Government agencies in the United States are yet again suffering from a widespread data hack, this time originating from Microsoft Exchange servers. This breach comes less than five months after the SolarWinds breach exposed vulnerabilities across dozens of industries, including government agencies. How is the government pivoting to protect their network from these increasingly widespread attacks?
A potential protection mechanism is being tested in the form of the Cybersecurity Maturity Model Certification, a Department of Defense (DOD) creation to help regulate the cybersecurity practices of the third parties working with government agencies. In the wake of the recent breaches, the DOD has implemented more stringent guidelines on how contractors and third parties need to meet cybersecurity maturity requirements before working within the department’s network.
What is included in the DOD’s Cybersecurity Maturity Model Certification, and what pieces of it should your organization include in your own vendor management strategies?
What is the Cybersecurity Maturity Model Certification?
Originally created in 2019, the Cybersecurity Maturity Model helped place contractors into different categories based on their cybersecurity maturity. The model required independent verification from a third party evaluator to a rank contractor in various cybersecurity categories. While a low cybersecurity maturity model score didn’t immediately mean an organization was prevented from doing business with the DOD, the public access to the cybersecurity maturity model certification results did mean all of their current and future business partners now could see the inherent risk associated with them as a contractor.
To give a sense of what’s included for each level of maturity, here is what’s written for what the DOD considers lowest to highest in terms of cybersecurity maturity model rankings:
- Level 1: Basic cybersecurity, limited resistance against data exfiltration.
- Practices are performed at least in ad-hoc manner
- Level 2: Inclusive of universally accepted cybersecurity best practices and are resilient against unskilled threat actors.
- Practices are documented
- Level 3: Coverage of all NIST SP 800-171 rev 1 controls, moderate resistance against data exfiltration with comprehensive knowledge of cyber assets.
- Processes are maintained and followed
- Level 4: Advanced and sophisticated cybersecurity practices that are resilient against threat actors, defenses responses approach machine speed.
- Processes are properly reviewed, resources, and improved across the enterprise
- Level 5: Highly advanced cybersecurity practices, machine performed analytics and defensive actions.
- Continuous improvement of processes across the enterprise