6 papers
Assessor Experiences in CMMC Level 2 Certification Assessments: An Interpretative Phenomenological Analysis of Role Expectations
Samuel Heuchert, John Hastings
The Cybersecurity Maturity Model Certification program requires third-party assessments be conducted under a non-consultative model. The model is intended to ensure impartiality fo…
The Need for Standardized Evidence Sampling in CMMC Assessments: A Survey-Based Analysis of Assessor Practices
Logan Therrien, John Hastings
The Cybersecurity Maturity Model Certification (CMMC) framework provides a common standard for protecting sensitive unclassified information in defense contracting. While CMMC defi…
Weak Enforcement and Low Compliance in PCI DSS: A Comparative Security Study
Soonwon Park, John D. Hastings
Although credit and debit card data continue to be a prime target for attackers, organizational adherence to the Payment Card Industry Data Security Standard (PCI DSS) remains surp…
Toward Secure and Compliant AI: Organizational Standards and Protocols for NLP Model Lifecycle Management
Sunil Arora, John Hastings
Natural Language Processing (NLP) systems are increasingly used in sensitive domains such as healthcare, finance, and government, where they handle large volumes of personal and re…
Securing Agentic AI Systems -- A Multilayer Security Framework
Sunil Arora, John Hastings
Securing Agentic Artificial Intelligence (AI) systems requires addressing the complex cyber risks introduced by autonomous, decision-making, and adaptive behaviors. Agentic AI syst…
Quantifying Return on Security Controls in LLM Systems
Richard Helder Moulton, Austin O'Brien, John D. Hastings
Although large language models (LLMs) are increasingly used in security-critical workflows, practitioners lack quantitative guidance on which safeguards are worth deploying. This p…