The Contracting Education Academy

Contracting Academy Logo
  • Home
  • Training & Education
  • Services
  • Contact Us
You are here: Home / Archives for cybersecurity standards

November 26, 2019 By cs

DoD Releases Version 0.6 of its Cybersecurity Maturity Model Certification

The Office of the Assistant Secretary of Defense for Acquisition has released Version 0.6 of its draft Cybersecurity Maturity Model Certification (CMMC) for public comment.

The CMMC was created in response to growing concerns by Congress and within DoD over the increased presence of cyber threats and intrusions aimed at the Defense Industrial Base (DIB) and its supply chains.

The model updates Version 0.4, which DoD released on September 4, 2019, and which we wrote about here. The CMMC establishes the framework necessary for contractors to obtain one of five certification levels necessary to perform work on certain DoD contracts, including those that require the handling of Controlled Unclassified Information. Whereas Version 0.4 merely listed the capabilities, controls, and processes that were expected to apply to each certification level, this version provides some additional discussion and clarification to assist contractors with meeting Level 1 certifications.

DoD has not explicitly asked for comment on this version of the CMMC, and has stated that the updated model is being released “so that the public can review the draft model and begin to prepare for the eventual CMMC roll out.” For this reason, although additional changes are to be expected to the model, contractors should review the general requirements closely to ensure that they are positioned to continue bidding on DoD contracts once DoD begins including a requirement to obtain a specific certification level in Requests for Proposal in Fall 2020.

Keep reading this article at: https://www.insidegovernmentcontracts.com/2019/11/dod-releases-version-0-6-of-its-cybersecurity-maturity-model-certification/

Filed Under: Government Contracting News Tagged With: CMMC, cybersecurity, Cybersecurity Maturity Model Certification, cybersecurity standards, DoD, requirements

November 7, 2019 By cs

Civilian vendor cybersecurity certification would look very different from DoD

A civilian counterpart to the Pentagon’s Cybersecurity Maturity Model Certification would need to suit the varying missions across government, according to federal deputy CIO Margie Graves.

The Defense Department is working on a new policy that will require its vendors to obtain a certification confirming the contractor’s own systems have strong enough cybersecurity to protect the department’s secrets. A civilian agency counterpart to that would look very different than what the Pentagon is developing, according to the second-ranking civilian IT official.

While the government does have a method for certifying the cybersecurity of vendors’ products — through the authority to operate, or ATO, process and the Federal Risk and Authorization Management Program, or FedRAMP — it does not have a program for assessing the security of the systems used by the vendors.

The Defense Department’s Cybersecurity Maturity Model Certification, or CMMC, looks to change that with a set of 18 “key sets of capabilities for cybersecurity,” according to the draft released in September.

Keep reading this article at: https://www.nextgov.com/cybersecurity/2019/10/civilian-vendor-cybersecurity-certification-would-look-very-different-dod/160982/

Filed Under: Government Contracting News Tagged With: CMMC, cybersecurity, cybersecurity compliant, Cybersecurity Maturity Model Certification, cybersecurity standards, DFARS, DoD, FAR, FedRAMP, technology

September 23, 2019 By cs

First wave of acquisition prohibitions take effect

The FAR Council released an Interim Rule in August implementing part of Section 889 of the John S. McCain National Defense Authorization Act for Fiscal Year 2019. 

In this briefing, we highlight points where the Interim Rule provides clarity; definitional issues that remain unresolved; and new procedural requirements that government contractors should track.

The Interim Rule covers the portion of Section 889, subsection (a)(1)(A), that prohibits the federal government from acquiring certain telecommunications equipment/services from Huawei, ZTE, and other Chinese companies.  Specifically: “The head of an executive agency may not … procure or obtain or extend or renew a contract to procure or obtain any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system.”

Section (a)(1)(A) took effect on August 13, 2019, although a 60-day window remains open for stakeholders to submit comments to be considered in the development of a final rule.  Comments on the (a)(1)(A) Interim Rule are due by October 15, 2019.

Keep reading this article at: https://www.insidegovernmentcontracts.com/2019/09/section-889-update-first-wave-of-acquisition-prohibitions-take-effect/

Filed Under: Government Contracting News Tagged With: acquisition policy, critical infrastructure, cybersecurity standards, FAR, FAR Council, interim rule, NDAA, prohibited activity, reporting requirements, Section 889, telecommunications

September 19, 2019 By cs

DoD will require vendor cybersecurity certifications by this time next year

The department released a draft maturity model and timeline for new certification requirements for all of the defense industrial base.

The government has stringent processes for verifying the IT products and services it uses comply with relevant cybersecurity standards, such as authorities to operate for cloud services and supply chain regulations for hardware products. But those standards and processes don’t cover the vendors.

For the Defense Department, this is a critical issue, as doing business with industry requires the department to share sensitive information, even at the earliest steps of the process.

The department has been kicking around the idea of creating a certification standard for defense industrial base companies to ensure vendors’ cybersecurity posture was adequate to handle controlled and classified information. That became an official effort in March, and on Sept. 4th the department released the first draft Cybersecurity Maturity Model Certification, or CMMC, outline for public comment.

Keep reading this article at: https://www.nextgov.com/cybersecurity/2019/09/dod-will-require-vendor-cybersecurity-certifications-time-next-year/159702/

 

 

Filed Under: Government Contracting News Tagged With: CMMC, cyber, cybersecurity, Cybersecurity Maturity Model Certification, cybersecurity standards, DoD, industry, industry feedback

September 12, 2019 By cs

DoD releases public draft of Cybersecurity Maturity Model Certification, seeks industry input

On September 4, the Office of the Assistant Secretary of Defense for Acquisition released Version 0.4 of its draft Cybersecurity Maturity Model Certification (CMMC) for public comment. 

The CMMC was created in response to growing concerns by Congress and within DoD over the increased presence of cyber threats and intrusions aimed at the Defense Industrial Base (DIB) and its supply chains.  In its overview briefing for the new model, DoD describes the draft CMMC framework as a “unified cybersecurity standard” for DoD acquisitions that is intended to build upon existing regulations, policy, and memoranda by adding a verification component to cybersecurity protections for safeguarding Controlled Unclassified Information (CUI) within the DIB.

As discussed in a prior post, the model describes the requirements that contractors must meet to qualify for certain maturity certifications, ranging from Level 1 (“Basic Cyber Hygiene” practices and “Performed” processes) through Level 5 (“Advanced / Progressive” practices and “Optimized” processes), with such certification determinations to generally be made by third party auditors.

The CMMC establishes a new framework for defense contractors to become certified as cybersecurity compliant.  DoD has stated that it intends to release Version 1.0 of the CMMC framework in January 2020 and will begin using that version in new DoD solicitations starting in Fall 2020.  Notwithstanding the pendency of these deadlines, a large number of questions remain outstanding.  DoD is seeking feedback on the current version of the model by September 25, 2019.

Keep reading this article at: https://www.insidegovernmentcontracts.com/2019/09/dod-releases-public-draft-of-cybersecurity-maturity-model-certification-and-seeks-industry-input/

Filed Under: Government Contracting News Tagged With: CMMC, controlled unclassified information, CUI, cybersecurity, cybersecurity compliant, Cybersecurity Maturity Model Certification, cybersecurity standards, DoD, industry

  • « Previous Page
  • 1
  • 2

Popular Topics

abuse acquisition reform acquisition strategy acquisition training acquisition workforce Air Force Army AT&L bid protest budget budget cuts competition cybersecurity DAU DFARS DHS DoD DOJ FAR fraud GAO Georgia Tech GSA GSA Schedule GSA Schedules IG industrial base information technology innovation IT Justice Dept. Navy NDAA OFPP OMB OTA Pentagon procurement reform protest SBA sequestration small business spending technology VA
Contracting Academy Logo
75 Fifth Street, NW, Suite 300
Atlanta, GA 30308
info@ContractingAcademy.gatech.edu
Phone: 404-894-6109
Fax: 404-410-6885

RSS Twitter

Search this Website

Copyright © 2022 · Georgia Tech - Enterprise Innovation Institute