• ClipSaver
  • dtub.ru
ClipSaver
Русские видео
  • Смешные видео
  • Приколы
  • Обзоры
  • Новости
  • Тесты
  • Спорт
  • Любовь
  • Музыка
  • Разное
Сейчас в тренде
  • Фейгин лайф
  • Три кота
  • Самвел адамян
  • А4 ютуб
  • скачать бит
  • гитара с нуля
Иностранные видео
  • Funny Babies
  • Funny Sports
  • Funny Animals
  • Funny Pranks
  • Funny Magic
  • Funny Vines
  • Funny Virals
  • Funny K-Pop

From Checklists to Code: Engineering the Future of FedRAMP w/ Pete Waterman скачать в хорошем качестве

From Checklists to Code: Engineering the Future of FedRAMP w/ Pete Waterman 3 недели назад

скачать видео

скачать mp3

скачать mp4

поделиться

телефон с камерой

телефон с видео

бесплатно

загрузить,

Не удается загрузить Youtube-плеер. Проверьте блокировку Youtube в вашей сети.
Повторяем попытку...
From Checklists to Code: Engineering the Future of FedRAMP w/ Pete Waterman
  • Поделиться ВК
  • Поделиться в ОК
  •  
  •  


Скачать видео с ютуб по ссылке или смотреть без блокировок на сайте: From Checklists to Code: Engineering the Future of FedRAMP w/ Pete Waterman в качестве 4k

У нас вы можете посмотреть бесплатно From Checklists to Code: Engineering the Future of FedRAMP w/ Pete Waterman или скачать в максимальном доступном качестве, видео которое было загружено на ютуб. Для загрузки выберите вариант из формы ниже:

  • Информация по загрузке:

Скачать mp3 с ютуба отдельным файлом. Бесплатный рингтон From Checklists to Code: Engineering the Future of FedRAMP w/ Pete Waterman в формате MP3:


Если кнопки скачивания не загрузились НАЖМИТЕ ЗДЕСЬ или обновите страницу
Если возникают проблемы со скачиванием видео, пожалуйста напишите в поддержку по адресу внизу страницы.
Спасибо за использование сервиса ClipSaver.ru



From Checklists to Code: Engineering the Future of FedRAMP w/ Pete Waterman

Paramify is making FedRAMP (Rev 5 or 20x), GovRAMP & CMMC fun. Get your $750 Gap Assessment at paramify.com/grc. To get access to the deep-dive transcript, subscribe to the GRC Engineer newsletter: grcengineer.com/subscribe Wrong ink colours. $300,000 authorizations. Congressional investigations within the first month. How do you fix federal compliance from the inside? In this episode, Pete Waterman, Director of FedRAMP, shares how he's applying 20+ years of engineering experience to rebuild federal authorization from first principles. What started with "violent hatred" of the programme has become one of the most significant transformations in government compliance. Pete's approach is radically different: treat policy like code, make the secure thing the easy thing, and let engineers lead whilst compliance follows. The results speak for themselves. Key Topics Discussed: The Problem State How FedRAMP became a programme where perfection was fetishised beyond security, packages were rejected for cosmetic issues, and $300k costs prevented small teams from using modern tools FedRAMP 20X Architecture The dual-path strategy: improving Rev5 whilst building something entirely new with Key Security Indicators, machine-readable evidence, and persistent validation Risk-Based Authorization Why "my job is to make the government take more risks" - moving from bar-based to spectrum-based assessment where agencies choose based on their risk tolerance Engineering-First Requirements How KSIs like "prevent unauthorized access" replace "do these 18 specific things" and why cloud-native thinking changes everything Radical Transparency Doctrine Why posting roadmap updates every two weeks on GitHub creates trust and how "pre-decisional" anxiety is outdated thinking Chapters: 00:00 - Introduction 01:21 - Pete's background: 20 years in engineering to FedRAMP Director 04:19 - "Reading laws like source code" - discovering policy misinterpretations 07:07 - First month chaos: Congressional investigations and "violent hatred" 08:46 - Government structure: 2M people, 500+ agencies, not a monolith 12:44 - Why FedRAMP became unwieldy trying to satisfy everyone 14:11 - Perfection fetishised: rejected for wrong ink colours 16:06 - Vision: 2-5 people managing 400 cloud services 18:46 - Why government gets crappy custom versions of software 21:09 - Security should improve engineering, not just check boxes 24:26 - Cloud-native approach: outcomes not prescriptive controls 26:54 - Future vision: click "encrypt everything" and you're done 29:43 - Machine-readable evidence: let engineers build what benefits them 31:48 - "Just grep out what I care about" - letting standards emerge 33:34 - Flipping the model: engineers lead, compliance follows 35:50 - The abstraction problem: policy writers who never built things 39:41 - Economics: $300k → $5k authorization pathway 43:31 - Threat modelling example: outcomes over prescribed frequency 45:48 - No bar to clear, just show your posture 52:26 - Radical transparency: GitHub roadmaps every 2 weeks 55:40 - AI in GRC: value-add vs adversarial compliance game 1:00:30 - "If it was automatable, someone would have done it 6 years ago" 1:05:00 - How engineers should prove security program funding 1:08:07 - Non-trivial work proving things we don't care about 1:13:22 - GRC skillset transformation: policy expert to product expert 1:17:30 - Risk philosophy: optimize how you ACCEPT risk 1:22:11 - "Make the secure thing the easy thing" 1:24:50 - Success metric: never hear "can't use it, not FedRAMPed" 1:27:00 - Ecosystem impact: GRC tools finally have use case 1:32:39 - Impact levels: same rules, different intensity 1:36:53 - Government leading the way for private sector 1:39:12 - Parting thoughts: let machines assess tech About the Guest: Pete Waterman is Director of FedRAMP, bringing over 20 years of engineering leadership experience to federal compliance. Previously worked with US Digital Service as a cloud expert, the Technology Modernization Fund coaching agencies on modernization, and ran engineering at an AI company. He took over FedRAMP in August 2023 with a mandate to transform the programme from an engineering-first perspective. Connect with Pete: Pete Waterman:   / petewaterman   About The GRC Engineer: The GRC Engineer explores how engineering principles are transforming governance, risk, and compliance. Hosted by Ayoub Fandi, each episode features practitioners, leaders, and innovators who are building the future of GRC through automation, code, and systems thinking. Subscribe for episodes and entries featuring deep-dives into GRC automation, compliance as code, risk engineering, and the intersection of security, compliance, and software development. 🌐 Visit: grcengineer.com 💼 Connect: linkedin.com/in/ayoubfandi 📧 Newsletter: grcengineer.com/subscribe #GRCEngineering #FedRAMP #Compliance #Automation #CyberSecurity #RiskManagement #DevSecOps #CloudSecurity

Comments
  • Beyond the Screenshot: Why Auditors Don't Trust Platforms & What Quality Really Costs w/ Troy Fine 8 дней назад
    Beyond the Screenshot: Why Auditors Don't Trust Platforms & What Quality Really Costs w/ Troy Fine
    Опубликовано: 8 дней назад
  • Breaking Into GRC Engineering Insights, Automation, and Careers 2 недели назад
    Breaking Into GRC Engineering Insights, Automation, and Careers
    Опубликовано: 2 недели назад
  • The GRC Engineering Blueprint for the Public Sector w/ Dr. Ibrahim Waziri Jr. from Google 2 месяца назад
    The GRC Engineering Blueprint for the Public Sector w/ Dr. Ibrahim Waziri Jr. from Google
    Опубликовано: 2 месяца назад
  • FedRAMP 20x - Launching Phase II - Hosted by ADI 1 месяц назад
    FedRAMP 20x - Launching Phase II - Hosted by ADI
    Опубликовано: 1 месяц назад
  • How to Build Trust Between GRC and Engineering | Tristan Ingold, Security GRC Program Manager @ Meta 2 недели назад
    How to Build Trust Between GRC and Engineering | Tristan Ingold, Security GRC Program Manager @ Meta
    Опубликовано: 2 недели назад
  • Is GRC Engineering the next DevSecOps? w/ Justin from Klaviyo | S2E1 1 год назад
    Is GRC Engineering the next DevSecOps? w/ Justin from Klaviyo | S2E1
    Опубликовано: 1 год назад
  • Крысы доедят Зеленского 7 часов назад
    Крысы доедят Зеленского
    Опубликовано: 7 часов назад
  • Understanding FedRAMP Compliance  - Full Episode The Other F Word 2 года назад
    Understanding FedRAMP Compliance - Full Episode The Other F Word
    Опубликовано: 2 года назад
  • Разговор с тем, кто поддерживает Путина / вДудь 17 часов назад
    Разговор с тем, кто поддерживает Путина / вДудь
    Опубликовано: 17 часов назад
  • Rebuilding GRC from Scratch: Build-First Engineering w/ Emre & Chad from Docker 1 месяц назад
    Rebuilding GRC from Scratch: Build-First Engineering w/ Emre & Chad from Docker
    Опубликовано: 1 месяц назад
  • Deep-dive on Cyber Risk Quantification and GRC w/ Tony Martin-Vegue from Netflix 3 месяца назад
    Deep-dive on Cyber Risk Quantification and GRC w/ Tony Martin-Vegue from Netflix
    Опубликовано: 3 месяца назад
  • FISMA против FedRAMP против NIST — всё, что вам нужно знать 1 год назад
    FISMA против FedRAMP против NIST — всё, что вам нужно знать
    Опубликовано: 1 год назад
  • GRC Practical Series
    GRC Practical Series
    Опубликовано:
  • ТОТАЛЬНЫЙ ПРОВАЛ Таркова: на что ушло 10 лет разработки и бета-теста? 18 часов назад
    ТОТАЛЬНЫЙ ПРОВАЛ Таркова: на что ушло 10 лет разработки и бета-теста?
    Опубликовано: 18 часов назад
  • GRC (governance, risk (management), and compliance)
    GRC (governance, risk (management), and compliance)
    Опубликовано:
  • Незнание экономических законов погубило СССР — погубит и Путина 14 часов назад
    Незнание экономических законов погубило СССР — погубит и Путина
    Опубликовано: 14 часов назад
  • How to Break into GRC Cybersecurity (Without a Tech Background) 6 месяцев назад
    How to Break into GRC Cybersecurity (Without a Tech Background)
    Опубликовано: 6 месяцев назад
  • Kubernetes — Простым Языком на Понятном Примере 3 месяца назад
    Kubernetes — Простым Языком на Понятном Примере
    Опубликовано: 3 месяца назад
  • Бюджет 2026 | Поправки на 7 триллионов — что с деньгами на войну (English subtitles) @Максим Кац 15 часов назад
    Бюджет 2026 | Поправки на 7 триллионов — что с деньгами на войну (English subtitles) @Максим Кац
    Опубликовано: 15 часов назад
  • Как генерал МВД зарабатывает на нелегальной миграции 17 часов назад
    Как генерал МВД зарабатывает на нелегальной миграции
    Опубликовано: 17 часов назад

Контактный email для правообладателей: [email protected] © 2017 - 2025

Отказ от ответственности - Disclaimer Правообладателям - DMCA Условия использования сайта - TOS



Карта сайта 1 Карта сайта 2 Карта сайта 3 Карта сайта 4 Карта сайта 5