DoD Publishes new DFARS Rule Impacting SPRS

DoD Publishes new DFARS Rule Impacting SPRS

The United States Department of Defense recently published a notice that a new rule, DFARS 252.204-7024, will be published soon. In her recent article (available here for free), Sara Friedman publishes analysis of that new rule, including comments from Robert Metzger, Eric Crusius, and me. The biggest takeaway I see is that DoD is laying a foundation for…

Security Without Governance is not Secure

Security Without Governance is not Secure

Background The Internet has quickly revolutionized the way governments, companies, and other organizations conduct business. But in their haste to gain market share and meet client/constituent expectations, many organizations are pushing out products and services that are not, and using IT infrastructure that is not, secure. This has made it easy for criminals and other…

DoD Adds Scrutiny to Contractor Cybersecurity Programs

DoD Adds Scrutiny to Contractor Cybersecurity Programs

Background Over the past few years, the US federal government has been gradually trying to improve its cybersecurity program, and has been encouraging contractors to do the same. The US Department of Defense led the way in these efforts, including through a variety of initiatives like DFARS 252.204-7012 and the Cybersecurity Maturity Model Certification (“CMMC”) program. The CMMC program…

75/25 – We Need You

75/25 – We Need You

Regan Edens’ LinkedIn post is nothing short of a CMMC national call to action. To bottom line it, there are two facts. According to John Ellis at DIBCAC there have been just shy of 20,000 SPRS scores submitted out of a pool, we are told, of 80,000. Best government estimates are that the interim rule changes…

Contractors not as Suppliers – but as Leaders

Contractors not as Suppliers – but as Leaders

I have to admit that I don’t always read things like the Executive Orders. As a regular citizen, I have always presumed they are filled with political platitudes rather than actionable direction. However, in discussing the Executive Order on Improving the Nation’s Cybersecurity with Jim Goepel, my colleague and founder of the CMMC Information Institute,…

Let’s Go DoD, There is Still Time to Fix CMMC.

Let’s Go DoD, There is Still Time to Fix CMMC.

Thank you, DoD, for showing us that you listen. In 2019 you listened and quickly created CMMC from the ether to answer a monumental need to secure our country’s supply chain. You showed you were listening again last week when you changed CMMC to address the concerns from contractors who felt CMMC 1.x was overly…

End of content

End of content