★ ANNUAL REVIEW 2027 SPONSORSHIPS NOW OPEN   Learn more →

Log In  |  Become a Member  |  Sponsor  |  ⌕ Search

News/Cyber & Privacy/Cybersecurity Maturity Model Certification and the Importance of Culture
Free SampleYou’re reading a free sample of the Cyber & Privacy Brief. Members get every case digest like this, six days a week.See Membership Options
DoD·Cyber & Privacy Brief

Cybersecurity Maturity Model Certification and the Importance of Culture

In many of the discussions about the Cybersecurity Maturity Model Certification (CMMC), I find one thing lacking. This is an emphasis on developing a culture of cybersecurity within Defense Industrial Base (DIB) contractors and how that translates into reality for companies large and small. Achieving certification at any of the 5 CMMC maturity levels isn’t just a one-time or even triennial event (every 3 years) to demonstrate compliance with tens or hundreds of security practices to a certified 3rd party assessor (C3PAO). Businesses that think this way may be in for a rude awakening as they go through the initial assessments. And even more so as the CMMC model evolves and becomes more challenging over time.

Source: 

Not ready to join? Take the free Pub K Weekly digest.One email. Free. Top industry articles, the community calendar, and the latest job postings.