What DOD’s Cyber Certification Program Reveals About Info-Sharing Challenges

NextGov: The Information Technology Industry Council is arguing that the foundation of U.S. cybersecurity policy—information sharing between organizations—presents a security threat that is too costly for many to address in response to a rule implementing the Pentagon’s Cybersecurity Maturity Model Certification Program.

The CMMC program was designed to change the Defense Department’s practice of having contractors simply attest to their own level of cybersecurity and institute a system of third-party auditors to validate required practices are in place.

Read article

Share