I’ll bet you didn’t know the Security Requirements in NIST SP 800-171 have relationships.
We see people just jumping into NIST SP 800-171 compliance, helping organizations and even CMMC Certified Assessors failing to understand how one requirement may be shaped by a preceding one and, in turn, influence subsequent requirements.
In this As the CMMC Churns, we look at how getting tunnel vision can negatively impact your implementation of the requirements. Likewise, we look at 5 use cases to demonstrate how the requirements fit together like a jigsaw puzzle. While not an exhaustive dissertation on Security Requirement relationships, these five do tell viewers where the relationship is breaking down, which may result in a NOT MET.
Key CMMC Organizations
- National Archives & Records Administration Controlled Unclassified Information (CUI) Homepage
- DoD CIO’s Cybersecurity Maturity Model Certification (CMMC) Home Page
- Cyber Accreditation Body (Cyber-AB)
- Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) Contractor Resource Page
- Defense Industrial Base (DIB) Cybersecurity Portal
Key Regulations
Key Acquisition References
- 48 CFR § 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems
- DFARS Clause 252.204-7008 Compliance with Safeguarding Covered Defense Information Controls.
- DFARS Clause 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
- DFARS Clause 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS Clause 252.204-7020 NIST SP 800-171 DoD Assessment Requirements.
- DFARS Clause 252.204-7021 Compliance with the Cybersecurity Maturity Model Certification Level Requirements.