10 mars 2020 | International, C4ISR, Sécurité

The Pentagon’s first class of cybersecurity auditors is almost here

Mark Pomerleau

The Pentagon hopes to have the first class of auditors to evaluate contractors' cybersecurity ready by April, a top Department of Defense official said March 5.

The auditors will be responsible for certifying companies under the new Cybersecurity Maturity Model Certification (CMMC), which is a tiered cybersecurity framework that grades companies on a scale of one to five. A score of one designates basic hygiene and a five represents advanced hygiene.

Currently, there are no auditors — known as Certified Third-Party Assessment Organizations (C3PAO) — as the accreditation board came about officially in January.

“Our goal is to have, in late April, our pilot pathfinder on the training for the C3PAOs,” Katie Arrington, chief information security officer for the Office of the Under Secretary of Defense for Acquisition, said at an event hosted by DreamPort in Columbia, Maryland.

The accreditation board is working on training the auditors and the accompanying training materials

Arrington said just because there aren't any auditors already working doesn't mean companies shouldn't be getting ready.

“You've got to get prepared for the audit,” she said. “You should be able to say ‘I think I've done my self assessment, I think I'm at this CMMC level.' Waiting for the audit to come in and then decide to get good or to get on track is not the way I would position my business.”

If all goes according to plan, all new contracts in 2025 will feature the security requirements.

Arrington also suggested that the framework has received interest outside the DoD.

“Do I think that other federal agencies are getting on board? Yes they are. They're waiting for me to get through my pathfinder,” she said.

She also referred to comments made by Under Secretary of Defense for Acquisition and Sustainment Ellen Lord, who explained nearly a dozen nations and international organizations are interested in adopting CMMC.

https://www.fifthdomain.com/dod/2020/03/09/the-pentagons-first-class-of-cybersecurity-auditors-is-almost-here/

Sur le même sujet

  • DARPA Explores New Computing Architectures to Deliver Verifiable Data Assurances

    17 janvier 2019 | International, C4ISR, Sécurité

    DARPA Explores New Computing Architectures to Deliver Verifiable Data Assurances

    Program seeks to create new software and hardware architectures that provide physically provable assurances around data security and privacy Whether a piece of information is private, proprietary, or sensitive to national security, systems owners and users have little guarantees about where their information resides or of its movements between systems. When a user enters information on a phone, for example, it is difficult to provably track that the data remains on the phone or whether it is uploaded to a server beyond the device. The national defense and security communities are similarly left with few options when it comes to ensuring that sensitive information is appropriately isolated, particularly when it's loaded to an internet-connected system. “As cloud systems proliferate, most people still have some information that they want to physically track – not just entrust to the ether,” said Walter Weiss, DARPA program manager. “Users should be able to trust their devices to keep their information private and isolated.” Keeping a system completely disconnected from all means of information transfer is an unrealistic security tactic. Modern computing systems must be able to communicate with other systems, including those with different security requirements. Today, commercial and defense organizations often leverage a series of air-gaps, or breaks between systems, to keep the most sensitive computing devices and information secure. However, interfaces to such air-gapped systems are typically added in after the fact and are exceedingly complex, placing undue burden on systems operators as they implement or manage them. To create scalable solutions that provide safe, verifiable methods of tracking information and communications between systems, DARPA launched the Guaranteed Architecture for Physical Security (GAPS) program. The goal of GAPS is to develop hardware and software architectures that can provide physically provable guarantees around high-risk transactions, or where data moves between systems of different security levels. DARPA wants to ensure that these transactions are isolated and that the systems they move across are enabled with the necessary data security assertions. The intended outputs of this program are hardware and software co-design tools that allow data separation requirements to be defined during design, and protections that can be physically enforced at system runtime. GAPS is divided into three research areas that will address: 1) the creation of hardware components and interfaces; 2) the development of software co-design tools; and, 3) the integration of these components and tools, as well as their validation against exemplar Department of Defense (DoD) systems. The new hardware components and interfaces are designed to provide system designers with a library of hardware tools to securely isolate data during transactions. The software co-design tools could someday allow developers to easily employ GAPS hardware components without requiring changes to their existing development processes and frameworks. Finally, the integration and validation of the hardware and software architectures on DoD systems could be used to demonstrate the capability and maturity of the GAPS approach for the kinds of problems DoD system integrators currently face, and expect to see in the future. Commercializing the resulting technologies is also an objective of the program. The verifiable security properties created under GAPS may also help create safer commercial systems that could be used for preserving proprietary information and protecting consumer privacy. GAPS is part of the second phase of DARPA's Electronics Resurgence Initiative (ERI) - a five-year, upwards of $1.5 billion investment in the future of domestic, U.S. government and defense electronics systems. Under ERI Phase II, DARPA is exploring the development of trusted electronics components, including the advancement of electronics that can enforce security and privacy protections. GAPS will help address the DoD's unique requirements for assured electronics while helping to move forward ERI's broader mission of creating a more robust, secure and heavily automated electronics industry. DARPA will hold a Proposers Day on January 23, 2019 from 9:00am to 2:30pm (EST) at the DARPA Conference Center, located at 675 North Randolph Street, Arlington, Virginia 22203, to provide more information about GAPS and answer questions from potential proposers. For details on the event, including registration requirements, please visit: http://www.cvent.com/events/gaps-proposers-day/event-summary-34cbadc0ab2248bb860db3df8223a2f6.aspx. A Broad Agency Announcement that fully describes the GAPS program structure and objectives can be found here: https://www.fbo.gov/index?s=opportunity&mode=form&id=cfecfe762954149924ec59c95ec6a7b8&tab=core&_cview=1. https://www.darpa.mil/news-events/2019-01-16

  • Lockheed Martin and Northrop Grumman Sign Letter of Intent with Rheinmetall to Manufacture F-35 Center Fuselages

    20 février 2023 | International, Aérospatial

    Lockheed Martin and Northrop Grumman Sign Letter of Intent with Rheinmetall to Manufacture F-35 Center Fuselages

    This potential partnership would establish a second F-35 center fuselage integrated assembly line (IAL) in Germany, expanding the significant role European industry plays in the F-35 program.

  • Le H160 d’Airbus Helicopters obtient la certification européenne

    6 juillet 2020 | International, Aérospatial

    Le H160 d’Airbus Helicopters obtient la certification européenne

    Le H160 d'Airbus Helicopters vient de décrocher son certificat de type auprès de l'Agence européenne de la sécurité aérienne (EASA), ouvrant la voie à sa prochaine mise en service. L'hélicoptériste européen prévoit que sa certification FAA suivra dans peu de temps, alors que la première livraison est destinée à un client américain qui n'a pas été dévoilé. Le nouvel hélicoptère biturbine multirôle de moyen tonnage d'Airbus se positionne comme le successeur direct de la famille Dauphin (SA365 à EC155). Il est motorisé par deux turbines de nouvelle génération conçues et produites par Safran Helicopter Engines. Journal de l'Aviation du 1er juillet 2020 – Les Echos du 2 juillet 2020

Toutes les nouvelles