Is your business struggling to implement procedures for Cybersecurity Maturity Model Certification (CMMC)?
Is your business chasing procedures for everything because of perceived compliance requirements coming from CMMC, NIST SP 800-171, and NIST SP 800-171A?
Well, this episode does some “Mythbusting” to bring you some clarity on how to approach procedures when getting ready for CMMC, NIST SP 800-171, PCI, ISO 27000, and any other framework out there. Really.
This episode will save business leaders involved in implementing CMMC compliance efforts via your “Little CMMC Engine That Could…” time, money, and effort plus reduce your risk of a gap being discovered during a Conformity Assessment.
Key CMMC Organizations
- National Archives & Records Administration Controlled Unclassified Information (CUI) Homepage
- DoD CIO’s Cybersecurity Maturity Model Certification (CMMC) Home Page
- Cyber Accreditation Body (Cyber-AB)
- Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) Contractor Resource Page
- Defense Industrial Base (DIB) Cybersecurity Portal
Key Regulations
Key Acquisition References
- 48 CFR § 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems
- DFARS Clause 252.204-7008 Compliance with Safeguarding Covered Defense Information Controls.
- DFARS Clause 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
- DFARS Clause 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS Clause 252.204-7020 NIST SP 800-171 DoD Assessment Requirements.
- DFARS Clause 252.204-7021 Compliance with the Cybersecurity Maturity Model Certification Level Requirements.