Arrington Supports Internal CMMC Review.

PositionBEST OF THE WEB

* The Defense Department has launched an internal review of its burgeoning Cybersecurity Maturity Model Certification program, but the leader of the initiative says she isn't concerned.

Katie Arlington, chief information security officer in the office of the undersecretary of defense for acquisition and sustainment and the face of the CMMC rollout, likened the assessment to a standard acquisition category, or ACAT 1, review of major defense acquisition programs.

The review will ensure "we're doing the implementation correctly internally" she said April 8 during a webinar hosted by Deltek. "That's actually been phenomenal [at]...helping us looking across the departments so we're not duplicating effort or anything like that."

CMMC is a far-reaching Pentagon initiative aimed at requiring the defense industrial base to better protect its networks and controlled unclassified information against cyberattacks and theft by competitors such as China.

The new cybersecurity standards, which companies must eventually adhere to if they want to do business with the Pentagon, was first unveiled in January 2020.

Arrington said work on the CMMC rollout is moving forward. The Pentagon is taking a phased approach and is on track to release 15 contracts with the CMMC requirements included in them this year. Seven of those have already been released.

The plan is to release 75 contracts with CMMC requirements in fiscal year 2022, Arrington said.

...

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT