New proposed rule for CMMC 2.0 lays out security requirements, raises some eyebrows

New proposed rule for CMMC 2.0 lays out security requirements, raises some eyebrows
New proposed rule for CMMC 2.0 lays out security requirements, raises some eyebrows

At its most basic level, under CMMC 2.0, defense contractors and subcontractors that have access to controlled unclassified information (CUI) will be required to demonstrate the “maturity” of their cybersecurity programs against a set of increasingly advanced capabilities. 

DoD official envisions faster ‘secure pipeline’ to help small business tech contractors protect information

DoD official envisions faster ‘secure pipeline’ to help small business tech contractors protect information
DoD official envisions faster ‘secure pipeline’ to help small business tech contractors protect information

“In my mind, these are some of these avenues that we’re looking at at an idea phase now to see if we can put resources behind it,” said Robert Vietmeyer, director for cloud and software modernization.

Pentagon eyeing the cloud to help firms meet CMMC cybersecurity requirements

Pentagon eyeing the cloud to help firms meet CMMC cybersecurity requirements
Pentagon eyeing the cloud to help firms meet CMMC cybersecurity requirements

“For instance, in the CMMC realm, rather than go out and assess each and every network of our industry partners, I’m kind of keen on establishing some sort of cloud services […]” said David McKeown, DoD deputy chief information officer and senior information security officer

Pentagon CIO hopes CMMC 2.0 will ‘raise’ cybersecurity ‘waterline’

Pentagon CIO hopes CMMC 2.0 will ‘raise’ cybersecurity ‘waterline’
Pentagon CIO hopes CMMC 2.0 will ‘raise’ cybersecurity ‘waterline’

“There’s a cost to your IP, there’s a cost to the US government and there’s a benefit to our adversaries if we don’t do something like this,” DoD Chief Information Officer John Sherman said of the Cybersecurity Maturity Model Certification program.

The health of the Defense Industrial Base is failing, trade group says

The health of the Defense Industrial Base is failing, trade group says
The health of the Defense Industrial Base is failing, trade group says

That conclusion is part of the National Defense Industrial Association’s third annual Vital Signs 2022 report, which offers an analysis of the US’s defense industrial base.

Pentagon rolls out v2.0 of controversial CMMC program

Pentagon rolls out v2.0 of controversial CMMC program
Pentagon rolls out v2.0 of controversial CMMC program

DoD said it will be “increas[ing] oversight of professional and ethical standards of third-party assessors.”

CMMC: Stopping Cyber Espionage Like Chinese Theft of F-35 Data

CMMC: Stopping Cyber Espionage Like Chinese Theft of F-35 Data
CMMC: Stopping Cyber Espionage Like Chinese Theft of F-35 Data

CMMC 1 is “what you’ve got to have to make sure your neighbor is not in your Netflix,” quipped Stacy Bostjanick, director of CMMC. “It’s very easy, and commensurate with basic cyber hygiene. I recommend that everyone get there, but as a COTS provider, you don’t have to.”

No CMMC Penalty for Companies Hit By Solar Wind Hack

No CMMC Penalty for Companies Hit By Solar Wind Hack
No CMMC Penalty for Companies Hit By Solar Wind Hack

“A determined adversary with the right capabilities is going to find their way in, especially if they put all their resources to bear on it,” said Karlton Johnson, the chair of the CMMC Accreditation Body board of directors.

‘Start Of A New Day’: DoD’s New Cybersecurity Regs Take Effect Today

‘Start Of A New Day’: DoD’s New Cybersecurity Regs Take Effect Today
‘Start Of A New Day’: DoD’s New Cybersecurity Regs Take Effect Today

Designed to help secure the supply chain, CMMC requires the defense industrial base to protect Controlled Unclassified Information.

Starting Dec. 1, Cybersecurity Is No Longer Optional

Starting Dec. 1, Cybersecurity Is No Longer Optional
Starting Dec. 1, Cybersecurity Is No Longer Optional

“This is the start of a new day in the Department of Defense where cybersecurity, as we’ve been saying for years is foundational for acquisitions, we’re putting our money where our mouth is. We mean it,” Katie Arrington says.

presented by
Transforming Missile Defense With Digital Twins

Transforming Missile Defense With Digital Twins
Transforming Missile Defense With Digital Twins

Smart tools and emerging technologies can deliver the Next-Gen Interceptor more affordably and faster than any other missile defense system.

NSA Warns Companies China Is Exploiting 25 Unpatched Vulnerabilities

NSA Warns Companies China Is Exploiting 25 Unpatched Vulnerabilities
NSA Warns Companies China Is Exploiting 25 Unpatched Vulnerabilities

The NSA cannot mandate patching on its own, but the new Cybersecurity Maturity Model Certification (CMMC) allows the Pentagon to penalize companies in its supply chain that fail to adequately protect their networks.

Lord Begins Long March To Supply Chain Cybersecurity

Lord Begins Long March To Supply Chain Cybersecurity
Lord Begins Long March To Supply Chain Cybersecurity

Undersecretary Ellen Lord took pains today to emphasize companies would have plenty of time and plenty of help to meet new security standards. Is she going too slow?