DO NOT watch this if you are a Defense Industrial Base (DIB) Contractor. You have real work to do by implementing NIST SP 800-171 Revision 2. Here is what you need to do:
1. Ignore all of the CMMC Ecosystem Drama around the NIST SP 800-171 R3 Draft for the next two years
2. Add a Risk Registry to “Monitor” NIST SP 800-171 R3 for impacts to your system compliance requirements
3. FOCUS on getting NIST SP 800-171 Revision 2 implemented, including the Non-Federal Organization controls
Okay, for everyone else, this “As the CMMC Churns” looks at NIST SP 800-171 Revision 3 Initial Public Draft. In our review, we concluded that Ron Ross & Victoria Pilliteri are brilliant at how they drafted revision 3 and their public math skills (a.k.a., Federal Math) were ‘challenging.’
The bottom line is there are more Information Security requirements under NIST SP 800-171. However, if I go by the strict count of requirements, I won the bet with Fernanda Machado of Cybersec Investments.
Key CMMC Organizations
- National Archives & Records Administration Controlled Unclassified Information (CUI) Homepage
- DoD CIO’s Cybersecurity Maturity Model Certification (CMMC) Home Page
- Cyber Accreditation Body (Cyber-AB)
- Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) Contractor Resource Page
- Defense Industrial Base (DIB) Cybersecurity Portal
Key Regulations
Key Acquisition References
- 48 CFR § 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems
- DFARS Clause 252.204-7008 Compliance with Safeguarding Covered Defense Information Controls.
- DFARS Clause 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
- DFARS Clause 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS Clause 252.204-7020 NIST SP 800-171 DoD Assessment Requirements.
- DFARS Clause 252.204-7021 Compliance with the Cybersecurity Maturity Model Certification Level Requirements.