Back to news

February 3, 2020 | International, Aerospace, Naval, Land, C4ISR, Security

Pentagon finalizes first set of cyber standards for contractors

Mark Pomerleau

The Pentagon has finalized the long anticipated cybersecurity standards contractors will have to follow before winning contracts from the Department of Defense, a new process called the Cybersecurity Maturity Model Certification (CMMC) 1.0.

The model is a tiered cybersecurity framework that grades companies on a scale of one to five based on the level of classification and security that necessary for the work they are performing.

“The government and the contractor community must keep working together to address real and growing cybersecurity threats, and we need a robust response to protect our infrastructure, information, and supply chains,” said David Berteau, president and chief executive of the Professional Services Council, a trade association for federal contractors. “With today's announcement, DoD has achieved a significant milestone.

Here's what industry officials need to know about the version finalized Jan. 31.

Why it was needed

Previously, the Pentagon did not have unified standard for cybersecurity that businesses needed to follow when bidding for contracts. Companies could claim to meet certain industry standards for cybersecurity, but those assertions were not tested by auditors, nor did the standards take into account the type of work a company was bidding to complete. Since then, defense officials have said that cybersecurity is not a one size fits all approach.

In the meantime, adversaries have discovered it is easier to target unsuspecting down tier suppliers, rather than prime contractors.

“Adversaries know that in today's great power competition environment, information and technology are both key cornerstones and attacking a sub-tier supplier is far more appealing than a prime,” Ellen Lord, the under secretary of defense for acquisition and sustainment, told reporters in a briefing at the Pentagon Jan. 31.

Officials have said cyber theft by adversaries costs the United States about $600 billion a year.

What will change?

Contracts will mandate bidders reach a certain level of certification to win specific jobs. For example, if businesses aren't bidding on a contract that has extremely sensitive information, they must only achieve the first level of certification, which involves basic cybersecurity such as changing passwords and running antivirus software. More sensitive programs will require more stringent controls.

Smaller companies down the supply chain will not, however, have to have the same level of certification as primes, said Katie Arrington, chief information security officer for the Office of the Under Secretary of Defense for Acquisition and the point person for the certification.

Another significant change with the new process is the creation of an accreditation board and assessors. The board is an outside entity, separate from DoD, that will be charged with approving assessors to certify companies in the process.

The accreditation body was formed earlier this month and officials are working on identifying and training the assessors, which will be called Certified Third-Party Assessment Organizations (C3PAO).

What's next?

Officials explained Jan. 31 that CMMC will follow a crawl, walk, run approach to ensure companies aren't unprepared for the change. The accreditation board is in the process of training the auditors that will oversee the certificaion. Once the requirements are met, a company's certification is good for 3 years.

In the meantime, DoD plans to release 10 requests for information and 10 requests for proposals that will include the new cyber standards this year. The first solicitation could come as early as June.

Arrington said earlier this week that she expects 1,500 companies to be certified by the end of 2021.

She added that all new contracts starting in fiscal year 2026 will contain the cybersecurity requirements, however, Lord noted that they will not be not retroactive to previous contracts.

https://www.fifthdomain.com/dod/2020/01/31/pentagon-finalizes-first-set-of-cyber-standards-for-contractors/

On the same subject

  • Rheinmetall unveils new ground robot for armed reconnaissance

    November 30, 2020 | International, Land

    Rheinmetall unveils new ground robot for armed reconnaissance

    By: Sebastian Sprenger COLOGNE, Germany — Rheinmetall has unveiled a new scouting configuration of its Mission Master ground robot, ratcheting up competition in a European market segment that is set to heat up in the coming years. The new version features a suite of sensors mounted on a collapsible, 3.5-meter mast, including an infrared sensor, a surveillance radar and a 360-degree camera. A laser rangefinder and target designator are also included on the vehicle, as is a 7.62mm gun on a remote-controlled weapon station, according to a company statement. “The Mission Master-Armed Reconnaissance is designed to execute high-risk scouting missions and deliver a real-time common operating picture without putting soldiers in danger,” the German company said. The six-wheeled vehicle's autonomous functions are powered by Rheinmetall's PATH kit, which the company advertises as a means to turn any vehicle into an unmanned platform. Multiple vehicles can be combined to operate as part a “Wolf Pack” cluster, a technology enabling communications, cueing and targeting toward a common mission objective, according to Rheinmetall. Ground robots with varying degrees of autonomy are rapidly becoming critical for ground forces worldwide. Cargo transport and surveillance are some of the most obvious applications. While some of the new robots carry weapons, Western manufacturers have shied away from connecting their most advanced autonomy algorithms to the process of firing them. Rheinmetall's Mission Master series is something of a counterpoint to Estonia's Milrem Robotics, which has been making inroads with European ground forces through its tracked THeMIS vehicle. Milrem has advertised its operational experience by way of a THeMIS deployment with the Estonian military to the French-led Barkhane counterterrorism mission in Mali. Milrem also sits atop a smattering of European companies charged with developing a common architecture for unmanned ground vehicles under the umbrella of the European Defence Industrial Development Programme. The effort is named iMUGS, which is short for “integrated Modular Unmanned Ground System,” and it received roughly $36 million in European Union funding over the summer. “The ambition is no less than developing an F-16 [fighter jet] of unmanned ground systems,” Kusti Salm, director general of the Estonian Centre for Defence Investments, was quoted as saying by the Baltic Times website in 2019. The iMUGS effort centers around Milrem's THeMIS vehicle as a prototype platform. Notable European land warfare companies are part of the consortium, including Germany's Krauss-Maffei Wegmann and France's Nexter. Absent from the EU-endorsed roster is Rheinmetall, which has mounted its own marketing and outreach campaign for the Mission Master series. Earlier in November, the company announced it had given a sample vehicle to the Royal Netherlands Army for experimentation. The robot will undergo a two-year evaluation toward what Rheinmetall described as “Future Manoeuvre Elements” to aid Dutch ground forces during operations. The Dutch previously ordered the THeMIS from Milrem. During the spring, Rheinmetall delivered four Mission Master vehicles configured for cargo transport to U.K. forces. “These unmanned ground vehicles will form part of the United Kingdom's Robotic Platoon Vehicle program,” Rheinmetall said in a statement at the time. “This program is designed to determine the extent to which unmanned vehicles can boost the combat effectiveness and capabilities of dismounted troops at platoon level.” https://www.defensenews.com/global/europe/2020/11/29/rheinmetall-unveils-new-ground-robot-for-armed-reconnaissance

  • UNC3886 Uses Fortinet, VMware 0-Days and Stealth Tactics in Long-Term Spying

    June 19, 2024 | International, Security

    UNC3886 Uses Fortinet, VMware 0-Days and Stealth Tactics in Long-Term Spying

    Discover how UNC3886 exploits Fortinet and VMware vulnerabilities in sophisticated cyber espionage campaigns. Learn about advanced persistence methods

  • La Fabrique Défense s’ouvre à l’Europe

    February 1, 2022 | International, Aerospace, Naval, Land, C4ISR, Security

    La Fabrique Défense s’ouvre à l’Europe

    La Fabrique Défense se veut le « rendez-vous de référence de l'ensemble des acteurs de l'écosystème de la défense », a expliqué la ministre des Armées Florence Parly lors de sa visite le 28 janvier en ouverture du salon à Paris. Il constitue un événement visant à participer au développement d'une culture européenne en matière de défense, notamment auprès des jeunes Européens. Outre le salon en lui-même, l'édition 2021-2022 a permis d'organiser une centaine d'événements en France et dans 20 autres pays européens autour de la question. A cette occasion, de nombreux acteurs (institutionnels, universités, associations, entreprises, think tanks, etc.) ont été associés pour organiser ces rendez-vous, autour de 136 stands répartis en 13 espaces thématiques. Outre les stands, un programme riche de tables rondes et de témoignages professionnels a permis aux visiteurs de découvrir les grands enjeux de la défense. Des espaces animations avec notamment des Serious Games (wargames, simulateurs de vol, etc.), et des démonstrations extérieures (drones) étaient également proposées. Au moment où la filière recrute, le GIFAS était présent, aux côtés de l'armée de l'Air et de l'Espace et des industriels du secteur. Cet espace avait vocation à présenter au public la contribution de l'industrie aéronautique et spatiale à la Défense et ses nombreuses opportunités de métiers et d'emplois.

All news