29 janvier 2020 | International, C4ISR, Sécurité

New cybersecurity standards for contractors could be finalized this week

The first version of the new cybersecurity requirements the Pentagon wants military contractors to follow could be finalized as soon as Jan. 31.

Katie Arrington, chief information security officer for the Office of the Under Secretary of Defense for Acquisition and the point person for the Cybersecurity Maturity Model Certification (CMMC), told an audience Jan. 28 that she will have the requirements by the end of the month.

The CMMC is a tiered cybersecurity framework that grades companies on a scale of one to five. A score of one designates basic hygiene and a five represents advanced hygiene. Arrington said Jan. 28 that the lowest level will become the default for Department of Defense contracts and will include basic tasks such as changing passwords.

Speaking at an event hosted by the law firm Holland and Knight, Arrington said the new standards won't be in effect overnight. The auditors and assessors who will grade companies need training and new contracts will be slowly phased in.

“The likelihood that any awards will be made until 2021 [of the certification] is, I would say, highly unlikely,” she said. She noted that companies are not required to have CMMC certification until the time of award. “You have a full year to get yourselves set, to get yourself in position.”

According to one slide in her presentation, all new contracts will have the requirements in fiscal year 2026. Arrington expects 1,500 companies to be certified by the end of 2021.

The requirements are expected to be free of jargon and overly technical language that can often make military documents befuddling.

“I asked if it could be created on an eighth grade reading level. Why? Because I'm not smart and I owned a small business and I fell prey to this,” she said. “I needed it to be in something that anybody could adapt to. We hear companies all the time say my nephew is doing my cybersecurity. I need your nephew to read what I need him to do.”

Arrington promised that the requirement would not become a simple checklist, because if it does “I've failed. We failed.”

Moreover, she suggested the framework be reevaluated at least once each year because cyber threats will continue to evolve.

https://www.fifthdomain.com/dod/2020/01/28/new-cybersecurity-standards-for-contractors-could-be-finalized-this-week/

Sur le même sujet

  • Fincantieri: works start on the first next-generation Offshore Patrol Vessel for the Italian Navy 24 September 2024

    25 septembre 2024 | International, Terrestre

    Fincantieri: works start on the first next-generation Offshore Patrol Vessel for the Italian Navy 24 September 2024

    This program, put in place to contribute to the modernization and renewal of the Italian Navy's units, envisages the construction of four vessels, with an option for additional two, with...

  • Raytheon awarded $551 million US Army contract to begin production of Patriot™ for the Kingdom of Bahrain

    11 mars 2020 | International, Terrestre

    Raytheon awarded $551 million US Army contract to begin production of Patriot™ for the Kingdom of Bahrain

    Tewksbury, Mass., March 9, 2020 /PRNewswire/ - The U.S. Army awarded Raytheon Company (NYSE: RTN) a $551 million contract to begin production of the combat-proven Patriot™ air and missile defense system for the Kingdom of Bahrain. The contract was awarded on January 31, 2020. "Raytheon's Patriot provides the Kingdom of Bahrain and 16 other countries around the globe with a combat-proven system that protects citizens, infrastructure and armed forces from a broad spectrum of threats," said Tom Laliberty, vice president of Integrated Air and Missile Defense at Raytheon's Integrated Defense Systems business. "Patriot works, has saved countless lives, and will continue to do so for many years because the system is constantly tested, modernized, upgraded and improved to stay ahead of the advancing threat." Raytheon's Patriot is the most advanced tactical air and missile defense system in the world, providing protection against a full range of advanced threats, including aircraft, tactical ballistic missiles, cruise missiles and unmanned aerial vehicles. About Raytheon Raytheon Company, with 2019 sales of $29 billion and 70,000 employees, is a technology and innovation leader specializing in defense, civil government and cybersecurity solutions. With a history of innovation spanning 98 years, Raytheon provides state-of-the-art electronics, mission systems integration, C5I® products and services, sensing, effects, and mission support for customers in more than 80 countries. Raytheon is headquartered in Waltham, Massachusetts. Follow us on Twitter. Note to Editors The 17 Patriot Nations are: United States of America The Netherlands Germany Japan Israel Kingdom of Saudi Arabia Kuwait Taiwan Greece Spain Republic of Korea United Arab Emirates Qatar Romania Sweden Poland Kingdom of Bahrain Media Contact Mike Nachshen +1.520.269.5697 idspr@raytheon.com SOURCE Raytheon Company View source version on Raytheon: http://raytheon.mediaroom.com/2020-03-09-Raytheon-awarded-551-million-US-Army-contract-to-begin-production-of-Patriot-TM-for-the-Kingdom-of-Bahrain

  • CISA Publishes Encrypted DNS Implementation Guidance to Federal Agencies | CISA
Toutes les nouvelles