Cybersecurity in the Supply Chain, the DoD Solution

What do Target, Wendy’s, and Home Depot have in common? All three were hacked, they suffered losses in the tens of millions of dollars, and all were hacked through their supply chain. The attackers were not successful in targeting these large companies directly; they successfully attacked the smaller, less prepared contractors and suppliers. The lessons from these cyberattacks and others are not lost on industry and government. These attacks point out that the weakest link in the cybersecurity defense chain is often contractors and suppliers.
The federal government, large corporations, and industry have spent over a decade working to improve their cybersecurity defense. They have developed security standards designed to protect healthcare information, critical infrastructure, financial and personal information, etc., and as a result, they have become a much harder target to attack. These standards have also migrated to Federal contractors as an example since 2016 Federal contracts (FAR 52.204-21) require contractors to meet fifteen basic security controls. To address the Defense Industrial Base supply chain vulnerabilities, the Department of Defense (DoD) in 2017 set the requirement for all contractors to implement the National Institute of Standards and Technology (NIST) 800-171 standard, titled “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations.” The goal is to improve cyber defense across the defense industry by requiring organizations to develop and follow a system security plan. However, as a requirement, it was ignored. For most companies, the requirement was overkill; for a few, it was not enough. In response, in January 2020, the DoD released the Cybersecurity Maturity Model Certification (CMMC). Unlike the NIST requirement, the CMMC model has five levels of certification, and it will require all defense contractors, prime or subcontractors, large or small, to be audited and certified. The goal of the CMMC program is to have all 300,000 businesses in the defense industrial based certified to one of the five CMMC levels by the beginning of Fiscal Year 2026. The bottom line is, to work in Defense Industrial Base, you will have to be audited and certified.
The CMMC model has five levels; the most common level will be Level 1, which has 17 practice requirements; the estimate is that 60% of the companies in the industrial base will be Level 1. The second most common level is CMMC Level 3, with 130 practices which is about 35% of all companies. Fewer companies will make up the remaining levels. The question is, what level will a company be? The answer is driven by the value of information. Within the CMMC model, there are essentially two classes of information, Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). CMMC Level 1 is focused on protecting FCI, which is contract information that is not in the public domain. This is contract information provided by the government. It can be delivery information, part numbers, contact points, etc., or what you produce as a contract requirement. CMMC Levels 2 to 5 are focused on protecting CUI; this is also information not in the public domain; it is information that requires safeguarding and must be marked. It may include engineering or manufacturing drawings, software, reports, etc. What will determine CUI will be listed in the contract and marked as CUI. For most manufacturing companies, the focus will be on CUI and the 130 practices for Level 3.
As with most things regarding requirements, standards, and compliance, the tendency is to address the issue when it is in front of you. This may not be a wise course of action. Though Level 1 has only 17 practice requirements and they are considered basic IT actions, they will require resources and time to implement. Most company networks and systems suffer from benign neglect. This is due to obsolete equipment, out-of-date software, default settings not changed. In the past, there was a checklist approach to security compliance; this changes with the CMMC model. For all CMMC levels, there will be an on-site visit, meaning the auditor will conduct the audit in person at your place of business. Another consideration is context; the CMMC model is not strictly cybersecurity or IT-focused; it takes a system security approach. It addresses physical security; it is focused on practices in terms of how well you follow your plan or instructions.
If your company has worked with the DoD, if you want to continue to work as a contractor, the CMMC audit and certification are a requirement. The contractor will pay for the audit, it is pass or fail, and the certification will be good for three years. At all CMMC levels, the best advice is to start now. Perhaps one of the most important considerations is to realize this is a companywide effort; this will take direct management involvement. This is more than a number of cybersecurity requirements; some compliance requirements will require business process changes. The bottom line, to ensure failure, is to foist this off to the IT department or some other group and walk away hoping for compliance.

171 Comply
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.