Department of Defense DFARS Interim Rule

Department of Defense DFARS Interim Rule cybersecurity article

On September 29th 2020, the Department of Defense (DoD) issued a Defense Federal Acquisition Regulation Supplement (DFARS) interim rule which was titled “Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)”. The new rule was highly anticipated, as it was to address the new Cybersecurity Maturity Model Certification (CMMC) that was released earlier this year and discuss the DoD’s implementation of the CMMC in the Defense Industrial Base (DIB). The interim rule added the following contract clauses:  Many people were shocked to learn that the new DFARS interim rule also added two new cybersecurity contract clauses on top of the CMMC clause, that will affect new contracts starting November 30th, 2020. There has been a lot of talk about the new interim rule and its requirements, as well as misinformation about the new rule. We want to assure you, the new interim rule is not as scary as it sounds or as some people are making it out to be. With that being said, let’s take a closer look at the new interim rule. We will only be looking at the contract clauses 252.204-7019/7020 in this post. We will discuss the CMMC clause (252.204-7021) in a future post. If you want to learn more about the CMMC now, please check out this video where we introduce and explain the CMMC in detail: https://www.youtube.com/watch?v=1CKjn5ztXCs  New DFARS Requirements  The interim rule also added the following contract clauses: 252.204-7019 “Notice of NIST SP 800-171 DoD Assessment Requirements” and 252.204-7020 “NIST SP 800-171 DoD Assessment Requirements”. These two contract clauses have gone into effect starting November 30th, 2020, and unfortunately, there has been a lot of misinformation being spread about these two clauses. Please read below for an in-depth overview of everything that you should be aware of regarding the two new DFARS clauses 252.204-7019 and 252.204-7020.  DFARS 252.204-7019 & DFARS 252.204-7020 Requirements:  Who This Applies to:   What is the Objective? The reason for all above requirements is to eventually become CMMC certified for CMMC level 3 (the CMMC maturity level that handles CUI). The CMMC will be rolled out over the next few years until September 30th, 2025. All contracts are expected to have the CMMC after that date. Our Suggestion Example Scenarios:  Our hope is to help answer all of your questions regarding the new DFARS interim rule, and the three clauses that have been added. We strongly recommend that you read the interim rule for yourself, which can be found here. Does your company have the right cybersecurity plan in place? Contact us for more information on how our customizable services may help protect your business. Posted by Brendan Kenney

Why You Need to Train Your Employees—What Is the Worst That Could Happen?

Why You Need to Train Your Employees—What Is the Worst That Could Happen? cybersecurity article

With email and other forms of telecommunication becoming more prominent than ever in the workplace, these forms of communication can leave holes in a company’s cyber security platform. Email addresses and public profiles can be hotspots of information that an attentive attacker can look to for gathering information and developing strategies to target the end user with attacks utilizing phishing, vishing, and other forms of social engineering. This leaves the everyday employee at the highest risk for these types of attacks. As a defense, proactive and continuous measures can help end users identify any emails that could be suspicious or malicious and help cybersecurity professionals identify these types of attacks and work to mitigate the damages caused.  Malicious attackers will target the end user with such tactics such as Social Engineering, trying to act as someone they are not and looking to trick these users to either transfer funds to them or divulge confidential information such as usernames and passwords in order to gain access to the victims’ credentials. With this they can look to further exploit a business or system, gathering business documents, companies’ data including names and private contact information. This can include customer data such as credit card or payment information, personal identification information and private contact information.  These types of attacks, if successful, can also lead to ransomware encrypting information on the businesses network and “holding it for ransom”. These can be extremely dangerous and costly if they propagate over a network. The methods of encrypting the data are often times extremely hard to decrypt or figure out without paying for the key. Dealing with ransomware groups and providing payment will never guarantee that the ransomware group will provide the data or give the key even after the payment is made.  Now you may be asking what can be done to defend against these types of social engineering, phishing and more complex attacks? The simplest and easiest answer is to educate your employees. Continuous and ever-evolving training can teach end users to look out for key giveaways to these types of attacks. It is important to have end users that can identify scam or phishing communications as they are sent. Having users understand how to react when receiving one of these emails can save a company in the long run. An educated end user base can act as a strong preventative defense against social engineering-type attacks and give the team who handles such attacks a heads up that these types of attacks are being launched. This simple idea of continuous and consistent security awareness training can be far cheaper than reacting after an end user was phished. Does your company have the right cybersecurity plan in place? Contact us for more information on how our customizable services may help protect your business. Posted by Kyle Rauschelbach

Where To Begin If You Have No Security Training Program

Where To Begin If You Have No Security Training Program cybersecurity article

In today’s day and age, many companies are realizing that security training is necessary for all employees. After all, the employees within an organization are the weakest link and are the easiest to exploit when looking for confidential information or when looking to do damage to a target company. Many companies do not know where to start when discussing security training for their employees. Most end up hiring outside help to assist in this process. But for those companies that cannot afford outside assistance on this issue, or for those that would like to keep this training in house, here are a few tips to get your Security Training Program started. Provide Basic Security Awareness Training Sessions for Users Most employees in the workplace are not aware of the threats that we face online every day. Most people will go through their work life clicking on all the links they receive in their inbox or submitting personal information in online forms on multiple occasions. This type of behavior is something we want to stop or limit in the workplace and the first step to eliminating that behavior is educating your users on what to look out for. There is a plethora of online resources available such as whitepapers, free online lessons, and various articles across the internet where you can gain valuable information to pass on to your users. At some organizations, you may already have an Information Technology or Information Security staff member who already has this knowledge that can be passed on to others. Take the time to schedule in person or virtual meetings where your more knowledgeable staff members or leadership can teach your other staff members valuable tips and tricks and things to look out for online and in their inbox. Test Your Users with Phishing Simulations After educating your users you are going to want to test their knowledge and what they have learned in a real-world scenario. One of the best ways to do this is to create a Phishing Simulation for all your users. These Simulations send emails that mimic emails they may receive in the workplace from potential attackers and test how they react to the email they receive. Will they open the email and click on a link, potentially giving an attacker access to their systems? Will they see the email, reflect on what they learned and ignore or delete it? These simulations are the best way to see what your employees will do in those tough situations. There are many online providers that can provide these tests for free if you sign up on their website. An example would be KnowBe4, who provides a free phishing test if you sign up on their website. Ensure User Training Occurs Consistently  New threats emerge each and every day, and the types of threats that emerge are evolving at a rapid rate. Because of this, it is important that your users receive training on at least an annual basis. This training can be done using your own staff as mentioned in this post, or if after a year you believe you do cannot constantly provide this training for your users, you may want to ask outside agencies for assistance.  DataSure24 offers Security Awareness Training for all business sizes and provides full management of the service itself via one of our Security Analysts. Learn more about our Security Awareness Training here. Does your company have the right cybersecurity plan in place? Contact us for more information on how our customizable services may help protect your business. Posted by Connor Karek

Four Proactive Measures to Prepare for a Cybersecurity Incident

Four Proactive Measures to Prepare for a Cybersecurity Incident cybersecurity article

Benjamin Franklin once said, “If you fail to plan, then you are planning to fail”. The same is true when it comes to an organization’s data security program. An organization that is well prepared for a security incident with a robust data security program will not only reduce the likelihood of suffering a security incident, but also significantly reduce the cost of a security incident. Below are four proactive measures your organization can take to prepare for a security incident and reduce your organization’s overall risk. 1. Develop an Incident Response Plan An Incident Response Plan (“IRP”) will establish the method and procedure for identifying, responding, and reporting a security incident. An IRP will set forth, in writing, each key stakeholders’ role in responding to an incident and ensure that every stakeholder is on the same page. An IRP should include the following: 2. Test the IRP with Tabletop Exercises Once an organization’s IRP is established, an organization should regularly test its IRP. This testing can be done through tabletop exercises that simulate a security incident and test the strength of an organization’s IRP. Following the tabletop exercise, an organization can adjust its IRP to make it better equipped to respond to a security incident effectively and efficiently. The Ponemon Institute conducts one of the largest research studies on data security breaches every year and produces a yearly report on the cost of a data breach. Last year the Ponemon Institute reviewed over 500 breached organizations and found that the highest cost saver for a business suffering a data breach was incident response preparedness. Specifically, organizations with an Incident Response Team that also regularly tested its IRP saved, on average, $295,267 in incident response costs when suffering a data breach [i]. This cost savings underscores the importance of developing an IRP and regularly testing the plan with tabletop exercises. 3. Employee Training An organization’s security system is only as strong as its weakest link. That weakest link can be an organization’s employees if they are not trained in best practices for security. Employees should be trained in identifying and preventing a security incident with strong passwords and password management, as well as identifying and reporting phishing emails and malicious links. An organization should also train its employees on how to recognize a security incident and report the incident to the proper stakeholders within an organization. This will help an organization efficiently address a security incident. An organization’s employee training should be completed during the onboarding process as well as yearly so that employees continue to be diligent in their day‑to‑day practices to keep an organization’s systems secure. 4. Vulnerability Scanning and Pen Testing One of the best ways to reduce the likelihood of a security incident is to regularly test an organization’s systems. This can be done with regular vulnerability scanning and penetration testing. Vulnerability scanning will scan an organization’s systems for security weaknesses and determine the vulnerabilities within an organization’s systems. Penetration testing, also known as pen testing, takes a deeper dive into an organization’s system. Pen testing is where an ethical hacker attempts to gain access to an organization’s systems by exploiting its vulnerabilities. A good analogy is if an organization were considered a home, vulnerability scanning would test to see if the doors were locked and pen testing would open the door and see if the doors to the rooms inside the home were locked. It is recommended that an organization conduct vulnerability scanning at least twice a year and pen testing at least once a year. These preventative measures reduce the likelihood of a security incident because an organization can use the results from vulnerability scanning and pen testing to patch weaknesses and make system modifications to further secure its systems. In addition, the Ponemon Institute “Cost of a Data Breach” study found that organizations that conduct vulnerability scans reduce the cost of a data breach by $172,817 [ii]. Therefore, in addition to preventing a security incident, vulnerability scans and pen testing will reduce the costs of a security incident, if and when a security incident should occur. In sum, take proactive measures to reduce the risk of a cyber security incident, as well as reduce the costs of an incident when it occurs. An Incident Response Plan, employee training, vulnerability scanning, and pen testing, are a few proactive measures an organization can take to secure its systems and best prepare for a security incident. If you have questions on how this specifically relates to your organization Greg Gaglione of Rupp Baase Pfalzgraf Cunningham can help. As it is often the case in life, those that are proactive and prepare, will perform the best. The same is true for an organization and its data security program. DISCLAIMER: This article is for general information purposes only. The information in this article does not, and is not intended to, constitute legal advice. Contact a qualified attorney to obtain advice with respect to any specific issue or legal question.Attorney Advertising. [i] Ponemon Inst., 2020 Cost of a Data Breach Study 42 (2020)[ii] See id. Does your company have the right cybersecurity plan in place? Contact us for more information on how our customizable services may help protect your business. Posted by Greg Gaglione

Password Complexity – What Matters the Most?

The number of daily internet users is consistently increasing, which means the number of vulnerable passwords is increasing as well. As a result of users’ increased presence online, malicious attackers are looking to exploit the lack of complexity in user passwords. When creating a new account on a website, streaming service, etc., you often see specific password requirements for length and character complexity (certain length, special characters, capitalization, etc.). While sometimes this can seem overbearing and annoying, it is important to understand that a complex password is often a more secure one. To best explain how attackers look to exploit passwords, we have created a die scenario that we will walk through. Through this example, we will look at how the complexity and length of a “secret sequence”, can make it harder for a hacker to break into an account. The setup begins by selecting a sequence that we must keep secret; this secret sequence will be our password. For our example, our secret sequence will be “2145”. Using the dice shown (Image 1), it is impossible for someone rolling each one to come up with our secret sequence. No matter how many times the dice are rolled, there are simply not enough dice to match our sequence (there are 4 numbers in our secret sequence, therefore an attacker would need 4 die to guess our sequence). If our numbers were more limited, even by one die, an attacker would be able to guess our secret sequence with ease. In scenario 2 (Image 2), we have added 2 new dice to the sequence. Using the same secret sequence, “2145”, the number of dice now meets the length requirement to guess our secret sequence, but the highest number on the dice is only 4. So again, no matter how many times a person rolled this set of dice, they will never be able to guess our secret sequence. In scenario 3 (Image 3), we have increased the total number of dice to five and total number of sides on each die to six. This combination of the dice gives a person the chance to finally guess our secret sequence. With five dice with six sides each in total, someone randomly rolling the dice would eventually be able guess our secret sequence of “2145”. If you wanted to add more security to your number sequence, you would want to increase the length of the overall sequence and use more numbers than just 1-6. By making these easy and simple changes, you would increase the difficulty of guessing the secret sequence immensely. Now let’s take this example and apply it to passwords. Hackers regularly perform an attack known as a “Brute Force”, where they are attempting to guess account passwords. Hackers can use computer programs to automate this attack so they can attempt thousands of passwords in just seconds. These brute force attacks can be carried out where an attacker has the program randomly guess characters and numbers in a sequence until they obtain access to the account. Hackers frequently use a brute force method, known as a “Dictionary Attack”. This type of attack uses common words that one would find in a dictionary, to guess an account’s password. Hackers will include numbers and special characters with these words, so the chances of them guessing your password are increased. So, how exactly does one protect themselves from a hacker guessing their password or obtaining the password from a brute force attack? Just like in our example, we can increase the complexity of our passwords. By making simple changes to increase the complexity of your account passwords, such as using longer passwords, with more complexity in the characters (i.e. special characters, numbers, and a mixture of lower case and capitalized letters), you can reduce the risk of your account’s password being guessed by a hacker. This will protect your personal, business, or sensitive information from being stolen by hackers. Does your company have the right cybersecurity plan in place? Contact us for more information on how our customizable services may help protect your business. Posted by Kyle Rauschelbach with additional contributors Mike Harber, Brendan Kenney & Max Winterburn

Who Let the Hacker in the Front Door?

These days, it’s not enough to just have a well-secured system and network protecting your business in the world we live in. Equally as important, you need to ensure that your employees are not letting the bad guys in through your front door. It has been well documented by Law Enforcement agencies and many security professionals that over 90% of all Ransomware attacks can be attributed to actions taken by an employee. This is not to say they are a willing accomplice or that their acts were intentional. Simply by them clicking on a malicious email link, falling prey to a doctored-up email, or visiting an unfamiliar website can cause significant disruption and potentially jeopardize your business. Some recent trends you may not be aware of: (KnowBe4) Over the years, DataSure24 has worked on several incident response events where an attack was initiated almost immediately after an employee “clicked “on something they should not have. With each event, there was no Cybersecurity Incident Response plan in place, and the time to recovery was significantly impacted. Other attacks can vary where the bad guys embed themselves in your network and lie undetected for many months only to learn more about how to best inflict the most pain on your organization and to ensure their ransom will be paid, or your data will be removed. Some best practices that would improve your cybersecurity posture are: implementing a 24/7 Managed Detection and Response service, an ongoing Vulnerability Management program, and performing regular security assessments. One of the top seven things you can do in building a solid defense in depth strategy to protect yourself from a cyber-attack is developing a Security Awareness Training program (SAT). Keys to a Successful Security Awareness Training Program: To ensure your Security Awareness Training program’s success, it is recommended that you have early buy-in from senior management, including activeparticipation. Additionally, having someone with either a Security orTraining background (both would be a plus) within your organization to manage the program or contracting with an outside firm will help to ensure success. Not only do I believe strongly in the benefits of a good Security AwarenessProgram, but several prominent compliance organizations believe this as well. Manyorganizations have to comply with various compliance acts to increase protection and avoid violations and fees, as listed below: Implementing a Security Awareness Training Program for your employees is extremely important in order to reduce your exposure to potential threats. The DataSure24 team can assess your employees’ current cybersecurity awareness and develop a training solution that fits your organization and its culture. For more information, visit our Security Awareness Training page. Does your company have the right cybersecurity plan in place? Contact us for more information on how our customizable services may help protect your business. Posted by Peter Ronca

Introduction to Amazon Web Services (AWS)

AWS is the world’s most comprehensive and broadly adopted cloud platform, which offers services from data centers all around the world. As of 2020, around 50 percent of all corporate data is stored in the cloud. The amount of data stored in the cloud has increased by 20 percent in the past 5 years, and that percentage is exponentially increasing every day as companies seek improvements in security, reliability, and cost of their organization’s resources. If you work in the IT industry, you have most likely heard of Amazon’s cloud platform known as Amazon Web Services, or AWS. However, you might be wondering what it is, what you can use it for and how it can help your organization. AWS’s core infrastructure is built to satisfy security requirements for all industries including the government, global banking, and other highly sensitive industries. AWS supports 90 different security standards and compliance certifications, and is backed by a deep set of cloud security tools. AWS offers a pay as you go approach for pricing, which makes testing the waters or scaling your organization’s resources easy and affordable. AWS offers 200 fully featured services to cover everything from simple data storage (Amazon S3), to commanding and controlling satellites (AWS Ground Station). Although controlling satellites is not the most frequently used among everyday organizations, it goes to show that the abilities of AWS are massive. Some of the more commonly used services, from my experience, such as Amazon S3, AWS Lambda, Amazon EC2, Amazon RDS, and DynamoDB, give organizations the ability to remove the need for on-prem servers, increase reliability and security of their resources, while decreasing costs of storage and compute power. On average, migrating your organizations’ infrastructure to AWS has an infrastructure cost savings of 31%. Also, migrating reduces unplanned downtime of organizational resources by 69%, while reporting 43% fewer security incidents per year. AWS has endless knowledge-based articles for helping with almost any problem you encounter while using their services. They have designed services specifically for migration to the cloud, and offer solutions to migrate any workload such as applications, websites, databases, storage, physical and virtual servers or even entire data centers. Organizations of every type, size, and industry are using AWS for a wide variety of use cases. Cloud computing is the future of computing, and the benefits are undeniable. From the elasticity of resources, to being able to deploy globally in minutes. This blog entry is the first in a series we will be posting on the topic of Amazon Web services. We will be detailing different use cases for a number of Amazon Web Services, types of cloud computing, migration tutorials, web application hosting, and others. Does your company have the right cybersecurity plan in place? Contact us for more information on how our customizable services may help protect your business. Posted by Bryan Cowing

Understanding DoD Frameworks

The Department of Defense or DoD provides the United States of America military with forces that are needed to deter war and ensure the nation’s security. To accomplish this mission, the DoD is partnered with the Defense Industrial Base sector, which involves over 100,000 Defense Industrial Base companies and their subcontractors to provide essential materials and services to the DoD. This includes research and development, as well as designing, producing, delivering, and maintaining military weapons systems and components or parts. Within the last decade, the DoD has worked continuously with the Defense Industrial Base sector to enhance the protection of Controlled Unclassified Information (CUI) within unclassified networks that belong to organizations within the Defense Industrial Base sector. What exactly is CUI and why does it need to be protected? The DoD has defined CUI as: Information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. To adequately safeguard CUI, the DoD has implemented several frameworks and contractual requirements that organizations within the Defense Industrial Base that handle CUI must comply with and implement. There are three main frameworks/contractual clauses that are currently being used to safeguard CUI or in the process of being implemented to safeguard CUI: The Defense Federal Acquisition Regulation Supplement also known as DFARS is the DoD’s Federal Acquisition Regulations (FAR) supplement that was published in December 2015. The primary objective of the DoD’s acquisition is to acquire quality supplies and services that satisfy users’ needs with measurable improvements and operational support at a fair and reasonable price. Within the DFARS clause there is a set of Cybersecurity requirements that DoD contractors must adhere to, to maintain or obtain a DoD contract. This requirement is in section 252.204-7012 of DFARS and is titled “Safeguarding Covered Defense Information and Cyber Incident Reporting.” The objective of this clause was to protect CUI and the flow of CUI on the contract holder’s information systems and networks. Within this clause, contractors within the Defense Industrial Base are required to provide adequate security on all covered contractor information systems. The DoD requires that the contractor’s information system and network implements the security requirements within NIST SP 800-171 which is titled “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations.” This publication that was developed by NIST is guidance for protecting the confidentiality of CUI when it resides on and flows through nonfederal organization’s information systems. Within NIST SP 800-171, there are 110 security controls that are spread out through 14 different control families or domains. These domains range from Access Control to System and Information Integrity. The implementation of the security controls from NIST SP 800-171 is recognized to be adequate security that protects against the loss, misuse, and unauthorized access to or modification of CUI. So, on top of the security controls from NIST SP 800-171, organizations also need to be compliant with additional requirements that were specific to DFARS section 252.204-7012. The main requirement is the Cyber Incident Reporting Requirement. This requirement in the clause states that when a contractor discovers a cyber related incident, the organization must conduct an investigation to determine the scope, impact, and results of the incident. The contractor must then submit a report of their findings to the DoD. To be compliant with the DFARS requirements, all it takes is for an organization to self-attest that they comply or will comply with the security controls and requirements within DFARS. There is no certification process for NIST 800-171 or DFARS, it is all based on the honor system. Therefore, it did not take the DoD long to realize that without a certification process, many organizations were performing self-assessments and were claiming to be DFARS compliant, without fully understanding the security controls and how to safeguard CUI within their information systems. This leads us to the creation of the CMMC. The CMMC was released on January 31st of 2020 and the intent of the CMMC is to incorporate a certification process into DFARS and use it as a requirement for contract award with the DoD. Much like DFARS, the purpose of the CMMC is to enhance the protection of CUI, within the Defense Industrial Base. CMMC measures cybersecurity maturity with 5 different levels. Each of these levels consists of a set of processes and security practices. There are a total of 171 security practices or controls throughout 17 different control families and 5 different processes within the CMMC model. Organizations within the Defense Industrial Base that handle CUI will be required to be at least CMMC level 3. CMMC level 3 consists of all 110 controls from NIST SP 800-171, as well as 20 other security practices specific to CMMC. Additionally, organizations will be required to implement 3 processes which are designed to mature the cybersecurity program. A major difference between CMMC and DFARS, is that CMMC requires assessments to be performed by 3rd party assessors only. Organizations are still responsible for implementing all of the cybersecurity requirements associated with the CMMC. However, there are no more self-assessments like there were with DFARS. All assessments must be performed by a CMMC-Accreditation Body (AB) approved assessor and then the assessment results will be sent to the CMMC-AB for review before a CMMC certification is awarded to the organization seeking certification. Does your company have the right cybersecurity plan in place? Contact us for more information on how our customizable services may help protect your business. Posted by Brendan Kenney

Cybersecurity: Where to Start (or Restart)

Every business, no matter the type or size, needs to take a proactive approach to cybersecurity. You do not want to find yourself questioning your business’s cybersecurity capabilities during a cyber incident or data breach. By having a strong cybersecurity program in place, not only will you be able to respond to a cyber incident quickly and effectively should one occur, but also mitigate the risk of becoming a target for a cyber-attack in the first place.   To develop an effective cybersecurity program for your company (without requiring a lot of resources), here are some important initial steps to take:  Here are some easy, but effective, actions you can take to protect your business’s sensitive data and core assets right now:   1. Harden Core Assets System hardening is the process of securing a system by reducing the amount of potential attack vectors, reducing the security risk. Some ways to secure your systems are limiting access to the system, regularly updating the system and its software, closing unused ports, removing unnecessary software, and collecting and reviewing audit logs. The Center for Internet Security (CIS) has published numerous benchmarks for different operating systems, software, network devices, mobile devices, and cloud providers. It is highly recommended that you start here for your system hardening needs.    2. Conduct Vulnerability ScansVulnerability scanning is the process of using automated tools to search for known vulnerabilities and provide details on what can occur if the vulnerability is exploited, and most importantly, how you can remediate the vulnerability.   There are two types of vulnerability scanning: Internal vulnerability scanning consists of deploying a scanning device on your internal network to search for vulnerabilities on other devices on the network.External vulnerability scanning uses a special scanner which is outside your network and checks your public facing devices and websites for vulnerabilities. It is highly recommended that an organization perform internal vulnerability scans at least quarterly, and external vulnerability scans at least once annually. Once vulnerabilities are discovered, technical teams should work to follow the guidance from the scan results to remediate the vulnerabilities on your organization’s systems and network. (Nessus, OpenVAS, Qualys, and Nikto are just a few examples of free or cost-effective vulnerability scanning tools)   3. Establish Proactive Security Defenses Taking a proactive approach to cybersecurity has many advantages and is not as difficult as you may think. Here are some things you can do right now:    4. Adhere to a Cybersecurity Framework & Create Security Policy Documentation  Your organization should have security policy documentation that details the organization’s security requirements.   A good security policy will:  The first step to creating effective security policy documentation is to identify and choose a cybersecurity framework that your organization wants to adhere to. There are many cybersecurity frameworks that your organization can adopt to provide guidance for protecting your sensitive data and core assets.   We recommend the National Institute of Standards and Technology Special Publication 800-171 r2 (https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r2.pdf). The publication also provides guidance on how to implement these best practices, so you can protect your information and organization. 

CMMC 2.0

In 2020, the manufacturing industry saw a 300% increase in cyberattacks, and moved from the 8th most targeted industry by cybercriminals to the 2nd, behind only finance and insurance. That is not surprising, as manufacturing businesses harbor a wealth of information that hackers can use to extort millions.  With more than 250,000 Defense Industrial Base (DIB) companies and subcontractors involved in work related to the U.S. Government, a data breach presents a significant threat to sensitive federal and unclassified information, as well as to national security. Government agencies responded to the cyber threats by proposing stricter regulations for companies that protect sensitive data.  In early 2020, the Cybersecurity Maturity Model Certification and the IoT Cybersecurity Act were both introduced to ensure minimum cybersecurity regulations for companies that work with government agencies. The CMMC defines levels of cybersecurity required for DoD contractors to bid on and complete projects for the DoD. This certification ensures all companies and subcontractors who supply DoD establish a specific framework for cybersecurity, to protect the data that the DoD entrusts them with.  Not surprisingly, there have been changes to the program since CMMC 1.0’s introduction in 2020.    CMMC 2.0 includes five key changes to the program: 1. The CMMC now defines 3 levels of cybersecurity required for DoD contractors to bid on and complete projects for the DoD. (The new CMMC 2.0 levels are based on the type of information DIB companies handle)  2. While CMMC 1.0 included 130 practices, CMMC 2.0, introduced in November 2021, is a 1:1 reflection of NIST SP 800-171, with 110 practices. The 20 practices added by the DoD have been removed. 3. CMMC 1.0 only let contractors and subcontractors pass with a perfect assessment score. Theres was no flexibility to remediate. CMMC 2.0 allows contractors and subcontractors to sign DoD contracts using the Plan of Actions and Milestones (POAM). Organizations who have not yet fully implemented NIST 800-171 can submit a solid plan for achieving full compliance, with specific dates and a timeline. This POAM is submitted before work begins and enables organizations to begin working for federal agencies whilst they simultaneously work towards full implementation of 800-171. 4. The maturity level is no longer based on processes and policies, but on practices used.  5. The maturation model was restructured from 5 levels to 3, to better reflect how mature and reliable a company’s cybersecurity infrastructure actually is.  As threats grow, and companies address cybersecurity regulations enforced by NIST and outlined by recently introduced legislation, companies who fail to address cybersecurity will fall behind. Even worse, these unprepared organizations may become easy targets for cybercriminals.  If you have any questions related to CMMC compliance, contact DataSure24 at info@datasure24.com.