Digitizing NRC 5.71: A Step Towards Seamless Compliance for the Nuclear Industry

Digitizing NRC 5.71: A Step Towards Seamless Compliance for the Nuclear Industry

Digitizing NRC 5.71: A Step Towards Seamless Compliance for the Nuclear Industry January 2, 2025 | By J. Travis Howerton Digitizing the NRC 5.71 Cyber Security Program in RegScale In an era where cyber threats are growing more sophisticated, organizations in regulated industries face increasing challenges in maintaining robust cybersecurity programs. For organizations under the…

Blog: The Hidden Costs of Manual GRC in a Cloud-First World

The Hidden Costs of Manual GRC in a Cloud-First World

The Hidden Costs of Manual GRC in a Cloud-First World October 30, 2024 | By J. Travis Howerton Rethinking GRC: Navigating Challenges in a Cloud-Native World Before I joined RegScale, I was a big buyer of legacy GRC tools. I won’t name any particular tools, but most of them featured 20-year-old approaches and “automation” in…

FedRAMP Loves Compliance as Code: Insights from the OMB’s Recent Memo

FedRAMP Loves Compliance as Code: Insights from the OMB’s Recent Memo

FedRAMP Loves Compliance as Code: Insights from the OMB’s Recent Memo July 26, 2024 | By J. Travis Howerton Today, July 26, 2024, the Office of Management and Budget (OMB) released a memo on their plans to modernize the FedRAMP program titled Modernizing the Federal Risk and Authorization Management Program (FedRAMP). This memorandum rescinds the Federal…

Thriving in 2030: The future of compliance and risk management

Thriving in 2030: The future of compliance and risk management

Thriving in 2030: The future of compliance and risk management June 18, 2024 | By J. Travis Howerton RegScale CEO Travis Howerton recently contributed an insightful byline to Security Magazine, “Thriving in 2030: The Future of Compliance and Risk Management.” This article details the future landscape of compliance and risk management as we approach 2030….

GRC + CCM, You Complete Me

GRC and CCM, You Complete Me

The reality is that GRC tools still serve a valuable function for compliance and risk, but the “how” they do it no longer works for most companies. What the world needs now is Continuous Controls Monitoring (CCM). The CCM approach extends beyond legacy GRC to provide real-time insights via automation, data-driven governance, and proactive risk mitigation.

RegScale Announces Support for the CISA Cross-Sector Cyber Security Performance Goals (CPG)

RegScale Announces Support for the CISA Cross-Sector Cyber Security Performance Goals (CPG)

As of February 2, 2023, RegScale has announced that we officially support the Cyber Security and Infrastructure Security Agency (CISA) CPG as a catalog within our platform with automated tools/wizards for building security plans for Critical Infrastructure Programs.