Cybersecurity Compliance for the DoD Soon a Work Precondition

The new compliance requirement for businesses working with the DoD is Cybersecurity Maturity Model Certification (CMMC) certification. The CMMC model is designed to protect the contact and technical information that are in DoD contracts. The model consists of five levels, with each higher level incorporating increasing layers of security. The goal is for all 300,000 companies in the defense industrial base to be audited and certified compliant by the end of Fiscal Year 2025. Essentially, CMMC compliance certification will be a baseline requirement; with the appropriate certification level, there will be access to contracts; without certification, a company will be deemed unqualified.
Information security compliance requirements are nothing new, and in many industries, they have been around for years. In healthcare, the requirement is the Healthcare Insurance Portability Accountability Act (HIPAA), which requires safeguarding patient information. In finance, one of the requirements is the Gramm–Leach–Bliley Act (GLBA), also known as the Financial Services Modernization Act of 1999. The requirement is to protect customer financial information. There is the International Organization for Standardization (ISO) Standards. The most common is ISO 9001, which is a quality management process. There is the ISO 27001, which is an information security standard. There are standards for design, environment, construction, and the experience modification rating (EMR) in the construction industry. The EMR rating is used to price workers’ compensation insurance premiums; it is a way to assign workplace loss and risk to a company. With a high EMR rating, a construction company will find it impossible to be awarded a large prime contractor or hired as a subcontractor. Increasingly meeting industry-specific compliance requirements is no longer an option; it is a decision point. If the business strategy is to work in a specific industry sector on large projects, meeting the compliance requirement is mandatory.
In terms of working within the defense industrial base as a defense contractor, meeting the appropriate CMMC Level will be mandatory, and meeting the compliance requirements is an investment in resources. As mentioned, there are five levels; most companies will be Level 1, which is 17 practices or requirements; by comparison, at Level 5, there are 171 practices. These 17 Level 1 practices include the 15 security practices mandated for all Federal contracts in June 2016 (FAR 52.204-21). Within the CMMC model, Level 1 is the minimum set of practices needed to achieve basic cyber-hygiene. In meeting the CMMC model requirements, it is important to realize that it is focused on system security; it is not only cybersecurity, it is not only IT. The model is focused on viewing security in terms of a holistic and all-hazards approach.
In broad terms, cybersecurity or system security should not be considered a single-purpose effort, with the only one benefit being CMMC certification. The reality is that all businesses need to protect their information and information systems. The CMMC model, with its practice requirements, focuses on safeguarding contact and technical information; these protections can also protect company-controlled information. This company-controlled information includes financial data, customer and employee information, company intellectual property, etc. In addition, these protections protect and secure access to the network, facilities, and computer hardware. Essentially, the practice requirements in the CMMC model need to be viewed as a list of universal best practices for securing the company’s information management system. The threat should not be considered only attacking government systems; it is directed to exploiting system vulnerabilities wherever they can be found. Most importantly, most small businesses are out of business six months after a cyber-attack.
There are four aspects to the certification process: compliance with the requirements, institutionalizing these processes, and an organizational management commitment of resources. All CMMC Levels require evidence of compliance, and there are three forms of objective evidence that determine compliance: interview, test, and evidence review. An interview is the accessor interviewing staff to determine if they know their compliance job. A test can be a system test that evaluates user behavior. The evidence review will often be policy, backed up by physical evidence of compliance, meeting notes, logs, and reports collected over time. The institutionalization of compliance is the organization conforming to the system security plan and demonstrating how it is achieved. This is resourcing, paying for employee time spent in training, management, monitoring, system upgrades, etc., this is the system security lifecycle costs. Of the three aspects, management commitment is the most important; and it is the one that is often wished away. For most manufacturers, the requirement will be meeting CMMC Level 3, with 130 compliance requirements. This will require developing a system security plan and meeting compliance for each requirement. Meeting some requirements will require management to engage in business process engineering. Institutionalization will require a budget for labor and system upgrades. Additionally, this is a time-consuming process; it will take about a year since this effort is no one’s full-time job. Most importantly, it will take direct management involvement and the sustainment of company resources over the organization’s life.

171 Comply
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.