Services

We are CISO

We have the solution expertise to support your Information Security Program, Disaster Recover Program, Business Continuity Plan, and designing new or relocating Data Centers.

CMMC - Cybersecurity Maturity Model Certification

At our core, we help defense contractors protect what matters most: their data and their contracts. Our CMMC Compliance Services are designed to guide your business through every requirement of the Cybersecurity Maturity Model Certification—ensuring your systems, networks, and processes meet the standards the Department of Defense now mandates.

From assessing your current cybersecurity posture to implementing NIST 800-171 controls, documenting policies, strengthening your infrastructure, and preparing you for certification, we deliver a clear, supported path to compliance. Whether you're handling FCI or CUI, our team provides the expertise, tools, and hands-on guidance needed to secure your environment and maintain eligibility for DoD contracts.

We don’t just help you check boxes—we help you build a stronger, more resilient cybersecurity foundation for your entire organization.

Payment Card Industry Security Compliance & Remediation

As a merchant, you have the obligation to protect your Client’s credit card information and if you experience a breach, you must notify the appropriate entities of that event.

This is only one task of the PCI DSS requirements that merchants are obligated to comply with when they accept credit card information.

We can help you determine what is required and how to comply. We review and assess your organizations’ PCI DSS Compliance status based upon the PCI DSS requirements.

We provide you with the assessment results, as well as, a prioritized remediation project plan.

You decide whether we assist you with the remediation or not, however, you own the plan and can continue the remediation efforts on your own.

If you need to dispose of electronic equipment safely, we have a partnership with Brass Valley (www.brassvalley.com) to assist you.

Information Security Program Support and Assessment


We have the solution expertise to support your Information Security Program based upon business and technology risk analysis and remediation planning.

For instance, if you own or license personal information about a resident of the Commonwealth of Massachusetts, you are compelled to comply with Massachusetts’ 201 CMR 17 Compliance regulation.

“This regulation establishes the minimum standards to be met in connection with the safeguarding of personal information contained in both paper and electronic records.”

We review and assess your organizations’ Massachusetts’ 201 CMR 17 Compliance status based upon a more detailed version of the 201 CMR 17 Compliance Checklist.

We provide you with the assessment results as well as a prioritized remediation project plan.

You decide whether we assist you with the remediation or not, however, you own the plan and can continue the remediation efforts on your own.

Disaster Recovery and Business Continuity Planning

Do you have a Business Continuity or Disaster Recovery Plan in place to respond to a disastrous event such as a key employee leaving; a natural disaster causing large-scale destruction; an Incident Response Program for a data security breach that places your business on the front page of the local paper as well as have you wondering about lawsuits and/or fines?

CISO Consulting understands what measures to employ now to mitigate the risk associated with potential threats to your business whether nature or human caused.

We can help you protect your business.

HIPAA Security Rule Compliance utilizing the HITRUST MyCSF

As a Covered Entity or Business Associate handling Protected Health Information, you must comply with the HIPAA Security Rule.

Keith S. Crumpton, President of CISO Consulting and certified HITRUST MyCSF Practitioner, can guide your organization through compliance using the HITRUST Common Security Framework (MyCSF).

The HITRUST MyCSF provides:

  • A consistent, efficient method for measuring HIPAA compliance

  • Clear tracking of remediation progress

  • Evidence gathering for audits and reporting

  • Assurance to customers and leadership of regulatory compliance

CISO Consulting can also assist with HITRUST Validated Assessments and develop customized security policies when needed.

Data Centers

We can assist you with designing your new or upgrading your existing data center. Need to relocate; we can assist your staff with the move. Consolidating data centers is a tedious and time-consuming process.

We are here to help you.

Certifications

Get started with CISO, today.