<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DoD Cybersecurity Maturity Model Certification CMMC in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/42708#M3122</link>
    <description>&lt;P&gt;Dr. Shelton,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you saying that the CMMC AB is going to require or accept DOD 8570 Certifications in lieu of custom curriculum they are developing for the RP - Registered Practitioner, CP Certified Professional, and CA Certified Assessor programs? Because those sound like their own custom certifications complete with Maturity Levels.&lt;BR /&gt;&lt;BR /&gt;They are going to a lot of trouble to register vet and train LPP's and LTP's who will develop and teach their certification information which is describe as "rigorous". Additionally, they are also becoming a certification body under ISO/IEC 17020 &amp;amp; 11. So while I think you are right in the short term for the general DoD IT individual, I think they are reinventing the wheel for those practitioners working in CMMC eco system. This could lead to two competing standards. Hence my question. If the government is developing its own Cyber Security Certifications, why would they continue to support competing commercial certifications under 8570?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 21 Jan 2021 15:01:13 GMT</pubDate>
    <dc:creator>CyberMenyaPro</dc:creator>
    <dc:date>2021-01-21T15:01:13Z</dc:date>
    <item>
      <title>DoD Cybersecurity Maturity Model Certification</title>
      <link>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/30858#M2020</link>
      <description>&lt;P&gt;For a new DoD contractor requirement that is supposedly being released in January, just a few weeks from now, the industry and the DoD sure have seemed quiet about the CMMC.&amp;nbsp; Have any of you been taking preparatory steps?&amp;nbsp; Have any good resources besides the draft and FAQ (&lt;A href="https://www.acq.osd.mil/cmmc/faq.html" target="_blank"&gt;https://www.acq.osd.mil/cmmc/faq.html&lt;/A&gt;) ?&amp;nbsp; The FAQ says the first version will be released in January and then implemented as a requirement starting in June, which is a pretty quick time frame considering they haven't even specified how third party assessors become certified to issue CMMCs.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2019 18:32:48 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/30858#M2020</guid>
      <dc:creator>N_Bakewell</dc:creator>
      <dc:date>2019-12-20T18:32:48Z</dc:date>
    </item>
    <item>
      <title>Re: DoD Cybersecurity Maturity Model Certification</title>
      <link>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/30865#M2021</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/545444613"&gt;@N_Bakewell&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;(&lt;A href="https://www.acq.osd.mil/cmmc/faq.html" target="_blank" rel="noopener"&gt;https://www.acq.osd.mil/cmmc/faq.html&lt;/A&gt;) ?&amp;nbsp; The FAQ says the first version will be released in January and then implemented as a requirement starting in June, which is a pretty quick time frame considering they haven't even specified how third party assessors become certified to issue CMMCs.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;This is gonna get VERY interesting. Recalling that DoD is still doing a shoddy job of enforcing the individual certifications requirements under 8570, I will be watching for how long it takes them to actually put the CMMC into contracts and enforce them for companies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2019 20:54:56 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/30865#M2021</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2019-12-20T20:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: DoD Cybersecurity Maturity Model Certification</title>
      <link>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/30888#M2023</link>
      <description>&lt;P&gt;This is certainly going to become very interesting indeed - the Australian Government are doing a similar scheme via the IRAP certification to ensure that Federal Government agencies comply with mandated controls.&amp;nbsp; Someone is going to be making a lot of money, and the rush to get certified will generate a lot of jobs for years to come.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cyber.gov.au/irap/irap_assessments" target="_blank"&gt;https://www.cyber.gov.au/irap/irap_assessments&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2019 05:07:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/30888#M2023</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-12-23T05:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: DoD Cybersecurity Maturity Model Certification</title>
      <link>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/33481#M2438</link>
      <description>&lt;P&gt;Well I assure you this is happening.&amp;nbsp; They have come to the realization that the initial aggressive timeline was a bit too unrealistic but you can expect CMMC to be in about 15 "pathfinder" contracts in the fall time frame with that flowing down to about 100 suppliers below.&amp;nbsp; There will be opportunities to 3PAO's, individual and organizations, to perform the assessments. Biggest thing I see now are the snake oil salesmen out trying to tell folks they can sell you something to make you CMMC compliant, ummmmm no......&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 15:35:47 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/33481#M2438</guid>
      <dc:creator>TXWayne</dc:creator>
      <dc:date>2020-03-09T15:35:47Z</dc:date>
    </item>
    <item>
      <title>Re: DoD Cybersecurity Maturity Model Certification</title>
      <link>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/33517#M2442</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1506319407"&gt;@TXWayne&lt;/a&gt;&amp;nbsp;&amp;nbsp; This is interesting, whilst the Australian Security Directorate, have told all those who went through the IRAP certification process, that the certification for Cloud will be dropped in July 2020.&amp;nbsp;&amp;nbsp; The rationale is to open up competition - more likely a lot more work by the Agencies themselves to verify whether or not they should be using cloud services from those entrepreneurs, who may have very little regard for security &amp;amp; privacy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A big headache coming up I reckon.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 03:52:32 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/33517#M2442</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2020-03-10T03:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: DoD Cybersecurity Maturity Model Certification</title>
      <link>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/40903#M3043</link>
      <description>&lt;P&gt;The rule will be final at the end of this month. This is getting real.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm working for a company that has been doing NIST 800-171 assessments and is already doing CMMC assessments. We are in line to be a CMMCAB Registered Practitioner.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Norris Carden&lt;/P&gt;&lt;P&gt;MADSecurity&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 14:56:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/40903#M3043</guid>
      <dc:creator>CyberNorris</dc:creator>
      <dc:date>2020-11-18T14:56:45Z</dc:date>
    </item>
    <item>
      <title>Re: DoD Cybersecurity Maturity Model Certification</title>
      <link>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/42687#M3119</link>
      <description>&lt;P&gt;Does anyone know what happens to DoD 8570 certifications like the CISSP once CMMC is fully implemented?&amp;nbsp; It seems as though they may be reinventing the wheel on Cyber Security Training when there are already 100's of certifying organizations like ISC2 providing this globally recognized training.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 21:31:14 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/42687#M3119</guid>
      <dc:creator>CyberMenyaPro</dc:creator>
      <dc:date>2021-01-20T21:31:14Z</dc:date>
    </item>
    <item>
      <title>Re: DoD Cybersecurity Maturity Model Certification</title>
      <link>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/42699#M3120</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/989136085"&gt;@CyberMenyaPro&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Does anyone know what happens to DoD 8570 certifications like the CISSP once CMMC is fully implemented?&amp;nbsp; It seems as though they may be reinventing the wheel on Cyber Security Training when there are already 100's of certifying organizations like ISC2 providing this globally recognized training.&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Samuel,&lt;/P&gt;&lt;P&gt;I am no longer working in that arena, but for many years I was directly&amp;nbsp; involved with and tracking 8570 aspects and implementation. That said, I doubt that will CMMC will subsume or replace the basic 8570 structure. That is because 8570 is about the certified capability of individual infosec workers, including DoD employees, military members, and contractors. CMMC, on the other hand, is about the organizational expertise and approach of contracted companies performing infosec work for DoD. CMMC is not about individual certifications, It is about the processes a company has established and can prove they follow in dong infosec work.&lt;/P&gt;&lt;P&gt;This is not a wheel re-invention, it is about adding a second wheel to your vehicle.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Summary: CMMC will not cause 8570 to go away because it supplements 8570, rather than replace it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 13:50:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/42699#M3120</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2021-01-21T13:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: DoD Cybersecurity Maturity Model Certification</title>
      <link>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/42701#M3121</link>
      <description>&lt;P&gt;What Craig says is correct but I wouldn't even say CMMC supplements 8570, there really is no connection between the two at all for the reasons he described.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 14:01:23 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/42701#M3121</guid>
      <dc:creator>TXWayne</dc:creator>
      <dc:date>2021-01-21T14:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: DoD Cybersecurity Maturity Model Certification CMMC</title>
      <link>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/42708#M3122</link>
      <description>&lt;P&gt;Dr. Shelton,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you saying that the CMMC AB is going to require or accept DOD 8570 Certifications in lieu of custom curriculum they are developing for the RP - Registered Practitioner, CP Certified Professional, and CA Certified Assessor programs? Because those sound like their own custom certifications complete with Maturity Levels.&lt;BR /&gt;&lt;BR /&gt;They are going to a lot of trouble to register vet and train LPP's and LTP's who will develop and teach their certification information which is describe as "rigorous". Additionally, they are also becoming a certification body under ISO/IEC 17020 &amp;amp; 11. So while I think you are right in the short term for the general DoD IT individual, I think they are reinventing the wheel for those practitioners working in CMMC eco system. This could lead to two competing standards. Hence my question. If the government is developing its own Cyber Security Certifications, why would they continue to support competing commercial certifications under 8570?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 15:01:13 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/42708#M3122</guid>
      <dc:creator>CyberMenyaPro</dc:creator>
      <dc:date>2021-01-21T15:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: DoD Cybersecurity Maturity Model Certification CMMC</title>
      <link>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/42711#M3123</link>
      <description>&lt;P&gt;The CMMC AB is not going to do anything with DoD 8570 certifications. That certification requirement is based on individuals and CMMC is based on assessing and certifying an organization and their IT infrastructure to a specific level in the CMMC model.&amp;nbsp; The two are not connected so they are not competing. Nowhere in NIST 800-171 or CMMC does it specify that an individual needs any specific certification.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 15:10:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/42711#M3123</guid>
      <dc:creator>TXWayne</dc:creator>
      <dc:date>2021-01-21T15:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: DoD Cybersecurity Maturity Model Certification CMMC</title>
      <link>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/42723#M3124</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/989136085"&gt;@CyberMenyaPro&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Dr. Shelton,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you saying that the CMMC AB is going to require or accept DOD 8570 Certifications in lieu of custom curriculum they are developing for the RP - Registered Practitioner, CP Certified Professional, and CA Certified Assessor programs? Because those sound like their own custom certifications complete with Maturity Levels.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;No, i am not saying that at all. I am not familiar with the CMMC details, so I cannot answer about the relationship between 8570 &lt;EM&gt;individual infosec/cybersec&lt;/EM&gt; certifications and &lt;EM&gt;role-specific&lt;/EM&gt; training required for individuals in CMMC assessor organizations that you list. I would assume, but do not know, that under 8570 requirements those seeking to qualify for those roles they would need 8570 certification plus the role-specific training.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;They are going to a lot of trouble to register vet and train LPP's and LTP's who will develop and teach their certification information which is describe as "rigorous". Additionally, they are also becoming a certification body under ISO/IEC 17020 &amp;amp; 11. So while I think you are right in the short term for the general DoD IT individual, I think they are reinventing the wheel for those practitioners working in CMMC eco system. This could lead to two competing standards. &lt;EM&gt;Hence my question. If the government is developing its own Cyber Security Certifications, why would they continue to support competing commercial certifications under 8570?&lt;/EM&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I am not sure, but I think you may be missing an understanding of the nature of &lt;EM&gt;capability maturity models&lt;/EM&gt; (CMM). CMMs are used to evaluate organizations, not individual people. To prove it actuallyh is following the CMM requirements, an organization must undergo an audit or assessment of the policies, procedures, and records to prove they have documented processes that they actually follow in line with the CMM. The assessments are handled by approved assessing organizations, and the individual assessors that work the audits on-sie must be proven as knowledgeable in the field. 8570 establishes generic individual certifications for broad categories of infosec work types. However, there may be more specific training required to perform the work of very specific jobs. I think that is the CMMC role-linked training is that you list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For another cybersec-related&amp;nbsp; program that evaluates contracted companies, but those companies must themselves be certified or accredited at a specified level, look at the federal cloud security provider (CSP) program under FedRAMP. For a cloud provider to get a contract to serve Federal systems they must undergo an external, independent assessment by an approved assessor organization. DoD has supplemented the general FedRAMP program with additional requirements for the level of sensitivity (or classification) of the data to be stored or processed in that cloud.&lt;/P&gt;&lt;P&gt;The CMMC program is somewhat similar to the DoD FedRAMP program in that they are looking at contractors that will be storing and processing government Controlled Unclassified Information on the organization's informtion systems.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The ISO/IEC certification body levels are another layer of showing trustworthy compliance with the desired level of performance.&lt;/P&gt;&lt;P&gt;It is all about who will check the checkers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, to reiterate, no, this is not duplication or re-inventing any wheel. It is about confirming and documenting capability and integrity of individuals (8570) and&amp;nbsp; organizations (FedRAMP &amp;amp; CMMC) to work with sensitive government information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 16:53:20 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/DoD-Cybersecurity-Maturity-Model-Certification/m-p/42723#M3124</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2021-01-21T16:53:20Z</dc:date>
    </item>
  </channel>
</rss>

