, but they...
Risk isn’t just a technical concern. For both public and private sector organizations, it's a strategic consideration tied directly to trust,...
HRTec has long supported public sector organizations through its secure, scalable FedHIVE platform and Compliance as a Service model. As a GovRAMP...
In this month’s Committee Corner, we’re excited to feature Siddique Chaudhry, Sr. Manager of Global Public Sector Compliance at Snowflake and a...
This month’s Committee Corner highlights Naomi Ward, an expert in Third Party Risk Management for the Commonwealth of Massachusetts and an active...
In this month’s Committee Corner, we’re proud to introduce Mase Izadjoo, Chief Information Security Officer at Earthling Security and a valued member...