It's Time to Get a Jumpstart on CMMC 2.0.

AuthorSfoglia, Pete
PositionCommentary

* During the Cold War, the Defense Department wanted a network that could reroute itself around areas where nuclear weapons had been destroyed or attacked by enemy spies, so they built one and called it ARPANET, or the Advanced Research Projects Agency Network. Scientists at major universities joined in, using it as a collaboration tool. The ARPANET, now called the internet, has become a business enabler extraordinaire, a behemoth transactional system that holds together a global economy. Like all things that evolve, it has taken on a level of complexity that businesses--large and small--are ill-equipped to address.

With the military and colleges as its sole users, we did not build the internet with security in mind. We realized this after its value as a social and business enabler became apparent, resulting in the exponential growth and increased diversity of its user base.

Unfortunately, hackers began exploiting America's first "killer app" for financial gain, disgruntled employees used it for revenge, and end-user neophytes made mistakes. The tech industry responded with vain attempts to repurpose an already mature and efficient architecture by retrofitting it with hardware like firewalls, and software such as encryption, antivirus and real-time monitoring tools. But these efforts weren't enough to stem the tide of assaults on our privacy, finances and reputation.

The government had to do something to rein in the beast it had created. So it used its heavy hand to impose sweeping cybersecurity regulations and control standards on big banks, broker/dealers, health insurance carriers, and critical infrastructure. But then, numerous breaches occurred at lower levels of the supply chain, attacking the same information that the big companies were spending millions to protect. Another example of government intervention is the Cybersecurity Maturity Model Certification (CMMC), which regulates government contractors who secure controlled unclassified information (CUI).

The first version, CMMC 1.0, never had a chance. It was complex, contained control requirements from too many authoritative sources, and lacked governance over third-party assessment pricing. So finally, after more than 18 months of contractor outrage, the Defense Department put a hold on CMMC and gave out a few clues on what's to come.

Now, there is CMMC 2.0.

The Defense Department comptroller estimates that it could be another seven to 20 months before CMMC 2.0 is signed into law. So, what can be done while waiting?

...

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT