Sara Friedman

Sara Friedman joined Inside Cybersecurity in February 2020. Previously, she covered government IT for GCN and education technology for THE Journal and Campus Technology. She graduated from Ithaca College with bachelor’s degrees in journalism and politics.

Connections
Archived Articles
Daily News | February 29, 2024

The Aerospace Industries Association is asking the Defense Department to provide information on how it will address flow-down requirements and the roles and responsibilities for primes and subcontractors, in response to the first proposed rule for the Pentagon's Cybersecurity Maturity Model Certification program.

Daily News | February 28, 2024

A coalition representing large defense and tech groups is asking the Defense Department to provide clarity on marking controlled unclassified information, defining responsibilities in contracts and flexibility on addressing assessment gaps, in formal comments on the first proposed rule for the Pentagon's Cybersecurity Maturity Model Certification program.

Daily News | February 27, 2024

The Pentagon's Cybersecurity Maturity Model Certification program enters a new stage this week with the end of the public comment period for a massive, proposed rulemaking that sets up parameters to implement the long-awaited initiative.

Daily News | February 21, 2024

The Defense Department is limiting its engagement plans to an "informational" video for the first rulemaking under the Pentagon's Cybersecurity Maturity Model Certification program in advance of the Feb. 26 comment deadline, according to a Federal Register notice published today.

Daily News | February 16, 2024

Pentagon officials are providing an overview of major ecosystem components and upcoming regulations for the Cybersecurity Maturity Model Certification program in a new recorded video posted in advance of a Feb. 26 public comment deadline for the first rulemaking and eight draft guidance documents.

Daily News | February 8, 2024

The Defense Department is turning down a request from industry groups to extend the comment period for its long-awaited proposed rule to implement the Cybersecurity Maturity Model Certification program, according to a Pentagon spokesperson.

Daily News | February 6, 2024

A coalition representing major defense associations and government contractors is asking the Defense Department to extend the comment period for a proposed rule to implement the Pentagon's cyber certification program, in a new letter highlighting three public comment periods for cyber rulemakings that closed last week.

Daily News | February 6, 2024

The Energy Department has published a guide comparing its voluntary maturity model for developing cybersecurity plans to the Pentagon's upcoming program for defense contractors who are handling sensitive government data on nonfederal systems.

Daily News | February 2, 2024

The accreditation body behind the Pentagon's Cybersecurity Maturity Model Certification program plans to release a new draft of its assessment process guide, known as "the CAP," for public comment before the Defense Department completes its rulemaking efforts to finalize the program, according to CEO Matthew Travis.

Daily News | January 24, 2024

The Aerospace Industries Association is advocating for the Defense Department's Cybersecurity Maturity Model Certification program to be used by civilian agencies, as part of an effort to address "ambiguity" over sensitive information held by contractors and create synergies.

Daily News | January 17, 2024

The Information Technology Industry Council anticipates details on incorporating acquisition requirements for contractors under the Pentagon's Cybersecurity Maturity Model Certification program will come in the next rulemaking for the initiative, which will focus on making changes to the Defense Department's acquisition regulations.

Daily News | January 16, 2024

The Professional Services Council is supportive of the Pentagon's plans to allow self assessment for less sensitive information held by defense contractors under the Cybersecurity Maturity Model Certification program, while recognizing that contracting officers could still decide to choose a higher level of security than needed to ensure adequate protection of the information on nonfederal systems.

Daily News | January 10, 2024

The Defense Department is asking for input on the process to report assessment results under its Cybersecurity Maturity Model Certification program and proposed parameters to address potential gaps.

Daily News | January 5, 2024

The Defense Department has issued a memorandum on equivalency for cloud service offerings between the General Services Administration’s Federal Risk and Authorization Management Program and the Pentagon's cyber certification program.

Daily News | January 5, 2024

The Pentagon’s proposed rule to implement the Cybersecurity Maturity Model Certification program details the role, expectations and tasks for the accreditation body responsible for building out on the major Defense Department initiative's assessment ecosystem.

Daily News | January 3, 2024

The Defense Department provides a rundown of how its proposed rule addresses small business concerns over the Cybersecurity Maturity Model Certification program, as part of a detailed breakdown of comments received on the 2020 interim final rule.

Daily News | January 2, 2024

The Defense Department has revealed its plans to revamp the Cybersecurity Maturity Model Certification program in guidance documents offering an official preview on changes to the model, assessment and scoping requirements as well as the process for submitting results to the Pentagon.

Daily News | December 29, 2023

A recent report commissioned by the Air Force Research Laboratory dives into how addressing cyber risks differs from other supply chain risk management issues and provides recommendations on how to take a "comprehensive approach" in addressing their needs together.

Daily News | December 28, 2023

Details on the assessment process, ecosystem roles, scoping requirements and more can be found in the Defense Department proposed rule published this week for the Cybersecurity Maturity Model Certification program.

Daily News | December 28, 2023

Two trade associations representing companies in the defense industrial base are raising concerns over the potential for burdensome regulation following the introduction of a massive Defense Department proposed rule to implement the major revamp of the Cybersecurity Maturity Model Certification program.

Not a subscriber? Request 30 days free access to exclusive, behind-the-scenes reporting on defense policy and procurement.