Expert Witness
Counsel retain me when the fight is the security program. I identify the baseline in the record, evaluate what was implemented on the organization and on the system, and explain what the evidence supports about whether those controls were effective. That includes whether the data the program was supposed to protect was in scope, marked, and actually controlled, not only whether a control existed on paper. The work is a written opinion. If the case needs it, deposition and trial.
I do this because it is my job on live systems, not because I learned the catalog for court. Over my career I have mapped thousands of NIST 800-53 controls and Control Correlation Identifiers (CCIs) to program, system, and organizational boundaries, and I have written the technical requirements when the contract did not flow them down. I have led Risk Management Framework (RMF) engineering from baseline selection through implementation and assessment. The opinion is the same question I already answer in the work: what was required, what was built, and what the record will support.
What I do
I evaluate control selection and implementation and explain what the evidence supports about effectiveness against identified technical criteria. That covers the organization, the program, and the system. I state the sources and assumptions behind the baseline I used, and I state where the evidence stops.
The same question shows up when the dispute is data protection or privacy: what data was covered, which systems touched it, and whether the controls on those systems were selected, implemented, and evidenced.
| Matter type | Typical issues | Side served |
|---|---|---|
| Control selection and implementation | Which baseline applied, what was put in place on the organization and the system, what the record supports | Either side |
| NIST SP 800-53 / 800-53B | Low / Moderate / High baselines, tailoring, inside or outside FIPS 199 | Either side |
| National Security Systems | CNSSI 1253 C/I/A ratings, overlays, control decomposition | Either side |
| CMMC / 800-171 / 800-172 | CUI handling, control implementation, compliance representations, contractor cybersecurity obligations | Either side |
| FAR / DFARS cyber clauses | 52.204-21, 7012, 7019, 7020, 7021 as they show up in the record | Either side |
| FedRAMP / DoD cloud | What the provider must still be able to show versus what the customer must still evidence | Either side |
| Data protection and privacy | What data was covered, which systems touched it, whether those controls were implemented and evidenced | Either side |
| Vendors and flow-down | Whether the language covers the data the buyer thinks it covers, and whether the seller can take that language on | Either side |
What I will not take as the primary opinion
- Device imaging and mobile forensics
- Malware reversing and attribution
- Pure source-code patent comparison
If that is the center of the case, you need someone who does that work every day. I will say so before you retain me.