broken image
broken image

創義科技

Cyber Security Innovation Technology

 

  • 主頁
  • 業務
  • 案例
  • 教育訓練
  • 專家部落格
  • 聯繫我們
  • …  
    • 主頁
    • 業務
    • 案例
    • 教育訓練
    • 專家部落格
    • 聯繫我們
    聯繫我們
    broken image
    broken image

    創義科技

    Cyber Security Innovation Technology

     

    • 主頁
    • 業務
    • 案例
    • 教育訓練
    • 專家部落格
    • 聯繫我們
    • …  
      • 主頁
      • 業務
      • 案例
      • 教育訓練
      • 專家部落格
      • 聯繫我們
      聯繫我們
      broken image

      網路安全成熟度模型驗證計畫最終規則發布

      美國DoD 全球國防工業基地(DIB)資訊安全的守護規則

      · CMMC

       

      broken image

      Cybersecurity Maturity Model Certification Program Final Rule Published

      Oct. 11, 2024 |   

      Today, the final program rule for the Cybersecurity Maturity Model Certification (CMMC) Program was released for public inspection on federalregister.gov and is anticipated to be published in the Federal Register, Tuesday, October 15.

      The purpose of CMMC is to verify that defense contractors are compliant with existing protections for federal contract information (FCI) and controlled unclassified information (CUI) and are protecting that information at a level commensurate with the risk from cybersecurity threats, including advanced persistent threats.

      This rule streamlines and simplifies the process for small-and medium-sized businesses by reducing the number of assessment levels from the five in the original program to three under the new program.

      This final rule aligns the program with the cybersecurity requirements described in Federal Acquisition Regulation part 52.204-21 and National Institute of Standards and Technology (NIST) Special Publications (SP) 800-171 Rev 2 and -172. It also clearly identifies the 24 NIST SP 800-172 requirements mandated for CMMC Level 3 certification.

      With the publication of this updated 32 CFR rule, DoD will allow businesses to self-assess their compliance when appropriate. Basic protection of FCI will require self-assessment at CMMC Level 1.General protection of CUI will require either third-party assessment or self-assessment at CMMC Level 2.A higher level of protection against risk from advanced persistent threats will be required for some CUI. This enhanced protection will require a Defense Industrial Base Cybersecurity Assessment Center led assessment at CMMC Level 3.

      CMMC provides the tools to hold accountable entities or individuals that put U.S. information or systems at risk by knowingly misrepresenting their cybersecurity practices or protocols, or knowingly violating obligations to monitor and report cybersecurity incidents and breaches. The CMMC Program implements an annual affirmation requirement that is a key element for monitoring and enforcing accountability of a company's cybersecurity status.

      With this revised CMMC Program, the Department also introduces Plans of Action and Milestones (POA&Ms). POA&Ms will be granted for specific requirements as outlined in the rule to allow a business to obtain conditional certification for 180 days while working to meet the NIST standards.

      The benefits of CMMC include:

      • Safeguarding sensitive information to enable and protect the warfighter
      • Enforcing DIB cybersecurity standards to meet evolving threats
      • Ensuring accountability while minimizing barriers to compliance with DoD requirements
      • Perpetuating a collaborative culture of cybersecurity and cyber resilience
      • Maintaining public trust through high professional and ethical standards

      The Department understands the significant time and resources required for industry to comply with DoD's cybersecurity requirements for safeguarding CUI and is intent upon implementing CMMC requirements to assess the degree to which they have done so. The Department would like to thank all the businesses and industry associations that provided input during the public comment period. Without this collaboration, it would not have been possible to meet our goals of improving security of critical information and increasing compliance with cybersecurity requirements while simultaneously making it easier for small and medium-sized businesses to meet their contractual obligations.

      Businesses in the defense industrial base should take action to gauge their compliance with existing security requirements and preparedness to comply with CMMC assessments. Members of the defense industrial base may use cloud service offerings to meet the cybersecurity requirements that must be assessed as part of the CMMC requirement. The DoD CIO DIB Cybersecurity Program has compiled a list of current resources available at dibnet.dod.mil under DoD DIB Cybersecurity-as-a-Service (CSaaS) Services and Support.

      The DoD's follow-on Defense Federal Acquisition Regulation Supplement (DFARS) rule change to contractually implement the CMMC Program will be published in early to mid-2025. Once that rule is effective, DoD will include CMMC requirements in solicitations and contracts. Contractors who process, store, or transmit FCI or CUI must achieve the appropriate level of CMMC as a condition of contract award. More information on the timing of the proposed DFARS rule can be found at https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202404&RIN=0750-AK81.

      More information on the CMMC Program can be found at https://dodcio.defense.gov/CMMC/.

      原文鏈接

       

      上一篇
      歐洲國會通過人工智慧(AI)法案監管
      下一篇
      美國欲主導世界一個安全、保密、負責任與可信賴 AI的發展
       返回網站
      Cookie的使用
      我們使用cookie來改善瀏覽體驗、保證安全性和資料收集。一旦點擊接受,就表示你接受這些用於廣告和分析的cookie。你可以隨時更改你的cookie設定。 了解更多
      全部接受
      設定
      全部拒絕
      Cookie 設定
      必要的Cookies
      這些cookies支援安全性、網路管理和可訪問性等核心功能。這些cookies無法關閉。
      分析性Cookies
      這些cookies幫助我們更了解訪客與我們網站的互動情況,並幫助我們發現錯誤。
      偏好的Cookies
      這些cookies允許網站記住你的選擇,以提升功能性與個人化。
      儲存