Amira Armond’s Post

View profile for Amira Armond, graphic

President @ Kieri Solutions | CMMC educator | Cybersecurity advocate

No mention of defense contractors or CMMC in this new DoD playbook on cybersecurity reciprocity. This is written for the government's internal use. However, I'm happy to see evidence that DoD CIO is actively thinking about reciprocity. Reciprocity is different from inheritance. Inheritance is evaluated at a granular level - control by control, requirement by requirement. In general, it is much easier to evaluate inheritance than to evaluate reciprocity. Example of cybersecurity inheritance: Assessor: "Are you performing vulnerability scans to protect your CUI?" Defense contractor: I'm not, but my managed service provider is." Assessor: "Do you have proof that they are actually doing it?" Defense contractor: "They got assessed by an independent audit firm that confirmed they perform vulnerability scans of all their customers. Here is the audit report that shows it." Assessor: "I see that a reputable company did the assessment, they verified the same criteria that I want to see for vulnerability scans, the assessment was performed a few months ago, and that the assessment scope included the department that manages your systems. Looks good. You're "MET" for vulnerability scans." In comparison to inheritance, reciprocity is evaluated as a whole. For the CMMC program, the DoD decides which frameworks are "good enough" for reciprocity. An example of reciprocity: Assessor: "Is your cloud performing all the requirements in CMMC Level 2?" Defense contractor: "No, but it was certified against this other standard, which is pretty stringent too." Assessor: "Hey DoD, do you think that standard is good enough?" DoD: "Yup, we feel it meets or exceeds CMMC Level 2." Assessor: "OK, no further questions about your cloud." No mention of SOC-2 or ISO 27001 in this playbook. This confirms to me that it is very unlikely these will count for anything from a DoD reciprocity standpoint. FedRAMP is the only real candidate I see for CMMC Level 2 reciprocity, though even that isn't official at this point. Shameless plug: Want a double-check on your CMMC preps? Contact Kieri Solutions - Authorized C3PAO to get a Gap Analysis by a Lead Assessor with real world CMMC, 800-171, and Joint Surveillance experience. Nice find, ⚡️Jil Wright! #CMMC

View profile for DoD Chief Information Officer, graphic

Official profile page of the Office of the DoD CIO. Please visit our LinkedIn Company page for postings and connections. Liking, sharing, replying does not equal endorsement.

DoD CIO announces the public release of the DoD Cybersecurity Reciprocity Playbook. This playbook, referenced in the DSD's Reciprocity Memo, provides guidance for employing cybersecurity reciprocity in DoD systems. It defines reciprocity as it relates to cybersecurity, discusses the benefits and risks, and includes example possible use cases. For more information read the playbook here: https://lnkd.in/e4K3d8DQ

  • Image of the cover of the DoD Cybersecurity Reciprocity Playbook
Chris Yu

Lead DevOps Engineer

2mo

Britton

Bob Dorsey

President, R.DORSEY+

2mo

Well done, thank you.

Like
Reply
Kyle Lai

President & CISO @ KLC Consulting | Authorized CMMC C3PAO, CMMC Gap Analysis, Joint Surveillance Voluntary Assessment, CMMC Consulting, COTS Exemption

2mo

Yup. Just internal to the government.

See more comments

To view or add a comment, sign in

Explore topics