COVID-19 was a massive catalyst to change how the United States and the world operate.
Businesses and the Federal Government had to shift to work from home on an unprecedented schedule. It forced businesses to transform all facets of their operations, including Information Technology.
COVID-19 forced organizations to change how they do Vulnerability Management for Remote Workers. This “As the CMMC Churns” looks at methods for small businesses just getting into meeting NIST SP 800-171 compliance can leverage tools to meet their compliance requirements and keep up with vulnerabilities.
We will briefly discuss tools from vendors like Automox, jamf, Microsoft, Qualys, Rapid7, and Tenable and how they may fit in your organization.
Key CMMC Organizations
- National Archives & Records Administration Controlled Unclassified Information (CUI) Homepage
- DoD CIO’s Cybersecurity Maturity Model Certification (CMMC) Home Page
- Cyber Accreditation Body (Cyber-AB)
- Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) Contractor Resource Page
- Defense Industrial Base (DIB) Cybersecurity Portal
Key Regulations
Key Acquisition References
- 48 CFR § 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems
- DFARS Clause 252.204-7008 Compliance with Safeguarding Covered Defense Information Controls.
- DFARS Clause 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
- DFARS Clause 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS Clause 252.204-7020 NIST SP 800-171 DoD Assessment Requirements.
- DFARS Clause 252.204-7021 Compliance with the Cybersecurity Maturity Model Certification Level Requirements.