Federal technology contractors hold the keys to our nation’s security in their networks, servers, and databases. Yet, recent incidents point to worrisome vulnerabilities that indicate increased cyber risk to defense contractors and the supply chain.
Bloomberg’s editorial board’s provocatively-titled article, Contractors are Giving Away America’s Military Edge, highlights a laundry list of eye-opening security breaches that have beset Department of Defense (DoD) contractors in recent months. Noteworthy incidents included theft by China of highly sensitive information, the 2018 DoD breach that exposed the personal information of 30,000 military and civilian personnel, and more. The article also quotes a recent Bitsight report that found that 5.6 percent of aerospace and defense contractors reported at least one data breach since 2016.
Now, the DoD has apparently had enough of the status quo. In September, the DoD issued a public draft of Version 0.4 of its Cybersecurity Maturity Model Certification (CMMC), which establishes a tiered framework that outlines specific criteria for defense contractor risk management.
With the CMMC, the DoD has laid down an ultimatum to its contractors: up your cyber defenses, or we simply will not do business with you.
What is the Cybersecurity Maturity Model Certification?
The model clearly articulates several requirements that contractors must meet to qualify for various maturity certifications. Those certifications range from Level 1, ”Basic cybersecurity,” to Level 5, “Highly advanced cybersecurity practices.”
The CMMC employs a complex and comprehensive matrix that encompasses 18 different cybersecurity best practices, from “Access Control” to “System and Information Integrity.” The amount of detail contained within the model takes it beyond the popular NIST Cybersecurity Framework, although it incorporates parts of that risk management framework and other sources.
You can learn more about the CMMC by reading the draft framework, which is scheduled to be finalized in January 2020.
What does the CMMC Mean for Third Party Contractors?
Upon finalization, the CMMC will require contractors to partner with an independent third party agency, which will schedule an assessment. Contractors can select the level of certification they’re applying for, and will be required to demonstrate their cybersecurity maturity to the assessor. There is no self-certification allowed.
Once the assessment is complete, the certification level (though not specific results) will be made available to the DoD and the public. That means that anyone will be able to easily determine the contractor’s cybersecurity maturity, which could potentially impact any business dealings the organization has even beyond the federal government.