Kenneth Ingham Consulting, LLC

Services

CMMC readiness

Preparation is the heart of this practice. Nearly everything that determines whether a CMMC assessment goes well—or goes expensively sideways—is settled before the assessor arrives.

At Level 1, Kenneth has helped a company complete its self-assessment and produce the supporting documentation and evidence needed to withstand a customer's verification. That is more than a basic checkbox exercise: the result has to remain defensible when someone outside the organization asks how each conclusion was reached.

This includes Level 3. A Level 3 gap assessment has been delivered for a client. Level 3 draws on a subset of NIST SP 800-172 rather than the whole of it, which is a deliberate and welcome choice: it captures most of the security benefit without some of 800-172's more operationally punishing requirements.

Assessment-day advocacy

Once an organization is genuinely ready, Kenneth Ingham Consulting can attend the certification assessment or remain on call throughout it.

Assessments often turn on whether evidence is understood the way the organization meant it. The role here is closer to defense counsel than to a second assessor: an advocate who already knows the environment, speaks the assessor's vocabulary, and can present the organization's position in those terms. Kenneth Ingham Consulting also works with Dyan Edington, a Lead Certified CMMC Assessor (LCCA).

Clients have completed their certification assessments with this support, achieving full certification rather than a conditional status carrying open remediation items.

Certification assessments

Certification assessments are performed by authorized C3PAOs. Kenneth Ingham Consulting is not itself a C3PAO, but it has working relationships with several, and two things follow from that:

That last condition is not a preference. For any single client, preparation and assessment are mutually exclusive: an organization this practice prepared for certification cannot then be assessed by it. Cyber AB conflict-of-interest rules prohibit doing both, and readiness is where this practice concentrates.

NIST frameworks and contract clauses

Assistance interpreting and implementing NIST SP 800-171, SP 800-172, and SP 800-53 controls for organizations that need defensible, sustainable security practices.

This includes the contract language that puts those controls in scope: DFARS 252.204-7012, -7019, -7020, and -7021. Knowing which clause applies, and what it actually obliges, often matters more than any individual control.

Scope note on FedRAMP: DFARS 7012 requires that cloud services handling covered defense information meet FedRAMP Moderate or equivalent. This practice can explain that obligation and help you choose a provider who already satisfies it. It does not guide organizations through FedRAMP authorization itself. That is specialist work, and the right answer there is a referral to someone who does it.

Choosing a control baseline

A shelf of unfamiliar standards is usually one problem wearing several hats. Some are built directly out of NIST SP 800-53:

Others were plainly written with it open, PCI-DSS among them, or have published crosswalks to it: the CJIS Security Policy, the HIPAA Security Rule through NIST SP 800-66, ISO 27001, the CIS Critical Security Controls, and the NIST Cybersecurity Framework.

The practical consequence is that work done once tends to count more than once. Controls implemented for one standard usually satisfy much of another.

Funding can carry security obligations too. Money from a state or federal source sometimes arrives with cybersecurity strings attached, and those strings are usually 800-53 controls in different clothing.

Start with the controls that pay

Controls differ enormously in what they cost and what they return. Phishing-resistant multifactor authentication—FIDO2 security keys or passkeys—is cheap and removes an entire class of attack. FIPS-validated cryptography is expensive and, absent a requirement demanding it, often buys an incremental improvement.

For an organization with no legal obligation forcing a particular standard, the order matters more than the list. The high-return controls come first.

Policies and procedures

Mature security is repeatable security—it survives people leaving. That depends on policies and procedures good enough that the work does not live only in someone's head.

A policy also has to say how you would know it is being followed. One you cannot verify compliance with is close to useless, however well it reads.

Documents written to describe what the organization really does:

Review of existing policies and procedures is also available. Deliverable: a report on what is working, what should change, and why and how.

Risk assessment

A risk assessment starts from who would attack this organization and why. Setting those attacker classes and motivations against your existing policies, procedures, and controls gives a first view of where risk actually sits and what already mitigates it. Refining it means working through the ways the organization genuinely uses technology, rather than the ways an inventory says it does.

Deliverable: a risk assessment document with existing and recommended mitigations.

AI governance and risk

For organizations adopting AI faster than they are governing it. Kenneth served on the City of Albuquerque's Artificial Intelligence Policy Working Group and has taken part in NIST's NCCoE Cyber AI Profile working sessions.

Policy review. A review of an existing AI policy, read alongside the related data protection and privacy policies it has to work with. Technology and rules both change, so an annual review is worth scheduling rather than waiting for something to force one. Deliverable: a report on what is working, what should change, and why and how.

AI risk assessment. What could go wrong, how likely it is, and what to do about it. Deliverable: a risk assessment with existing and recommended mitigations.

Finding unregistered AI use. A policy requiring departments to register their AI use is only as good as your ability to check. Web proxy logs, firewall logs, and purchasing records each show part of the picture. None of them will show a device with its own cellular connection—an automated license plate reader, for instance—which is exactly the sort of thing that gets missed.

Training. Review of existing AI training, help specifying what a training module needs to cover, or help selecting a vendor. Buying existing training is usually more cost effective than building it, though building it is possible.

Protecting sensitive information

Security planning for Defense Industrial Base organizations, government contractors, educational institutions subject to FERPA, and healthcare organizations subject to HIPAA.

Scope note: This public site is not approved for transmitting CUI, regulated records, credentials, incident details, or other sensitive data. Use the contact form only to request a secure follow-up channel.

Cybersecurity consulting

Focused help for small and medium-sized businesses that need effective controls without an oversized security department.

Every engagement begins by clarifying scope, obligations, decision owners, and the evidence that will show the work is complete.

Independence

Kenneth Ingham Consulting has no agreement with any vendor to be paid for recommending a product, a service, or a training course. No commissions, no referral fees, no reseller margin.

This is deliberate, and it is the reason a recommendation from here is worth anything: nothing is gained by which way it goes. When the right answer is a product this practice does not sell, or a specialist it cannot supply, that is the recommendation you get.

Where the work happens

Kenneth Ingham Consulting is based in Albuquerque and registered in New Mexico, and works with clients throughout the United States. Location has never been the constraint: most of this work is reading, analysis, and conversation. Where being on site matters—an assessment, a tabletop exercise, a walkthrough of how things really run—travel is arranged.