SlideShare a Scribd company logo
FED GOV CON
Webinar
Wednesdays
2020 Series
JSchaus & Associates
Washington DC
+ 1 – 2 0 2 – 3 6 5 – 0 5 9 8
About Our Webinars:
- Every Wednesday;
- Complimentary;
- Recorded;
- YouTube & our Website;
- No Questions
About Us:
Professional Services for
Federal Contractors
- GSA Sched;
- SBA 8(a);
- Proposal Writing;
- Pricing;
- Contract Administration;
- Business Development
Upcoming Events:
FEB 10
5.30-7.30pm
Meet With STATE DPT
and
150 Federal Contractors
Sponsorships Available
Advertise In Our Newsletter:
Reach 16,600+ Subscribers!
Includes Government &
Government Contractors
Hello@JenniferSchaus.com
About Our Speaker:
David Dempsey
Dempsey Fontana, PLLC
www.deftlaw.com
The Dawn Of CMMC
Wednesday,
January 15, 2020
BACKGROUND TO “CYBERSECURITY”
Federal Information Security Management Act(s) 2002/2014
NARA Establishes A “Uniform” Program for “CUI” (32
C.F.R.2002; 81 FED. REG. 63336; Sept 14, 2016
(“CUI BASIC,” “CUI SPECIFIC,” “CUI REGISTRY’)
INFORMATION SECURITY OVERSIGHT OFFICE
REVISED THE NISP ON MAY 7, 2018 (INSIDER THREAT,
FOCI, ACCESS TO CLASSIFIED)
FISMA to NARA to ISSO to NIST SP-171 to CMMC (v.07)
© January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author.
8
2020 – Fed Gov Con Webinar Series - Washington DC
JSchaus & Associates
FEDERAL CYBERSECURITY AND SUPPLY CHAIN REQUIREMENTS
ISOO’S CUI REGULATION INCORPORATES:
NIST SP 800-53 r4 Security and Privacy Controls for Federal
Information Systems and Organizations (updated through Jan.
2015);*
NIST SP 800-171 r1, (Protecting [CUI] in Nonfederal Systems and
Organizations r1 (updated through June 2016)**
* Rev. 5 in final review
**Rev. B in final review
DAWN OF CMMC
© January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author.
9
2020 – Fed Gov Con Webinar Series - Washington DC
JSchaus & Associates
BACKGROUND TO “SUPPLY CHAIN REQUIREMENTS”
2013 NDAA: § 806
2014 NDAA: §§ 325, 811, 391, 942, 3113
2015 NDAA: §§ 834, 1628, 1632
2016 NDAA: §§ 238, 346
2017 NDAA: §§ 1641, 1650, 1841-44
2018 NDAA: §§ 807 (Enhanced Supply Chain Scrutiny), 1631- 1649, 1656, 1659,
1696
2019 NDAA: §§ 880, 881, 889 (permanent authority on supply chain risk)
2020 NDAA: § 881 (technical assistance for SBIR and STTR programs)
© January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author.
10
2020 – Fed Gov Con Webinar Series - Washington DC
JSchaus & Associates
Secure Technology Act – Pub. L. 115-390
§ 101(a) – DHS to “report security vulnerabilities” (US-CERT weekly vulnerability summaries
have been available for years (see “us-cert.gov” & “us-cert.gov/security-publications” &
“uscert.gov/resources” & “us- cert.gov/resources/smb”/ etc.)
► Cyber resilience review at us-cert.gov/resources
§ 201 “Federal Acquisition Supply Chain Security Act of 2018” (authority to review and
designate items / services that federal procurement personnel cannot purchase)
20+ DoD Memoranda (including Feb. 2019 DCMA guidance on CPSR – now at $50 million
threshold)
Culminating in the 2020 bridge to CMMC implementation
© January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author.
11
2020 – Fed Gov Con Webinar Series - Washington DC
JSchaus & Associates
Nov. 14, 2019 OUSD Memorandum on “Assessing Contractor Implementation of
Cybersecurity Requirements” – guidance for 2020
► NIST SP 800-171, Rev. 1 DoD Assessment Methodology, Version 1.0
♥ Levels of Assessment (Basic, Medium, High)
● Annex A - NIST SP 800-171, Rev.1 DoD Assessment Scoring Template
regarding the 110 NIST SP 800-171, Rev. 1 elements
● Annex B – Basic (Contractor Self-Assessment) NIST SP 800-171, Rev. 1
DoD Assessment Results Format
“Annex A” is the final version of the April 24, 2018 “DoD Guidance for Reviewing System
Security Plans and the NIST SP 800-171, Rev. 1 Security Requirements Not Yet
Implemented (Draft)”
© January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author.
12
2020 – Fed Gov Con Webinar Series - Washington DC
JSchaus & Associates
July 2019: DoD’s CMMC Initiative: Cybersecurity Model Maturity Certification
► https://www.acq.osd.mil/cmmc/
August – December 2019:CMMC Draft v.0.4 (58 pages), 0.6 and 0.7 (190 pages) seeking
a “unified cybersecurity standard” for DoD by mapping cybersecurity standards from
NARA, NIST, ISO 27001:2013, CERT and “best practices” from the Defense Industrial
Base community (e.g., Center for Internet Security (cisecurity.org), NDIA, AIA National
Aerospace Standards)
© January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author.
13
2020 – Fed Gov Con Webinar Series - Washington DC
JSchaus & Associates
CMMC:
♦ measures maturity of a company’s cybersecurity practices/processes
♦ uses “CUI” and “CDI” as in DFARS 252.204-7012 (safeguard and
reporting clause)
♦ CO identifies the CMMC Level for each contract in §§ L and M
♦ all businesses dealing with DoD (including subcontractors) must be certified by
an accredited third-party auditor regardless …
♦ role of DCMA and DCSA (formerly DSS) uncertain for audits
♦ CMMC v.1 to facilitate training and by June 2020, CMMI requirements
may appear in RFIs and in RFP §§L and M by September 2020
© January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author.
14
2020 – Fed Gov Con Webinar Series - Washington DC
JSchaus & Associates
CMMC objective: cost effective cybersecurity for large and small companies per:
17 “domains” comprised of capabilities (e.g., processes and controls regarding
such “domains” as access control, training, ID/authentication, media protection,
asset inventory, risk assessment, security assessment) (NIST has 14 domains)
Resulting in 5 Maturity Levels:
Basic Cyber Hygiene (FAR 52.204-21) Level 1
Intermediate Cyber Hygiene Level 2
Good Cyber Hygiene (DFARS 252.204-7012) Level 3
Proactive Level 4
Advanced Level 5
© January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author.
15
2020 – Fed Gov Con Webinar Series - Washington DC
JSchaus & Associates
►CMMC Level 1, Basic Cyber Hygiene (17 technical controls): FAR 52.204-21, “Basic
Safeguarding of Covered Contractor Information Systems” (June 2016) identifies specific
responsibilities for those receiving or possessing “Federal Contract Information” or “FCI”
► Per 52.204-21(b)(1) The Contractor shall apply the following basic safeguarding
requirements and procedures:
♦ Limit information system access to authorized users; (NIST 3.1.1, 3.1.2)
♦ Verify and control/limit connections to and use of information systems; (NIST 3.1.20)
♦ Control information posted or processed on publicly accessible information systems;
(NIST 3.1.22)
♦ Identify information system users, processes acting on behalf of users, or devices; (NIST
3.5.1)
♦ Verify the identities of those users as a prerequisite to allowing access; (NIST 3.5.2)
© January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author.
16
2020 – Fed Gov Con Webinar Series - Washington DC
JSchaus & Associates
♦ Sanitize or destroy information system media containing Federal Contract Information
before disposal or reuse; (NIST 3.8.3)
♦ Escort visitors and monitor visitor activity; maintain audit logs of physical access; and
control and manage physical access devices; (NIST 3.10.1, 3.10.3, 3.10.4, 3.10.5)
♦ Monitor, control, and protect organizational communications at the external boundaries
and key internal boundaries of the information systems; (NIST 3.13.1)
♦ Implement subnetworks for publicly accessible system components that are physically or
logically separated from internal networks; (NIST 3.13.1)
♦ Timely identify, report, and correct system flaws; (NIST 3.14.1)
♦ Provide protection from malicious code; (NIST 3.14.21)
♦ Update malicious code protection mechanisms; (NIST 3.14.4)
♦ Perform periodic scans of the information system (NIST 3.14.5)
Source: OUSD Memorandum on “Assessing Contractor Implementation of Cybersecurity
Requirements,” Annex A (assessment template for NIST SP 800-171, Rev. 1)
© January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author.
17
2020 – Fed Gov Con Webinar Series - Washington DC
JSchaus & Associates
CMMC Level 2 Intermediate Cyber Hygiene (72 technical controls) Demonstrate
documented processes for each control IAW contractor’s cybersecurity program
For example:
♦ least privilege (NIST 3.1.5; UK NCSC Cyber Essentials)
♦ audit logging (NIST 3.3.7)
♦ awareness and training (NIST 3.2.1, 3.2.2; CERT RMM* v1.2)
♦ password (NIST 3.5.7, 3.5.8; 3.5.9, 3.5.10; UK NCSC Cyber Essentials)
♦ vulnerability scanning / remediate (NIST 3.11.2, 3.113)
♦ control user-installed software (NIST 3.4.9)
♦ monitor and control remote access (NIST 3.1.12)
* CERT Resilience Management Model, v. 1.2
© January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author.
18
2020 – Fed Gov Con Webinar Series - Washington DC
JSchaus & Associates
CMMC Level 3 Good Cyber Hygiene (DFARS 252.204-7012)
131 technical controls to safeguard CUI and Covered Defense Information (CDI)
Demonstrate managed processes for each control with adequate resources and review
adherence to policies and procedures
For example:
♦ control connection and encrypt CUI on mobile devices (NIST 3.1.18, 3.1.19; UK NCSC
Cyber Essentials)
♦ multi-factor authentication (NIST 3.5.3; Australian ACSC Essential Eight)
♦ encryption (FIPS)(NIST 3.1.11, 3.1.13, 3.1.17, 3.1.19, 3.13.8, 3.13.10, 3.8.6)
♦ off-site, off-line backup (CIS* v.7.1 10.1, 10.2 and 10.5
♦ email protection (CIS v.7.1 17.10; CMMC)
*Center for Internet Security, Critical Security Controls, v. 7.1 (July 2019)
© January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author.
19
2020 – Fed Gov Con Webinar Series - Washington DC
JSchaus & Associates
In addition to CMMC Level 1, 2 or 3 requirements contractors are subject to:
DFARS 252.204-7008, COMPLIANCE WITH SAFEGUARDING COVERED DEFENSE
INFORMATION CONTROLS (OCT 2016)(by submission of this offer certifies it will implement
NIST SP 800-171, Rev.1 …)
DFARS 252.204-12: (a) have a SSP (NIST 3.12.4) and a POA&M (NIST 3.12.2); (b)applies to
CDI which is marked by CO; (c) report cyber incidents within 72 hours with medium
assurance certificate; (d) flow down clause throughout supply chain (no exceptions)
DFARS 252.239-7018, SUPPLY CHAIN RISK (FEB 2019)(the contractor shall mitigate supply
chain risk and government can exclude a source perceived to be a supply chain risk)
© January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author.
20
2020 – Fed Gov Con Webinar Series - Washington DC
JSchaus & Associates
Prepare for CMMC third party audit to obtain certification:
In the context of the NIST SP 800-171, Rev.1:
♦ review current cybersecurity status (i.e., VPN, password, anti-malware software, access,
etc.) in your operating environment / network (describe and illustrate) conduct an IT
inventory (workstations, laptops, handhelds, iPads, smart phones, printers, etc.)
♦ Conduct a network vulnerability assessment on your network
♦ Establish a System Security Plan and a Plan of Action & Milestones based on:
https://csrc.nist.gov/publications/sp and us-cert.gov/resources and OUSD’s “Assessing
Contractor Implementation of Cybersecurity Requirements”
♦ Implement the controls for Level 3 because contracting officers by late 2020 are likely to
require this level because DFARS 252.204-7012 has been in effect since October 2016
© January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author.
21
2020 – Fed Gov Con Webinar Series - Washington DC
JSchaus & Associates
THANK YOU!
JSchaus & Associates
Washington DC
hello@JenniferSchaus.com
www.JenniferSchaus.com
+ 1 – 2 0 2 – 3 6 5 – 0 5 9 8
David B. Dempsey
ddempsey@deftlaw.com
(703) 880-9171
© January 2020 All Rights Reserved. No part of this
information may be reproduced without the prior written
approval of the author.
22

More Related Content

Similar to Government Contracting- The Dawn of the CMMC - Win Federal Contracts

Application security and pa dss certification
Application security and pa dss certificationApplication security and pa dss certification
Application security and pa dss certification
Alexander Polyakov
 
Trackment
TrackmentTrackment
Trackment
meaannn
 
ControlCase CMMC Basics Deck Final.pdf
ControlCase CMMC Basics Deck Final.pdfControlCase CMMC Basics Deck Final.pdf
ControlCase CMMC Basics Deck Final.pdf
AmyPoblete3
 
CMMC 2.0 vs. ISO/IEC 27001 vs. NIST 800-171: What You Need to Know
CMMC 2.0 vs. ISO/IEC 27001 vs. NIST 800-171: What You Need to KnowCMMC 2.0 vs. ISO/IEC 27001 vs. NIST 800-171: What You Need to Know
CMMC 2.0 vs. ISO/IEC 27001 vs. NIST 800-171: What You Need to Know
PECB
 
Ncma saguaro cyber security 2016 law & regulations asis phoenix dely fina...
Ncma saguaro cyber security 2016 law & regulations asis phoenix dely fina...Ncma saguaro cyber security 2016 law & regulations asis phoenix dely fina...
Ncma saguaro cyber security 2016 law & regulations asis phoenix dely fina...
John Hamilton, DAHC,EHC,CFDAI, CPP, PSPO
 
FED GOV CON - Cybersecurity Compliance Under The FAR
FED GOV CON - Cybersecurity Compliance Under The FARFED GOV CON - Cybersecurity Compliance Under The FAR
FED GOV CON - Cybersecurity Compliance Under The FAR
JSchaus & Associates
 
Cybersecurity Maturity Model Certification
Cybersecurity Maturity Model CertificationCybersecurity Maturity Model Certification
Cybersecurity Maturity Model Certification
Murray Security Services
 
A Clear Path to NIST & CMMC Compliance - 2022 Summit.pptx
A Clear Path to NIST & CMMC Compliance - 2022 Summit.pptxA Clear Path to NIST & CMMC Compliance - 2022 Summit.pptx
A Clear Path to NIST & CMMC Compliance - 2022 Summit.pptx
Jack Nichelson
 
Smart Cards In The USA
Smart Cards In The USASmart Cards In The USA
Smart Cards In The USA
Agile Set, LLC
 
Isf 2015 continuous diagnostics monitoring may 2015
Isf 2015 continuous diagnostics monitoring  may 2015Isf 2015 continuous diagnostics monitoring  may 2015
Isf 2015 continuous diagnostics monitoring may 2015
abhi75
 
CMMC for Contractors and Manufacturers – What to Know for 2023
CMMC for Contractors and Manufacturers – What to Know for 2023CMMC for Contractors and Manufacturers – What to Know for 2023
CMMC for Contractors and Manufacturers – What to Know for 2023
Withum
 
1105 Media - 2014 Core Market Capabilities Presentation
1105 Media - 2014 Core Market Capabilities Presentation1105 Media - 2014 Core Market Capabilities Presentation
1105 Media - 2014 Core Market Capabilities Presentation
Christina Langer
 
Government Webinar: Preparing for CMMC Compliance Roundtable
Government Webinar: Preparing for CMMC Compliance Roundtable Government Webinar: Preparing for CMMC Compliance Roundtable
Government Webinar: Preparing for CMMC Compliance Roundtable
SolarWinds
 
PCI DSS Success: Achieve Compliance and Increase Web Application Security
PCI DSS Success: Achieve Compliance and Increase Web Application SecurityPCI DSS Success: Achieve Compliance and Increase Web Application Security
PCI DSS Success: Achieve Compliance and Increase Web Application Security
Citrix
 
Webinar - CMMC Certification.pptx
Webinar - CMMC Certification.pptxWebinar - CMMC Certification.pptx
Webinar - CMMC Certification.pptx
ControlCase
 
Government Contracting - OTA Consortia Overview - And How To Get Involved
Government Contracting - OTA Consortia Overview - And How To Get InvolvedGovernment Contracting - OTA Consortia Overview - And How To Get Involved
Government Contracting - OTA Consortia Overview - And How To Get Involved
JSchaus & Associates
 
Government Contracting - Teaming Agreements & The L Word (Leverage) - Win Fed...
Government Contracting - Teaming Agreements & The L Word (Leverage) - Win Fed...Government Contracting - Teaming Agreements & The L Word (Leverage) - Win Fed...
Government Contracting - Teaming Agreements & The L Word (Leverage) - Win Fed...
JSchaus & Associates
 
Cost effective cyber security
Cost effective cyber securityCost effective cyber security
Cost effective cyber security
임채호 박사님
 
2016 01-05 csr css non-confidential slide deck
2016 01-05 csr  css non-confidential slide deck2016 01-05 csr  css non-confidential slide deck
2016 01-05 csr css non-confidential slide deck
Richard (Dick) Kaufman
 
Meeting DFARS Requirements in AWS GovCloud (US) | AWS Public Sector Summit 2017
Meeting DFARS Requirements in AWS GovCloud (US) | AWS Public Sector Summit 2017Meeting DFARS Requirements in AWS GovCloud (US) | AWS Public Sector Summit 2017
Meeting DFARS Requirements in AWS GovCloud (US) | AWS Public Sector Summit 2017
Amazon Web Services
 

Similar to Government Contracting- The Dawn of the CMMC - Win Federal Contracts (20)

Application security and pa dss certification
Application security and pa dss certificationApplication security and pa dss certification
Application security and pa dss certification
 
Trackment
TrackmentTrackment
Trackment
 
ControlCase CMMC Basics Deck Final.pdf
ControlCase CMMC Basics Deck Final.pdfControlCase CMMC Basics Deck Final.pdf
ControlCase CMMC Basics Deck Final.pdf
 
CMMC 2.0 vs. ISO/IEC 27001 vs. NIST 800-171: What You Need to Know
CMMC 2.0 vs. ISO/IEC 27001 vs. NIST 800-171: What You Need to KnowCMMC 2.0 vs. ISO/IEC 27001 vs. NIST 800-171: What You Need to Know
CMMC 2.0 vs. ISO/IEC 27001 vs. NIST 800-171: What You Need to Know
 
Ncma saguaro cyber security 2016 law & regulations asis phoenix dely fina...
Ncma saguaro cyber security 2016 law & regulations asis phoenix dely fina...Ncma saguaro cyber security 2016 law & regulations asis phoenix dely fina...
Ncma saguaro cyber security 2016 law & regulations asis phoenix dely fina...
 
FED GOV CON - Cybersecurity Compliance Under The FAR
FED GOV CON - Cybersecurity Compliance Under The FARFED GOV CON - Cybersecurity Compliance Under The FAR
FED GOV CON - Cybersecurity Compliance Under The FAR
 
Cybersecurity Maturity Model Certification
Cybersecurity Maturity Model CertificationCybersecurity Maturity Model Certification
Cybersecurity Maturity Model Certification
 
A Clear Path to NIST & CMMC Compliance - 2022 Summit.pptx
A Clear Path to NIST & CMMC Compliance - 2022 Summit.pptxA Clear Path to NIST & CMMC Compliance - 2022 Summit.pptx
A Clear Path to NIST & CMMC Compliance - 2022 Summit.pptx
 
Smart Cards In The USA
Smart Cards In The USASmart Cards In The USA
Smart Cards In The USA
 
Isf 2015 continuous diagnostics monitoring may 2015
Isf 2015 continuous diagnostics monitoring  may 2015Isf 2015 continuous diagnostics monitoring  may 2015
Isf 2015 continuous diagnostics monitoring may 2015
 
CMMC for Contractors and Manufacturers – What to Know for 2023
CMMC for Contractors and Manufacturers – What to Know for 2023CMMC for Contractors and Manufacturers – What to Know for 2023
CMMC for Contractors and Manufacturers – What to Know for 2023
 
1105 Media - 2014 Core Market Capabilities Presentation
1105 Media - 2014 Core Market Capabilities Presentation1105 Media - 2014 Core Market Capabilities Presentation
1105 Media - 2014 Core Market Capabilities Presentation
 
Government Webinar: Preparing for CMMC Compliance Roundtable
Government Webinar: Preparing for CMMC Compliance Roundtable Government Webinar: Preparing for CMMC Compliance Roundtable
Government Webinar: Preparing for CMMC Compliance Roundtable
 
PCI DSS Success: Achieve Compliance and Increase Web Application Security
PCI DSS Success: Achieve Compliance and Increase Web Application SecurityPCI DSS Success: Achieve Compliance and Increase Web Application Security
PCI DSS Success: Achieve Compliance and Increase Web Application Security
 
Webinar - CMMC Certification.pptx
Webinar - CMMC Certification.pptxWebinar - CMMC Certification.pptx
Webinar - CMMC Certification.pptx
 
Government Contracting - OTA Consortia Overview - And How To Get Involved
Government Contracting - OTA Consortia Overview - And How To Get InvolvedGovernment Contracting - OTA Consortia Overview - And How To Get Involved
Government Contracting - OTA Consortia Overview - And How To Get Involved
 
Government Contracting - Teaming Agreements & The L Word (Leverage) - Win Fed...
Government Contracting - Teaming Agreements & The L Word (Leverage) - Win Fed...Government Contracting - Teaming Agreements & The L Word (Leverage) - Win Fed...
Government Contracting - Teaming Agreements & The L Word (Leverage) - Win Fed...
 
Cost effective cyber security
Cost effective cyber securityCost effective cyber security
Cost effective cyber security
 
2016 01-05 csr css non-confidential slide deck
2016 01-05 csr  css non-confidential slide deck2016 01-05 csr  css non-confidential slide deck
2016 01-05 csr css non-confidential slide deck
 
Meeting DFARS Requirements in AWS GovCloud (US) | AWS Public Sector Summit 2017
Meeting DFARS Requirements in AWS GovCloud (US) | AWS Public Sector Summit 2017Meeting DFARS Requirements in AWS GovCloud (US) | AWS Public Sector Summit 2017
Meeting DFARS Requirements in AWS GovCloud (US) | AWS Public Sector Summit 2017
 

More from JSchaus & Associates

2024: The FAR - Federal Acquisition Regulations, Part 42
2024: The FAR - Federal Acquisition Regulations, Part 422024: The FAR - Federal Acquisition Regulations, Part 42
2024: The FAR - Federal Acquisition Regulations, Part 42
JSchaus & Associates
 
2024: The FAR - Federal Acquisition Regulations, Part 41
2024: The FAR - Federal Acquisition Regulations, Part 412024: The FAR - Federal Acquisition Regulations, Part 41
2024: The FAR - Federal Acquisition Regulations, Part 41
JSchaus & Associates
 
2024: The FAR - Federal Acquisition Regulations, Part 40
2024: The FAR - Federal Acquisition Regulations, Part 402024: The FAR - Federal Acquisition Regulations, Part 40
2024: The FAR - Federal Acquisition Regulations, Part 40
JSchaus & Associates
 
2024: The FAR - Federal Acquisition Regulations, Part 39
2024: The FAR - Federal Acquisition Regulations, Part 392024: The FAR - Federal Acquisition Regulations, Part 39
2024: The FAR - Federal Acquisition Regulations, Part 39
JSchaus & Associates
 
2024: The FAR - Federal Acquisition Regulations, Part 38
2024: The FAR - Federal Acquisition Regulations, Part 382024: The FAR - Federal Acquisition Regulations, Part 38
2024: The FAR - Federal Acquisition Regulations, Part 38
JSchaus & Associates
 
Federal Contractors Basic Marketing Guide
Federal Contractors Basic Marketing GuideFederal Contractors Basic Marketing Guide
Federal Contractors Basic Marketing Guide
JSchaus & Associates
 
2024: The FAR - Federal Acquisition Regulations, Part 37
2024: The FAR - Federal Acquisition Regulations, Part 372024: The FAR - Federal Acquisition Regulations, Part 37
2024: The FAR - Federal Acquisition Regulations, Part 37
JSchaus & Associates
 
2024: The FAR - Federal Acquisition Regulations, Part 36
2024: The FAR - Federal Acquisition Regulations, Part 362024: The FAR - Federal Acquisition Regulations, Part 36
2024: The FAR - Federal Acquisition Regulations, Part 36
JSchaus & Associates
 
2024: The FAR - Federal Acquisition Regulations, Part 35
2024: The FAR - Federal Acquisition Regulations, Part 352024: The FAR - Federal Acquisition Regulations, Part 35
2024: The FAR - Federal Acquisition Regulations, Part 35
JSchaus & Associates
 
2024: The FAR - Federal Acquisition Regulations, Part 34
2024: The FAR - Federal Acquisition Regulations, Part 342024: The FAR - Federal Acquisition Regulations, Part 34
2024: The FAR - Federal Acquisition Regulations, Part 34
JSchaus & Associates
 
2024: The FAR - Federal Acquisition Regulations, Part 33
2024: The FAR - Federal Acquisition Regulations, Part 332024: The FAR - Federal Acquisition Regulations, Part 33
2024: The FAR - Federal Acquisition Regulations, Part 33
JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations, Part 32
2024: The FAR, Federal Acquisition Regulations, Part 322024: The FAR, Federal Acquisition Regulations, Part 32
2024: The FAR, Federal Acquisition Regulations, Part 32
JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations, Part 31
2024: The FAR, Federal Acquisition Regulations, Part 312024: The FAR, Federal Acquisition Regulations, Part 31
2024: The FAR, Federal Acquisition Regulations, Part 31
JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations, Part 30
2024: The FAR, Federal Acquisition Regulations, Part 302024: The FAR, Federal Acquisition Regulations, Part 30
2024: The FAR, Federal Acquisition Regulations, Part 30
JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 29
2024: The FAR, Federal Acquisition Regulations - Part 292024: The FAR, Federal Acquisition Regulations - Part 29
2024: The FAR, Federal Acquisition Regulations - Part 29
JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 28
2024: The FAR, Federal Acquisition Regulations - Part 282024: The FAR, Federal Acquisition Regulations - Part 28
2024: The FAR, Federal Acquisition Regulations - Part 28
JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 27
2024: The FAR, Federal Acquisition Regulations - Part 272024: The FAR, Federal Acquisition Regulations - Part 27
2024: The FAR, Federal Acquisition Regulations - Part 27
JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 26
2024: The FAR, Federal Acquisition Regulations - Part 262024: The FAR, Federal Acquisition Regulations - Part 26
2024: The FAR, Federal Acquisition Regulations - Part 26
JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 25
2024: The FAR, Federal Acquisition Regulations - Part 252024: The FAR, Federal Acquisition Regulations - Part 25
2024: The FAR, Federal Acquisition Regulations - Part 25
JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 24
2024: The FAR, Federal Acquisition Regulations - Part 242024: The FAR, Federal Acquisition Regulations - Part 24
2024: The FAR, Federal Acquisition Regulations - Part 24
JSchaus & Associates
 

More from JSchaus & Associates (20)

2024: The FAR - Federal Acquisition Regulations, Part 42
2024: The FAR - Federal Acquisition Regulations, Part 422024: The FAR - Federal Acquisition Regulations, Part 42
2024: The FAR - Federal Acquisition Regulations, Part 42
 
2024: The FAR - Federal Acquisition Regulations, Part 41
2024: The FAR - Federal Acquisition Regulations, Part 412024: The FAR - Federal Acquisition Regulations, Part 41
2024: The FAR - Federal Acquisition Regulations, Part 41
 
2024: The FAR - Federal Acquisition Regulations, Part 40
2024: The FAR - Federal Acquisition Regulations, Part 402024: The FAR - Federal Acquisition Regulations, Part 40
2024: The FAR - Federal Acquisition Regulations, Part 40
 
2024: The FAR - Federal Acquisition Regulations, Part 39
2024: The FAR - Federal Acquisition Regulations, Part 392024: The FAR - Federal Acquisition Regulations, Part 39
2024: The FAR - Federal Acquisition Regulations, Part 39
 
2024: The FAR - Federal Acquisition Regulations, Part 38
2024: The FAR - Federal Acquisition Regulations, Part 382024: The FAR - Federal Acquisition Regulations, Part 38
2024: The FAR - Federal Acquisition Regulations, Part 38
 
Federal Contractors Basic Marketing Guide
Federal Contractors Basic Marketing GuideFederal Contractors Basic Marketing Guide
Federal Contractors Basic Marketing Guide
 
2024: The FAR - Federal Acquisition Regulations, Part 37
2024: The FAR - Federal Acquisition Regulations, Part 372024: The FAR - Federal Acquisition Regulations, Part 37
2024: The FAR - Federal Acquisition Regulations, Part 37
 
2024: The FAR - Federal Acquisition Regulations, Part 36
2024: The FAR - Federal Acquisition Regulations, Part 362024: The FAR - Federal Acquisition Regulations, Part 36
2024: The FAR - Federal Acquisition Regulations, Part 36
 
2024: The FAR - Federal Acquisition Regulations, Part 35
2024: The FAR - Federal Acquisition Regulations, Part 352024: The FAR - Federal Acquisition Regulations, Part 35
2024: The FAR - Federal Acquisition Regulations, Part 35
 
2024: The FAR - Federal Acquisition Regulations, Part 34
2024: The FAR - Federal Acquisition Regulations, Part 342024: The FAR - Federal Acquisition Regulations, Part 34
2024: The FAR - Federal Acquisition Regulations, Part 34
 
2024: The FAR - Federal Acquisition Regulations, Part 33
2024: The FAR - Federal Acquisition Regulations, Part 332024: The FAR - Federal Acquisition Regulations, Part 33
2024: The FAR - Federal Acquisition Regulations, Part 33
 
2024: The FAR, Federal Acquisition Regulations, Part 32
2024: The FAR, Federal Acquisition Regulations, Part 322024: The FAR, Federal Acquisition Regulations, Part 32
2024: The FAR, Federal Acquisition Regulations, Part 32
 
2024: The FAR, Federal Acquisition Regulations, Part 31
2024: The FAR, Federal Acquisition Regulations, Part 312024: The FAR, Federal Acquisition Regulations, Part 31
2024: The FAR, Federal Acquisition Regulations, Part 31
 
2024: The FAR, Federal Acquisition Regulations, Part 30
2024: The FAR, Federal Acquisition Regulations, Part 302024: The FAR, Federal Acquisition Regulations, Part 30
2024: The FAR, Federal Acquisition Regulations, Part 30
 
2024: The FAR, Federal Acquisition Regulations - Part 29
2024: The FAR, Federal Acquisition Regulations - Part 292024: The FAR, Federal Acquisition Regulations - Part 29
2024: The FAR, Federal Acquisition Regulations - Part 29
 
2024: The FAR, Federal Acquisition Regulations - Part 28
2024: The FAR, Federal Acquisition Regulations - Part 282024: The FAR, Federal Acquisition Regulations - Part 28
2024: The FAR, Federal Acquisition Regulations - Part 28
 
2024: The FAR, Federal Acquisition Regulations - Part 27
2024: The FAR, Federal Acquisition Regulations - Part 272024: The FAR, Federal Acquisition Regulations - Part 27
2024: The FAR, Federal Acquisition Regulations - Part 27
 
2024: The FAR, Federal Acquisition Regulations - Part 26
2024: The FAR, Federal Acquisition Regulations - Part 262024: The FAR, Federal Acquisition Regulations - Part 26
2024: The FAR, Federal Acquisition Regulations - Part 26
 
2024: The FAR, Federal Acquisition Regulations - Part 25
2024: The FAR, Federal Acquisition Regulations - Part 252024: The FAR, Federal Acquisition Regulations - Part 25
2024: The FAR, Federal Acquisition Regulations - Part 25
 
2024: The FAR, Federal Acquisition Regulations - Part 24
2024: The FAR, Federal Acquisition Regulations - Part 242024: The FAR, Federal Acquisition Regulations - Part 24
2024: The FAR, Federal Acquisition Regulations - Part 24
 

Recently uploaded

PAS PSDF Mop Up Workshop Presentation 2024 .pptx
PAS PSDF Mop Up Workshop Presentation 2024 .pptxPAS PSDF Mop Up Workshop Presentation 2024 .pptx
PAS PSDF Mop Up Workshop Presentation 2024 .pptx
PAS_Team
 
快速办理(UVM毕业证书)佛蒙特大学毕业证学位证一模一样
快速办理(UVM毕业证书)佛蒙特大学毕业证学位证一模一样快速办理(UVM毕业证书)佛蒙特大学毕业证学位证一模一样
快速办理(UVM毕业证书)佛蒙特大学毕业证学位证一模一样
yemqpj
 
CBO’s Outlook for U.S. Fertility Rates: 2024 to 2054
CBO’s Outlook for U.S. Fertility Rates: 2024 to 2054CBO’s Outlook for U.S. Fertility Rates: 2024 to 2054
CBO’s Outlook for U.S. Fertility Rates: 2024 to 2054
Congressional Budget Office
 
Contributi dei parlamentari del PD - Contributi L. 3/2019
Contributi dei parlamentari del PD - Contributi L. 3/2019Contributi dei parlamentari del PD - Contributi L. 3/2019
Contributi dei parlamentari del PD - Contributi L. 3/2019
Partito democratico
 
原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样
原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样
原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样
ii2sh2v
 
Practical guide for the celebration of World Environment Day on june 5th.
Practical guide for the  celebration of World Environment Day on  june 5th.Practical guide for the  celebration of World Environment Day on  june 5th.
Practical guide for the celebration of World Environment Day on june 5th.
Christina Parmionova
 
Abiy Berehe - Texas Commission on Environmental Quality Updates
Abiy Berehe - Texas Commission on Environmental Quality UpdatesAbiy Berehe - Texas Commission on Environmental Quality Updates
Abiy Berehe - Texas Commission on Environmental Quality Updates
Texas Alliance of Groundwater Districts
 
United Nations World Oceans Day 2024; June 8th " Awaken new dephts".
United Nations World Oceans Day 2024; June 8th " Awaken new dephts".United Nations World Oceans Day 2024; June 8th " Awaken new dephts".
United Nations World Oceans Day 2024; June 8th " Awaken new dephts".
Christina Parmionova
 
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
OECDregions
 
A guide to the International day of Potatoes 2024 - May 30th
A guide to the International day of Potatoes 2024 - May 30thA guide to the International day of Potatoes 2024 - May 30th
A guide to the International day of Potatoes 2024 - May 30th
Christina Parmionova
 
Antyodaya saral portal haryana govt schemes
Antyodaya saral portal haryana govt schemesAntyodaya saral portal haryana govt schemes
Antyodaya saral portal haryana govt schemes
narinav14
 
Milton Keynes Hospital Charity - A guide to leaving a gift in your Will
Milton Keynes Hospital Charity - A guide to leaving a gift in your WillMilton Keynes Hospital Charity - A guide to leaving a gift in your Will
Milton Keynes Hospital Charity - A guide to leaving a gift in your Will
fundraising4
 
Transit-Oriented Development Study Working Group Meeting
Transit-Oriented Development Study Working Group MeetingTransit-Oriented Development Study Working Group Meeting
Transit-Oriented Development Study Working Group Meeting
Cuyahoga County Planning Commission
 
IEA World Energy Investment June 2024- Statistics
IEA World Energy Investment June 2024- StatisticsIEA World Energy Investment June 2024- Statistics
IEA World Energy Investment June 2024- Statistics
Energy for One World
 
Item #s 8&9 -- Demolition Code Amendment
Item #s 8&9 -- Demolition Code AmendmentItem #s 8&9 -- Demolition Code Amendment
Item #s 8&9 -- Demolition Code Amendment
ahcitycouncil
 
Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...
Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...
Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...
ssuser05e8f3
 
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHOMonitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Christina Parmionova
 
CFYT Rolling Ads Dawson City Yukon Canada
CFYT Rolling Ads Dawson City Yukon CanadaCFYT Rolling Ads Dawson City Yukon Canada
CFYT Rolling Ads Dawson City Yukon Canada
pmenzies
 
A Guide to AI for Smarter Nonprofits - Dr. Cori Faklaris, UNC Charlotte
A Guide to AI for Smarter Nonprofits - Dr. Cori Faklaris, UNC CharlotteA Guide to AI for Smarter Nonprofits - Dr. Cori Faklaris, UNC Charlotte
A Guide to AI for Smarter Nonprofits - Dr. Cori Faklaris, UNC Charlotte
Cori Faklaris
 
在线办理美国乔治华盛顿大学毕业证(gwu毕业证书)学历学位证书原版一模一样
在线办理美国乔治华盛顿大学毕业证(gwu毕业证书)学历学位证书原版一模一样在线办理美国乔治华盛顿大学毕业证(gwu毕业证书)学历学位证书原版一模一样
在线办理美国乔治华盛顿大学毕业证(gwu毕业证书)学历学位证书原版一模一样
9d5c8i83
 

Recently uploaded (20)

PAS PSDF Mop Up Workshop Presentation 2024 .pptx
PAS PSDF Mop Up Workshop Presentation 2024 .pptxPAS PSDF Mop Up Workshop Presentation 2024 .pptx
PAS PSDF Mop Up Workshop Presentation 2024 .pptx
 
快速办理(UVM毕业证书)佛蒙特大学毕业证学位证一模一样
快速办理(UVM毕业证书)佛蒙特大学毕业证学位证一模一样快速办理(UVM毕业证书)佛蒙特大学毕业证学位证一模一样
快速办理(UVM毕业证书)佛蒙特大学毕业证学位证一模一样
 
CBO’s Outlook for U.S. Fertility Rates: 2024 to 2054
CBO’s Outlook for U.S. Fertility Rates: 2024 to 2054CBO’s Outlook for U.S. Fertility Rates: 2024 to 2054
CBO’s Outlook for U.S. Fertility Rates: 2024 to 2054
 
Contributi dei parlamentari del PD - Contributi L. 3/2019
Contributi dei parlamentari del PD - Contributi L. 3/2019Contributi dei parlamentari del PD - Contributi L. 3/2019
Contributi dei parlamentari del PD - Contributi L. 3/2019
 
原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样
原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样
原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样
 
Practical guide for the celebration of World Environment Day on june 5th.
Practical guide for the  celebration of World Environment Day on  june 5th.Practical guide for the  celebration of World Environment Day on  june 5th.
Practical guide for the celebration of World Environment Day on june 5th.
 
Abiy Berehe - Texas Commission on Environmental Quality Updates
Abiy Berehe - Texas Commission on Environmental Quality UpdatesAbiy Berehe - Texas Commission on Environmental Quality Updates
Abiy Berehe - Texas Commission on Environmental Quality Updates
 
United Nations World Oceans Day 2024; June 8th " Awaken new dephts".
United Nations World Oceans Day 2024; June 8th " Awaken new dephts".United Nations World Oceans Day 2024; June 8th " Awaken new dephts".
United Nations World Oceans Day 2024; June 8th " Awaken new dephts".
 
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
 
A guide to the International day of Potatoes 2024 - May 30th
A guide to the International day of Potatoes 2024 - May 30thA guide to the International day of Potatoes 2024 - May 30th
A guide to the International day of Potatoes 2024 - May 30th
 
Antyodaya saral portal haryana govt schemes
Antyodaya saral portal haryana govt schemesAntyodaya saral portal haryana govt schemes
Antyodaya saral portal haryana govt schemes
 
Milton Keynes Hospital Charity - A guide to leaving a gift in your Will
Milton Keynes Hospital Charity - A guide to leaving a gift in your WillMilton Keynes Hospital Charity - A guide to leaving a gift in your Will
Milton Keynes Hospital Charity - A guide to leaving a gift in your Will
 
Transit-Oriented Development Study Working Group Meeting
Transit-Oriented Development Study Working Group MeetingTransit-Oriented Development Study Working Group Meeting
Transit-Oriented Development Study Working Group Meeting
 
IEA World Energy Investment June 2024- Statistics
IEA World Energy Investment June 2024- StatisticsIEA World Energy Investment June 2024- Statistics
IEA World Energy Investment June 2024- Statistics
 
Item #s 8&9 -- Demolition Code Amendment
Item #s 8&9 -- Demolition Code AmendmentItem #s 8&9 -- Demolition Code Amendment
Item #s 8&9 -- Demolition Code Amendment
 
Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...
Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...
Bangladesh studies presentation on Liberation War 1971 Indepence-of-Banglades...
 
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHOMonitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHO
 
CFYT Rolling Ads Dawson City Yukon Canada
CFYT Rolling Ads Dawson City Yukon CanadaCFYT Rolling Ads Dawson City Yukon Canada
CFYT Rolling Ads Dawson City Yukon Canada
 
A Guide to AI for Smarter Nonprofits - Dr. Cori Faklaris, UNC Charlotte
A Guide to AI for Smarter Nonprofits - Dr. Cori Faklaris, UNC CharlotteA Guide to AI for Smarter Nonprofits - Dr. Cori Faklaris, UNC Charlotte
A Guide to AI for Smarter Nonprofits - Dr. Cori Faklaris, UNC Charlotte
 
在线办理美国乔治华盛顿大学毕业证(gwu毕业证书)学历学位证书原版一模一样
在线办理美国乔治华盛顿大学毕业证(gwu毕业证书)学历学位证书原版一模一样在线办理美国乔治华盛顿大学毕业证(gwu毕业证书)学历学位证书原版一模一样
在线办理美国乔治华盛顿大学毕业证(gwu毕业证书)学历学位证书原版一模一样
 

Government Contracting- The Dawn of the CMMC - Win Federal Contracts

  • 1. FED GOV CON Webinar Wednesdays 2020 Series JSchaus & Associates Washington DC + 1 – 2 0 2 – 3 6 5 – 0 5 9 8
  • 2. About Our Webinars: - Every Wednesday; - Complimentary; - Recorded; - YouTube & our Website; - No Questions
  • 3. About Us: Professional Services for Federal Contractors - GSA Sched; - SBA 8(a); - Proposal Writing; - Pricing; - Contract Administration; - Business Development
  • 4. Upcoming Events: FEB 10 5.30-7.30pm Meet With STATE DPT and 150 Federal Contractors Sponsorships Available
  • 5. Advertise In Our Newsletter: Reach 16,600+ Subscribers! Includes Government & Government Contractors Hello@JenniferSchaus.com
  • 6. About Our Speaker: David Dempsey Dempsey Fontana, PLLC www.deftlaw.com
  • 7. The Dawn Of CMMC Wednesday, January 15, 2020
  • 8. BACKGROUND TO “CYBERSECURITY” Federal Information Security Management Act(s) 2002/2014 NARA Establishes A “Uniform” Program for “CUI” (32 C.F.R.2002; 81 FED. REG. 63336; Sept 14, 2016 (“CUI BASIC,” “CUI SPECIFIC,” “CUI REGISTRY’) INFORMATION SECURITY OVERSIGHT OFFICE REVISED THE NISP ON MAY 7, 2018 (INSIDER THREAT, FOCI, ACCESS TO CLASSIFIED) FISMA to NARA to ISSO to NIST SP-171 to CMMC (v.07) © January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author. 8 2020 – Fed Gov Con Webinar Series - Washington DC JSchaus & Associates
  • 9. FEDERAL CYBERSECURITY AND SUPPLY CHAIN REQUIREMENTS ISOO’S CUI REGULATION INCORPORATES: NIST SP 800-53 r4 Security and Privacy Controls for Federal Information Systems and Organizations (updated through Jan. 2015);* NIST SP 800-171 r1, (Protecting [CUI] in Nonfederal Systems and Organizations r1 (updated through June 2016)** * Rev. 5 in final review **Rev. B in final review DAWN OF CMMC © January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author. 9 2020 – Fed Gov Con Webinar Series - Washington DC JSchaus & Associates
  • 10. BACKGROUND TO “SUPPLY CHAIN REQUIREMENTS” 2013 NDAA: § 806 2014 NDAA: §§ 325, 811, 391, 942, 3113 2015 NDAA: §§ 834, 1628, 1632 2016 NDAA: §§ 238, 346 2017 NDAA: §§ 1641, 1650, 1841-44 2018 NDAA: §§ 807 (Enhanced Supply Chain Scrutiny), 1631- 1649, 1656, 1659, 1696 2019 NDAA: §§ 880, 881, 889 (permanent authority on supply chain risk) 2020 NDAA: § 881 (technical assistance for SBIR and STTR programs) © January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author. 10 2020 – Fed Gov Con Webinar Series - Washington DC JSchaus & Associates
  • 11. Secure Technology Act – Pub. L. 115-390 § 101(a) – DHS to “report security vulnerabilities” (US-CERT weekly vulnerability summaries have been available for years (see “us-cert.gov” & “us-cert.gov/security-publications” & “uscert.gov/resources” & “us- cert.gov/resources/smb”/ etc.) ► Cyber resilience review at us-cert.gov/resources § 201 “Federal Acquisition Supply Chain Security Act of 2018” (authority to review and designate items / services that federal procurement personnel cannot purchase) 20+ DoD Memoranda (including Feb. 2019 DCMA guidance on CPSR – now at $50 million threshold) Culminating in the 2020 bridge to CMMC implementation © January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author. 11 2020 – Fed Gov Con Webinar Series - Washington DC JSchaus & Associates
  • 12. Nov. 14, 2019 OUSD Memorandum on “Assessing Contractor Implementation of Cybersecurity Requirements” – guidance for 2020 ► NIST SP 800-171, Rev. 1 DoD Assessment Methodology, Version 1.0 ♥ Levels of Assessment (Basic, Medium, High) ● Annex A - NIST SP 800-171, Rev.1 DoD Assessment Scoring Template regarding the 110 NIST SP 800-171, Rev. 1 elements ● Annex B – Basic (Contractor Self-Assessment) NIST SP 800-171, Rev. 1 DoD Assessment Results Format “Annex A” is the final version of the April 24, 2018 “DoD Guidance for Reviewing System Security Plans and the NIST SP 800-171, Rev. 1 Security Requirements Not Yet Implemented (Draft)” © January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author. 12 2020 – Fed Gov Con Webinar Series - Washington DC JSchaus & Associates
  • 13. July 2019: DoD’s CMMC Initiative: Cybersecurity Model Maturity Certification ► https://www.acq.osd.mil/cmmc/ August – December 2019:CMMC Draft v.0.4 (58 pages), 0.6 and 0.7 (190 pages) seeking a “unified cybersecurity standard” for DoD by mapping cybersecurity standards from NARA, NIST, ISO 27001:2013, CERT and “best practices” from the Defense Industrial Base community (e.g., Center for Internet Security (cisecurity.org), NDIA, AIA National Aerospace Standards) © January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author. 13 2020 – Fed Gov Con Webinar Series - Washington DC JSchaus & Associates
  • 14. CMMC: ♦ measures maturity of a company’s cybersecurity practices/processes ♦ uses “CUI” and “CDI” as in DFARS 252.204-7012 (safeguard and reporting clause) ♦ CO identifies the CMMC Level for each contract in §§ L and M ♦ all businesses dealing with DoD (including subcontractors) must be certified by an accredited third-party auditor regardless … ♦ role of DCMA and DCSA (formerly DSS) uncertain for audits ♦ CMMC v.1 to facilitate training and by June 2020, CMMI requirements may appear in RFIs and in RFP §§L and M by September 2020 © January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author. 14 2020 – Fed Gov Con Webinar Series - Washington DC JSchaus & Associates
  • 15. CMMC objective: cost effective cybersecurity for large and small companies per: 17 “domains” comprised of capabilities (e.g., processes and controls regarding such “domains” as access control, training, ID/authentication, media protection, asset inventory, risk assessment, security assessment) (NIST has 14 domains) Resulting in 5 Maturity Levels: Basic Cyber Hygiene (FAR 52.204-21) Level 1 Intermediate Cyber Hygiene Level 2 Good Cyber Hygiene (DFARS 252.204-7012) Level 3 Proactive Level 4 Advanced Level 5 © January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author. 15 2020 – Fed Gov Con Webinar Series - Washington DC JSchaus & Associates
  • 16. ►CMMC Level 1, Basic Cyber Hygiene (17 technical controls): FAR 52.204-21, “Basic Safeguarding of Covered Contractor Information Systems” (June 2016) identifies specific responsibilities for those receiving or possessing “Federal Contract Information” or “FCI” ► Per 52.204-21(b)(1) The Contractor shall apply the following basic safeguarding requirements and procedures: ♦ Limit information system access to authorized users; (NIST 3.1.1, 3.1.2) ♦ Verify and control/limit connections to and use of information systems; (NIST 3.1.20) ♦ Control information posted or processed on publicly accessible information systems; (NIST 3.1.22) ♦ Identify information system users, processes acting on behalf of users, or devices; (NIST 3.5.1) ♦ Verify the identities of those users as a prerequisite to allowing access; (NIST 3.5.2) © January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author. 16 2020 – Fed Gov Con Webinar Series - Washington DC JSchaus & Associates
  • 17. ♦ Sanitize or destroy information system media containing Federal Contract Information before disposal or reuse; (NIST 3.8.3) ♦ Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices; (NIST 3.10.1, 3.10.3, 3.10.4, 3.10.5) ♦ Monitor, control, and protect organizational communications at the external boundaries and key internal boundaries of the information systems; (NIST 3.13.1) ♦ Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks; (NIST 3.13.1) ♦ Timely identify, report, and correct system flaws; (NIST 3.14.1) ♦ Provide protection from malicious code; (NIST 3.14.21) ♦ Update malicious code protection mechanisms; (NIST 3.14.4) ♦ Perform periodic scans of the information system (NIST 3.14.5) Source: OUSD Memorandum on “Assessing Contractor Implementation of Cybersecurity Requirements,” Annex A (assessment template for NIST SP 800-171, Rev. 1) © January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author. 17 2020 – Fed Gov Con Webinar Series - Washington DC JSchaus & Associates
  • 18. CMMC Level 2 Intermediate Cyber Hygiene (72 technical controls) Demonstrate documented processes for each control IAW contractor’s cybersecurity program For example: ♦ least privilege (NIST 3.1.5; UK NCSC Cyber Essentials) ♦ audit logging (NIST 3.3.7) ♦ awareness and training (NIST 3.2.1, 3.2.2; CERT RMM* v1.2) ♦ password (NIST 3.5.7, 3.5.8; 3.5.9, 3.5.10; UK NCSC Cyber Essentials) ♦ vulnerability scanning / remediate (NIST 3.11.2, 3.113) ♦ control user-installed software (NIST 3.4.9) ♦ monitor and control remote access (NIST 3.1.12) * CERT Resilience Management Model, v. 1.2 © January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author. 18 2020 – Fed Gov Con Webinar Series - Washington DC JSchaus & Associates
  • 19. CMMC Level 3 Good Cyber Hygiene (DFARS 252.204-7012) 131 technical controls to safeguard CUI and Covered Defense Information (CDI) Demonstrate managed processes for each control with adequate resources and review adherence to policies and procedures For example: ♦ control connection and encrypt CUI on mobile devices (NIST 3.1.18, 3.1.19; UK NCSC Cyber Essentials) ♦ multi-factor authentication (NIST 3.5.3; Australian ACSC Essential Eight) ♦ encryption (FIPS)(NIST 3.1.11, 3.1.13, 3.1.17, 3.1.19, 3.13.8, 3.13.10, 3.8.6) ♦ off-site, off-line backup (CIS* v.7.1 10.1, 10.2 and 10.5 ♦ email protection (CIS v.7.1 17.10; CMMC) *Center for Internet Security, Critical Security Controls, v. 7.1 (July 2019) © January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author. 19 2020 – Fed Gov Con Webinar Series - Washington DC JSchaus & Associates
  • 20. In addition to CMMC Level 1, 2 or 3 requirements contractors are subject to: DFARS 252.204-7008, COMPLIANCE WITH SAFEGUARDING COVERED DEFENSE INFORMATION CONTROLS (OCT 2016)(by submission of this offer certifies it will implement NIST SP 800-171, Rev.1 …) DFARS 252.204-12: (a) have a SSP (NIST 3.12.4) and a POA&M (NIST 3.12.2); (b)applies to CDI which is marked by CO; (c) report cyber incidents within 72 hours with medium assurance certificate; (d) flow down clause throughout supply chain (no exceptions) DFARS 252.239-7018, SUPPLY CHAIN RISK (FEB 2019)(the contractor shall mitigate supply chain risk and government can exclude a source perceived to be a supply chain risk) © January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author. 20 2020 – Fed Gov Con Webinar Series - Washington DC JSchaus & Associates
  • 21. Prepare for CMMC third party audit to obtain certification: In the context of the NIST SP 800-171, Rev.1: ♦ review current cybersecurity status (i.e., VPN, password, anti-malware software, access, etc.) in your operating environment / network (describe and illustrate) conduct an IT inventory (workstations, laptops, handhelds, iPads, smart phones, printers, etc.) ♦ Conduct a network vulnerability assessment on your network ♦ Establish a System Security Plan and a Plan of Action & Milestones based on: https://csrc.nist.gov/publications/sp and us-cert.gov/resources and OUSD’s “Assessing Contractor Implementation of Cybersecurity Requirements” ♦ Implement the controls for Level 3 because contracting officers by late 2020 are likely to require this level because DFARS 252.204-7012 has been in effect since October 2016 © January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author. 21 2020 – Fed Gov Con Webinar Series - Washington DC JSchaus & Associates
  • 22. THANK YOU! JSchaus & Associates Washington DC hello@JenniferSchaus.com www.JenniferSchaus.com + 1 – 2 0 2 – 3 6 5 – 0 5 9 8 David B. Dempsey ddempsey@deftlaw.com (703) 880-9171 © January 2020 All Rights Reserved. No part of this information may be reproduced without the prior written approval of the author. 22