1 min read

Navigating Cyber Risk: Mimecast’s Strategy for GovRAMP Compliance

Navigating Cyber Risk: Mimecast’s Strategy for GovRAMP Compliance

Why did your organization become a GovRAMP member?

Mimecast chose to become a GovRAMP member because we want to help public sector organizations reduce cyber risk. We help close security and continuity gaps by defending against the biggest sources of cyber risk. We have a dedicated team of professionals solely focused on helping public sector organizations work protected.

What advice do you have for other providers progressing through the GovRAMP process?

  • For first-timers, allow more time for the audit because the level of assurance is higher than that of SOC2. Think of it more as a marathon rather than a sprint.
  • Manage expectations internally to get ahead of things and partner with relevant subject matter experts in the business as early as possible (i.e. CISO, Product and Engineering).
  • Establish a good working relationship with your 3PAO as they are a huge part of your assessment and learning journey.

Please share any specific challenges or lessons learned from your GovRAMP journey.

Mimecast was ahead of the game with our well-established and innovative consolidated audit program for external assurance. However, there were upgrades we needed to make to meet higher standards such as:

  • The GovRAMP audit process sets a high bar for the required technical detail of evidence collected during continuous monitoring.
  • 3PAO auditors are technically competent information security professionals, so we had to prepare for detailed examinations of how our cloud platforms were configured, and a deep dive into our code base.
  • We augmented our internal training program for our auditors to include hands-on technical mentoring, with Product and Engineering, on how our products and services are designed and built.

 

About Mimecast

Since 2003, Mimecast has empowered over 40,000 customers to mitigate risk and manage complexities across a threat landscape driven by malicious cyberattacks, human error, and technology fallibility. Their advanced solutions provide proactive threat detection, brand protection, awareness training, and data retention capabilities workplaces need today. Mimecast transforms email and collaboration security into the eyes and ears of organizations worldwide.

Understanding Threats and Vulnerabilities in Government Cybersecurity

Understanding Threats and Vulnerabilities in Government Cybersecurity

In cybersecurity, especially in the public sector, clarity matters. Terms like “threat” and “vulnerability” are often used interchangeably, but they...

Read More
What Is Risk—And Why It Matters in Cybersecurity Risk Management for Government

What Is Risk—And Why It Matters in Cybersecurity Risk Management for Government

Risk isn’t just a technical concern. For both public and private sector organizations, it's a strategic consideration tied directly to trust,...

Read More
HRTec: Enabling Secure Government Infrastructure with GovRAMP

HRTec: Enabling Secure Government Infrastructure with GovRAMP

HRTec has long supported public sector organizations through its secure, scalable FedHIVE platform and Compliance as a Service model. As a GovRAMP...

Read More
Scinary Cybersecurity: Aligning with State Standards through GovRAMP Membership

Scinary Cybersecurity: Aligning with State Standards through GovRAMP Membership

Why did your organization become a GovRAMP member? During the course of moving to our cloud model, we want to make sure that we comply with federal...

Read More
Splunk: Elevating Security and Resilience for Government with GovRAMP

Splunk: Elevating Security and Resilience for Government with GovRAMP

Why did your organization decide to become a GovRAMP member? At Splunk, we place a high priority on the security needs of our government customers...

Read More
Innovative Driven: Elevating Data Management and Cybersecurity for State Agencies

Innovative Driven: Elevating Data Management and Cybersecurity for State Agencies

Why did your organization become a GovRAMP member? We saw the opportunity to leverage our extensive experience supporting federal agencies in the...

Read More