Jacob Horne’s Post

View profile for Jacob Horne, graphic

CMMC Town Crier | Ask me about NIST cybersecurity controls | Smashing compliance frameworks for fun and profit | Cyber policy wonk |

3 things have been true since CMMC 2.0 was announced in November 2021 1) CMMC is happening 2) DoD will offer cybersecurity tools and services 3) There is a huge gap between CMMC requirements and DoD's solutions It started with the DoD CIO's Town Hall in February 2022 and has persisted in various panels, presentations, and testimonies since then. Now, years after CMMC became an inevitability, those offerings are formalized in Appendix III of DoD's recent DIB Cyber Strategy: - Network traffic monitoring x2 - Threat detection and blocking x2 - Vulnerability scanning x2 - Cybersecurity program evaluation - Network mapping - Phishing assessments - Asset discovery - Training through Project Spectrum and Blue Cyber Yet the gap between the offerings and the requirements verified by CMMC remains and I see no possible way that changes between now and roll-out of CMMC (which could start as early as the end of this year). The bottom line: hoping that DoD will suddenly change course to match tools and services to the requirements imposed on the DIB is not a strategy. Contractors and subs should plan accordingly.

Mike Balazsy

CMMC Advisory for C-Level Business Leadership - Charting a Course Through Time, Cost, and Risk in the Cyber Domain.

2mo

Nothing like keep’in it real!

Brandon A Fausti, Founder, PMP, MBA, GCAcct, ITIL4, PSM, TQL

SBA HUBZone, WOSB & SDVOSB. ISO 9001/20000-1/27001/31000. Seeking PRIME Federal Contractor Teaming Partners in FED Healthcare, PPBE, and IT Service Management.

2mo

So, you're saying there's a chance?! https://youtu.be/KX5jNnDMfxA?si=GW-15kmS97DaJzwV

Like
Reply
Matt Stamper, CIPP/US, CISA, CISM, CRISC, CDPSE, QTE

Chief Information Security Officer (CISO) / Co-Author: CISO Desk Reference Guide (1 & 2) / Co-Author: Data Privacy Program Guide

2mo

I'd love to see more emphasis of application-level risks (e.g., runtime, APIs, SCA, etc.). Separately, are those prescription?

Bobby Lansing

Product Manager | 🎖 USAF Veteran | Father of 3 | ✝ Christian

2mo
Like
Reply
See more comments

To view or add a comment, sign in

Explore topics