网络安全成熟度
模型的认证

认证的邮票
盾牌标志

什么是网络安全成熟度模型认证?

To enhance the protection of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) within the supply chain, 美国.S. 国防部(DoD)正在与国防部利益相关者合作, 大学附属研究中心, federally funded centers and industry at large to develop the 网络安全成熟度模型认证 (CMMC), a process that measures the ability of company within the defense industrial base (DIB) sector to protect FCI and CUI. CMMC also adds a certification element to verify implementation of cybersecurity requirements and certifications will need to be performed by accredited third parties such as bet9游戏平台.

CMMC is designed to provide the DoD assurance that a DIB contractor can adequately protect CUI at a level commensurate with the risk and account for flow down to subcontractors in a multitier supply chain. The CMMC will be included in RFIs and RFPs in 2020 and will eventually be mandatory for all.

To learn more about the potential costs and how your organization can prepare for CMMC, download our 网络安全成熟度模型认证(CMMC)指南

金属梁

CMMC模型框架

The CMMC model framework categorizes cybersecurity best practices at the highest level by domains.

Each domain is further segmented by a set of capabilities and achievements to ensure that cybersecurity objectives are met within each domain. Companies will further validate compliance with the required capabilities by demonstrating adherence to practices and processes that have been mapped across five maturity levels (explained below). 在这个背景下, practices will measure the technical activities required to achieve compliance with a given capability requirement, 过程将度量公司的成熟度.

块

CMMC水平

CMMC模型有五个已定义的级别, 每个都有一组支持实践和过程, from 1级 that addresses basic cyber hygiene to proactive and advanced Levels 4 and 5. 并行, 过程的范围从级别1开始, documented at 2级 and optimized across the organization at Level 5. 满足特定的CMMC级别, an organization must meet the practices and processes within that level and below. 级别描述如下:

  • 1级 要求组织展示基本的网络卫生. 当实践被期望执行时, 过程成熟度在CMMC第1级没有提到, 因此, a CMMC 1级 organization may have limited or inconsistent cybersecurity maturity. 在这个层面上, 可以向组织提供FCI, which is information not intended for public release but provided by or generated for the government under a contract to develop or deliver a product or service to the government.
  • 2级 要求组织展示中级网络卫生. 在这个层面上, an organization is expected to establish and document standard operating procedures, policies and strategic plans to guide the implementation of their cybersecurity program. 在第2级,组织可能被提供FCI.
  • 3级 Requires an organization to demonstrate good cyber hygiene and effective NIST SP 800-171 Rev 1 security requirements. 过程成熟度, a 3级 organization is expected to adequately resource and review activities related to adherence to policy and procedures, 并论证管理实践的实施. Organizations that require access to CUI and/or generate CUI should achieve 3级.
  • 四级和五级 在4级和5级, 一个组织有一个实质性的和前瞻性的网络安全计划, with the capability to adapt their protection and sustainment activities to address the changing tactics, apt使用的技术和程序(TTPs). 过程成熟度, the organization is expected to review and document activities for effectiveness and inform high-level management of any issues, as well as ensure that process implementation has been generally optimized across the organization.
bet9平台游戏器

CMMC域

CMMC模型由17个域组成, the majority which originated from the FIPS 200 security-related areas and the NIST SP 800-171 control families. 域包括:

  • 访问控制(AC)
  • 资产管理(AM)
  • 审计与问责(AA)
  • 意识及训练(AT)
  • 配置管理(CM)
  • 识别和认证(IDA)
  • 事件响应(IR)
  • 维护(MA)
  • 媒体保护(MP)
  • 人事保安(PS)
  • 实物保护(PP)
  • 恢复(RE)
  • 风险管理(RM)
  • 保安评估(SAS)
  • 态势感知(SA)
  • 系统和通信保护(SCP)
  • 系统和信息完整性(SII)
图图表

时间表和成本

虽然CMMC的草案版本目前可供审查, the final version of CMMC is not expected to be released until January 2020. CMMC将于2020年6月开始出现在rfi中, and the expectation is that it will start appearing in RFPs in September 2020.

因为这与价格有关, CMMC网页的常见问题解答部分指出, 认证的成本将被认为是允许的, 可报销的费用,不会令人望而却步. 对于需要CMMC的合同, you may be disqualified from participating if your organization is not certified. 考虑到, we expect future RFIs and RFPs will allow prime contractors subcontractors to work the cost of compliance into their bids.

图图表

CMMC评估

bet9游戏平台 has successfully completed the Certified Third-Party Assessor Organization (C3PAO) accreditation process and applied for the CMMC ML-3 assessment performed by the Defense Contract Management Agency’s (DCMA) Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). 施耐德·唐斯是C3PAO候选人 and pending a successful CMMC ML-3 assessment, bet9游戏平台 will be authorized to provide certification assessments for the Department of Defense’s (DoD) 网络安全成熟度模型认证 (CMMC) program. 

施耐德倒下有何帮助?

施耐德·唐斯是C3PAO候选人. Our team currently offers CMMC readiness and consulting services as a Registered Provider Organization (RPO). Our team includes several members currently in the process of applying for CMMC Certified Assessor status. OSCs should note that a single firm cannot perform both consulting and audit services for a single client per the CMMC-AB standards. 与此同时, 直到这些要求公之于众, we can help your organization prepare for CMMC by performing an assessment against the NIST 800-171 framework. 要了解更多关于我们的CMMCbet9平台游戏,请下载我们的 CMMCbet9平台游戏概述.

欲了解更多信息,请发送电子邮件 埃里克·赖特.

查看我们的其他IT风险咨询bet9平台游戏和功能

网络安全资源

图书馆资源

探索我们的网络安全资源库, 包括案例研究, 白皮书, 最佳实践和专家思想领导.

了解更多 >

我们对

bet9游戏平台’ experts deliver analysis about the cybersecurity trends that impact our clients and organizations of all types and sizes.

了解更多 >

bet9平台游戏