Has your business made implementing NIST SP 800-171 harder than it needs to be?
Are your employees using one device for CUI work and another for regular work?
If so, there is a good chance you have overengineered your environment to get ready for CMMC. In this case, your business may have provided “a solution to a problem in an elaborate or complicated manner, where a simpler solution can be demonstrated to exist with the same efficiency and effectiveness as that of the original design.”
We run into overengineering all the time. Many try to treat CUI as SECRET and overprotect it, while many don’t understand how to use NIST SP 800-171 to avoid overengineering.
This “As the CMMC Churns” looks at “Overengineering for CMMC” and we even channel a little Jeff Foxworthy plus Dungeons & Dragons along the way.
Key CMMC Organizations
- National Archives & Records Administration Controlled Unclassified Information (CUI) Homepage
- DoD CIO’s Cybersecurity Maturity Model Certification (CMMC) Home Page
- Cyber Accreditation Body (Cyber-AB)
- Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) Contractor Resource Page
- Defense Industrial Base (DIB) Cybersecurity Portal
Key Regulations
Key Acquisition References
- 48 CFR § 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems
- DFARS Clause 252.204-7008 Compliance with Safeguarding Covered Defense Information Controls.
- DFARS Clause 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
- DFARS Clause 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS Clause 252.204-7020 NIST SP 800-171 DoD Assessment Requirements.
- DFARS Clause 252.204-7021 Compliance with the Cybersecurity Maturity Model Certification Level Requirements.