Latest draft of DOD cyber certification plan relies on pending NIST security controls

By Rick Weber / December 17, 2019 at 9:55 AM
The Defense Department has issued a draft plan for its Cybersecurity Maturity Model Certification program that addresses the highest levels of risks for contractors and relies on security controls developed by the National Institute of Standards and Technology that are still under review. "The CMMC model consists of 17 domains" which are sets of capabilities based on cybersecurity "best practices" for protecting controlled unclassified information, according to the latest CMMC draft issued last week. "The majority of these CMMC domains...

Not a subscriber? Sign up for 30 days free access to exclusive, behind-the-scenes reporting on defense policy and procurement.

Log in to access this content.