CMMC is a US Department of Defense Cyber Risk Framework
At CMMC Plus, we consider CMMC to be Compliance+, but NOT a Continuous Security Improvement Risk Framework
Where to Start
CMMC Program Pros
- Professionally Certified Risk Program
- Rigorously developed assessment program
- Validates that defense contractors actually do what they were already required to be doing
- Will eventually be required by other government organizations (improving our overall security posture as a nation)
- Constantly updated to meet changing threat landscape
- Pre-defines the risk associated with DoD data types, essentially defining data classification
CMMC Program Cons
- Doesn’t support government classified data, so THE most important DoD data still has no externally certifiable risk posture
- Does not manage data classification types not used by the DoD (FCI, CUI, and CTI)
- Does not drive a culture of continuous security improvement. ‘Assigns a predetermined baseline control set’ as opposed to tracking control progress. – Tom Cornelius
- Does not consider business objectives at all
- Allows security dips or failures between certifications every 3 years
- It is not a classic maturity model within specific security controls. It is a program maturity model. ‘Rigor > Security Posture’
- Does not map to CMMI though it looks like it should. This will cause confusion.
- CMMC Level 2 value does not scale, as most contracts will require level 1 or 3 certification
- CMMC levels 4 and 5 will be driven by contract requirements as opposed to security needs
- The cost of being an RPO or C3PAO is fixed, meaning it dramatically impacts small businesses more than large.
Why Do We Need CMMC Plus?
This is just a great blog post about understanding the value of CMMC and some of the vernacular. After you read it, we are going to disagree with the article in some ways, but not because it is wrong, but how we WANT to actually use the words in a way that is more manageable for contemporary cybersecurity teams and leaders.