The Department of Defense (DoD) has been working to implement changes designed to increase the protection of controlled unclassified information (CUI) throughout the Defense Industrial Base (DIB) supply chain.
Effective November 30, 2020 the interim Defense Federal Acquisition Regulation Supplement (DFARS) rule officially implemented the — Cybersecurity Maturity Model Certification (CMMC) requirement over the next five years.
- Data Inventory and CUI: Having a complete data inventory, understanding where your CUI resides and scoping out your CMMC boundary
- The move from self-assessment to third-party assessment: “If it isn’t written it doesn’t exist.” documentation and process to prove control implementation
- Frequently underinvested domains: Asset Management and Configuration Management often overlooked as security areas and consequently underinvested in
- Governance: How to track requirements, implement plans of action and generate artifacts to ensure compliance
Hear from CMMC-Registered Practitioner (CMMC-RP), Darren Van Booven, Lead Principal Security Consultant at LevelBlue and former CISO for the United States House of Representatives, as he addresses these common challenges and preparing your organization for CMMC verification requirements.