Featured Pentagon eyeing the cloud to help firms meet CMMC cybersecurity requirements

Published on April 22nd, 2022 📆 | 7704 Views ⚑

0

Pentagon eyeing the cloud to help firms meet CMMC cybersecurity requirements


iSpeech

Wires protrude from a server at the 9th Medical Group, Beale Air Force Base, Calif. Jan 22, 2020. The Medical Information Services flight maintains all the connectivity through the medical group. (Photo by Staff Sgt. Taylor White)

WASHINGTON: The Pentagon is assessing whether to develop cloud service offerings to help contractors meet requirements for its cyber certification program, according to the Defense Departmentā€™s deputy chief information officer.Ā 

The Cybersecurity Maturity Model Certification (CMMC) program aims to strengthen the cybersecurity of the defense industrial base by holding contractors accountable for following best practices to protect their network, but can be an onerous undertaking both for the companies and their assessors. The Pentagon last November rolled out CMMC version 2.0, streamlining the security tiers of the program from five to three and resulting in some requirements changes for its first two levels.Ā 

David McKeown, DoD deputy chief information officer and senior information security officer, whose office leads the CMMC effort, said Tuesday at the AFCEA Cyber Mission Summit heā€™s looking for ā€œinnovative solutionsā€ to help contractors meet at least 85 out of 110 controls in NIST Special Publication 800-171 in order to achieve certification required for Level 2 of CMMC.Ā 

ā€œFor instance, in the CMMC realm, rather than go out and assess each and every network of our industry partners, Iā€™m kind of keen on establishing some sort of cloud services that either achieve many of the 110 controls in [NIST SP] 800-171 or all of them that industry partners can consume to store our data and safeguard our data without us having to go out onto your network,ā€ McKeown said.Ā 

Pentagon CIO John Sherman in February said he hoped the upgraded CMMC program would raise the cybersecurity ā€œwaterlineā€ across DoD to keep potential adversaries away from critical data.Ā 

ā€œThis is basic hygiene to raise the water level to make sure we can protect our sensitive data so that when our service members have to go into action, theyā€™re not going to have an unfair position because our adversaryā€™s already stolen key data and technologies thatā€™ll put them at an advantage,ā€ Sherman said at the AFCEA Space Force IT conference.Ā 





RELATED: Pentagon CIO Hopes CMMC 2.0 Will ā€˜Raiseā€™ Cybersecurity ā€˜Waterlineā€™

Meanwhile, CMMCā€™s policy director said Wednesday another interim rule for the program could come in May. The Pentagon released its first interim rule, which define some mandatory compliance requirements, in September 2020 for the first version of CMMC, prompting hundreds of comments and criticism from industry regarding the timeframe and complexity of the program.Ā 

ā€œOur anticipation is that we will be allowed to have another interim rule like we did last time,ā€ Stacy Bostjanick, CMMC policy director for the Office of the Undersecretary of Defense for Acquisition and Sustainment, said. ā€œWeā€™re hoping that the interim rule will go into effect by May. In fact, my team is very frustrated with me today because Iā€™m sitting here with you guys and theyā€™re stuck in a room going through a rule thatā€™s like hundreds of pages long.ā€Ā 

Once the rulemaking process is over, she said she hopes ā€œthere will be only one more aspect that weā€™ll have to address and that will be the international partners.ā€Ā 

ā€œThat will probably take some rulemaking effort,ā€ Bostjanick said. ā€œWeā€™re working through how thatā€™s going to work in getting that laying flat today.ā€



Source link

Tagged with: ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢



Comments are closed.