Is your organization getting ready to undergo a formal Conformity Assessment for NIST SP 800-171?
If so, you need to watch this video!!! With the uptick in non-voluntary and Joint Surveillance Voluntary Assessments (JSVA) done by the Defense Industrial Base Cybersecurity Assurance Center (DIBCAC), understanding the mindset of your Assessor (cough “toddler”) is critical for your survival.
In this episode of “As the CMMC Churns,” we will look at the similarities between Assessors and Toddlers; why you can’t leave them unattended; and, we will explain how they learn.
We also explain one of the best parenting methods for guiding your Assessor (cough “toddler”), the Document Traceability Matrix. You can download the matrix at https://peakinfosec.com/wp-content/uploads/2023/06/Document-Traceability-Matrix-Template.docx
Key CMMC Organizations
- National Archives & Records Administration Controlled Unclassified Information (CUI) Homepage
- DoD CIO’s Cybersecurity Maturity Model Certification (CMMC) Home Page
- Cyber Accreditation Body (Cyber-AB)
- Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) Contractor Resource Page
- Defense Industrial Base (DIB) Cybersecurity Portal
Key Regulations
Key Acquisition References
- 48 CFR § 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems
- DFARS Clause 252.204-7008 Compliance with Safeguarding Covered Defense Information Controls.
- DFARS Clause 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
- DFARS Clause 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS Clause 252.204-7020 NIST SP 800-171 DoD Assessment Requirements.
- DFARS Clause 252.204-7021 Compliance with the Cybersecurity Maturity Model Certification Level Requirements.