<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>Cybersecurity &#8211; SolvereOne</title>
	<atom:link href="https://www.solvereone.com/tag/cybersecurity/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.solvereone.com</link>
	<description>SolvereOne Site</description>
	<lastBuildDate>Thu, 08 Sep 2022 17:33:40 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>
	<item>
		<title>What Is Cybersecurity Maturity Model Certification (CMMC) &#8211; Updated 2021</title>
		<link>https://www.solvereone.com/cybersecurity-maturity-model-certification-cmmc/</link>
		
		<dc:creator><![CDATA[solvereone]]></dc:creator>
		<pubDate>Wed, 27 Jan 2021 12:30:40 +0000</pubDate>
				<category><![CDATA[Homepage Slider]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Resources]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[cmmc]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://www.solvereone.com/pages/?p=6198</guid>

					<description><![CDATA[Cybersecurity Maturity Model Certification (CMMC) Explained Two years ago, the Department of Defense (DoD) required all their contractors to comply with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171. NIST’s 800-171 outlined 110 controls for contractors that work with controlled unclassified information (CUI) to help them attain basic cybersecurity standards. Contractors [&#8230;]]]></description>
										<content:encoded><![CDATA[<h1>Cybersecurity Maturity Model Certification (CMMC) Explained</h1>
<p><strong>Two years ago, the Department of Defense (DoD) required</strong> all their contractors to comply with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171.</p>
<p>NIST’s 800-171 outlined 110 controls for contractors that work with controlled unclassified information (CUI) to help them attain basic cybersecurity standards. Contractors were required to be in compliance or have a plan for compliance by the end of 2017.</p>
<p>Now, the DoD is in the process of releasing a new publication for cybersecurity, which will essentially replace 800-171 and require contractors to attain certification. The new standard will be called <em>the Cybersecurity Maturity Model Certification (CMMC)</em>.</p>
<p>&nbsp;</p>
<h2>The Purpose of the CMMC in 2021</h2>
<p><img fetchpriority="high" decoding="async" class="alignleft wp-image-6201" src="https://www.solvereone.com/wp-content/uploads/purpose-of-cmmc-certification.png" alt="the purpose of the cmmc certification" width="237" height="237" srcset="https://www.solvereone.com/wp-content/uploads/purpose-of-cmmc-certification.png 449w, https://www.solvereone.com/wp-content/uploads/purpose-of-cmmc-certification-300x300.png 300w, https://www.solvereone.com/wp-content/uploads/purpose-of-cmmc-certification-150x150.png 150w" sizes="(max-width: 237px) 100vw, 237px" />The certification is designed to <strong>correct issues with NIST’s 800-171</strong> and set an enforceable uniform cybersecurity standard for DoD contractors throughout <a href="https://www.solvereone.com/it-security-consultant-northern-virginia.html">Washington DC and Northern Virginia</a>.</p>
<p>Currently, contractors are allowed to confirm their own compliance with 800-171 by documenting an existing security plan that meets the controls and a subsequent plan for any unmet controls.</p>
<p>However, this system left many contractors with inadequate <em>cybersecurity practices</em> that had yet to meet the requirements and put data at risk. Compromised sensitive information led to numerous incidents for the DoD, and they’re now trying to improve their standards.</p>
<p>CMMC aims to designate universal cybersecurity practices for all DoD contractors.</p>
<p>The DoD will require third-party certification for this new model. Contractors must have met the issued requirements and attain certification to do business with the department.</p>
<p>The CMMC is expected to specify five levels of data security, ranging from basic measures to advanced practices.</p>
<p>The purpose of these varying levels is to allow contractors to implement the procedures most appropriate for their particular work.</p>
<p>&nbsp;</p>
<h2>Who Will Be Affected by the New Certification</h2>
<p><img decoding="async" class="alignright wp-image-6202" src="https://www.solvereone.com/wp-content/uploads/who-is-affected-cmmc-certification.png" alt="who is affected" width="209" height="209" srcset="https://www.solvereone.com/wp-content/uploads/who-is-affected-cmmc-certification.png 366w, https://www.solvereone.com/wp-content/uploads/who-is-affected-cmmc-certification-300x300.png 300w, https://www.solvereone.com/wp-content/uploads/who-is-affected-cmmc-certification-150x150.png 150w" sizes="(max-width: 209px) 100vw, 209px" /><strong>Any DoD contractors</strong> that work with controlled unclassified information <strong>will be expected to gain certification</strong> under a third-party auditor. The DoD is expected to utilize a nonprofit organization to manage the certification process and auditors, although it’s not yet clear which organization will be hired or who the auditors will be.</p>
<p>The certification will also apply to all contractors who do business with the DoD. DoD contracts will detail the required security level needed to attain certification. The model is expected to be made so that most small businesses in Washington DC will be able to at least meet the level one requirements.</p>
<p>It&#8217;s also possible that the expenses of gaining compliance could be an allowable cost, so <em>contractors could recover their expenses by achieving the certification</em>.</p>
<p>&nbsp;</p>
<h2>When Is the Deadline</h2>
<p><img decoding="async" class="alignleft wp-image-6203" src="https://www.solvereone.com/wp-content/uploads/when-is-the-deadline.png" alt="when is the deadline" width="214" height="214" srcset="https://www.solvereone.com/wp-content/uploads/when-is-the-deadline.png 378w, https://www.solvereone.com/wp-content/uploads/when-is-the-deadline-300x300.png 300w, https://www.solvereone.com/wp-content/uploads/when-is-the-deadline-150x150.png 150w" sizes="(max-width: 214px) 100vw, 214px" />The <a href="https://www.acq.osd.mil/cmmc/index.html" target="_blank" rel="noopener">Cybersecurity Maturity Model Certification guidelines</a> haven’t yet been released and likely won’t be until later this year.</p>
<p>It’s expected that the certification process will begin throughout 2020 and 2021, although there is no set deadline to attain certification at this point.</p>
<p>Contractors throughout the area including <strong>Northern Virginia</strong> should expect to gain compliance and begin the certification process starting in 2020.</p>
<p>&nbsp;</p>
<h2>How You Can Prepare</h2>
<p><img loading="lazy" decoding="async" class="alignright wp-image-6204" src="https://www.solvereone.com/wp-content/uploads/how-to-prepare.png" alt="how to prepare" width="225" height="225" srcset="https://www.solvereone.com/wp-content/uploads/how-to-prepare.png 453w, https://www.solvereone.com/wp-content/uploads/how-to-prepare-300x300.png 300w, https://www.solvereone.com/wp-content/uploads/how-to-prepare-150x150.png 150w" sizes="(max-width: 225px) 100vw, 225px" />Although no specifics have been published, the CMMC is expected to have new controls as well as some current ones carried over from the 800-171 publication.</p>
<p>Although some contractors in <strong>Washington DC</strong> may have NIST’s 800-171 controls in place, they need to be aware of the new controls as they’re released and make plans to meet them.</p>
<p>Contractors should not expect that just because they have gained 800-171 compliance that they will automatically be eligible for the Cybersecurity Maturity Model Certification.</p>
<p>There will be <em>new controls</em> and depending on which level contractors are required to meet, the cybersecurity measures could be much more advanced than what <em>contractors in Northern Virginia are currently applying</em>.</p>
<p>If the certification is successful in improving cybersecurity for DoD contractors and those that do business with the department, future models could be published for other sectors of the government as well.</p>
<p>&nbsp;</p>
<h2>Solvere One Is CMMC Ready!</h2>
<p><img loading="lazy" decoding="async" class="alignleft wp-image-6205" src="https://www.solvereone.com/wp-content/uploads/solvere-one-cmmc-certification-ready.png" alt="solvere one is CMMC certification ready" width="204" height="204" srcset="https://www.solvereone.com/wp-content/uploads/solvere-one-cmmc-certification-ready.png 400w, https://www.solvereone.com/wp-content/uploads/solvere-one-cmmc-certification-ready-300x300.png 300w, https://www.solvereone.com/wp-content/uploads/solvere-one-cmmc-certification-ready-150x150.png 150w" sizes="(max-width: 204px) 100vw, 204px" /><strong>If you do business with the DoD</strong>, you need to be ready for the new Cybersecurity Maturity Model that’ll be released later this year.</p>
<p><em>Solvere One provides CMMC-ready solutions</em> and is prepared to help you meet the necessary controls.</p>
<p>Our expert team can help you prepare now to ensure you’re ready to gain compliance, and when the model is released, you’ll be ahead of the game to <strong>attain certification!</strong></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Six Things You Should Know About Cybersecurity Regulation</title>
		<link>https://www.solvereone.com/six-things-know-cybersecurity-regulation/</link>
		
		<dc:creator><![CDATA[solvereone]]></dc:creator>
		<pubDate>Mon, 27 Nov 2017 23:00:16 +0000</pubDate>
				<category><![CDATA[Homepage Slider]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Resources]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Provider]]></category>
		<category><![CDATA[Regulation]]></category>
		<guid isPermaLink="false">https://www.solvereone.com/pages/?p=5029</guid>

					<description><![CDATA[Six Things You Should Know About Cybersecurity Regulation With the upcoming DoD deadline to incorporate the new cybersecurity regulation items into your nonfederal information system, government contractors are attempting to meet these requirements before December 31, 2017. Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 stipulates that nonfederal organizations put measures in place to protect classified [&#8230;]]]></description>
										<content:encoded><![CDATA[<h1>Six Things You Should Know About Cybersecurity Regulation</h1>
<p>With the upcoming DoD deadline to <strong>incorporate the new cybersecurity</strong> regulation items into your nonfederal information system, government contractors are attempting to meet these requirements before December 31, 2017.</p>
<p>Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 stipulates that <em>nonfederal organizations</em> put measures in place to protect classified defense information (CDI). These measures are outlined in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, Revision 1.</p>
<p>Are you ready for the upcoming deadline? Here are six things you should know about the new cybersecurity regulation.</p>
<p>&nbsp;</p>
<h2> For Accurate and Timely Results, Work with Professionals</h2>
<p>&nbsp;</p>
<p><a href="https://www.solvereone.com/wp-content/uploads/cyber-security.jpg"><img loading="lazy" decoding="async" class="alignleft wp-image-5032 size-full" src="https://www.solvereone.com/wp-content/uploads/cyber-security.jpg" alt="security" width="300" height="201" /></a></p>
<p>This is especially true if you’re in a time crunch. As a contractor, you can <strong>evaluate and select a professional IT</strong> company to provide you with high quality services to meet this cybersecurity regulation. These professionals can measure your cybersecurity risks and work with you to implement all 110 controls of NIST SP 800-171.</p>
<p>Working with a <a href="https://www.bloomberg.com/news/articles/2017-11-06/regulation-can-t-solve-cybersecurity-problems-fed-official-says" target="_blank" rel="noopener">professional IT provider</a> will help you get the ball rolling much faster—not to mention more accurately—than if you were to try and meet the requirements by yourself. To <em>get your company in gear</em>, find an IT provider that can help.</p>
<p><strong> </strong></p>
<h2></h2>
<h2>If You Fail to Comply, Expect Consequences</h2>
<p><a href="https://www.solvereone.com/wp-content/uploads/cybersecurity-regulation.jpg"><img loading="lazy" decoding="async" class="alignright wp-image-5034 size-full" src="https://www.solvereone.com/wp-content/uploads/cybersecurity-regulation.jpg" alt="security regulation" width="300" height="201" /></a>Although currently the government lacks resources to audit your compliance, they may ask to see your <strong>documented security plan</strong>. If your security plan is found to be in non-compliance with cybersecurity regulation, your organization may face consequences.</p>
<p>These penalties include having up to 20% of your pay withheld, your work suspended, or termination of your contract. You can <em>avoid these consequences</em> by ensuring compliance is met before the December 31, 2017 deadline.</p>
<p><strong> </strong></p>
<h2>The Cost of Compliance</h2>
<p><a href="https://www.solvereone.com/wp-content/uploads/cybersecurity-professionals.jpg"><img loading="lazy" decoding="async" class="alignleft wp-image-5035 size-full" src="https://www.solvereone.com/wp-content/uploads/cybersecurity-professionals.jpg" alt="professional cybersecurity" width="300" height="201" /></a>Currently, specific guidelines are lacking for how these compliance expenses will be handled. For some companies, meeting the cybersecurity regulation will only require a few tweaks in their system. For others, a complete overhaul <strong>may be needed</strong>.</p>
<p>These <em>business expenses</em> related to compliance may be considered indirect costs; therefore, they may be allowable expenses under your contract if considered fair and reasonable. Regardless of the cost of compliance, you’ll still be expected to meet the requirements in order to continue your work for the government.</p>
<p><strong> </strong></p>
<h3></h3>
<h3>Cybersecurity Liability Insurance Isn’t Required</h3>
<p><a href="https://www.solvereone.com/wp-content/uploads/professional-it-cybersecurity.jpg"><img loading="lazy" decoding="async" class="alignright wp-image-5036 size-full" src="https://www.solvereone.com/wp-content/uploads/professional-it-cybersecurity.jpg" alt="IT cybersecurity" width="300" height="201" /></a>DFARS isn’t requiring contractors to <strong>purchase cybersecurity</strong> liability insurance. If you choose to purchase this insurance, the cost may or may not be allowable under your contract, depending on whether or not it’s necessary and sufficient.</p>
<p>&nbsp;</p>
<p>Keep in mind that even if you experience a breach and your cybersecurity insurance denies to cover the costs, there’s no guarantee that it would be an allowed expense relating to your contract for this cybersecurity regulation. <em>Your company needs</em> to decide whether cybersecurity liability insurance would be worth it for your contract.</p>
<p><strong> </strong></p>
<h3>Liability Concerning Government Contractors</h3>
<p><strong><a href="https://www.solvereone.com/wp-content/uploads/professional-it-company.jpg"><img loading="lazy" decoding="async" class="alignleft wp-image-5037 size-full" src="https://www.solvereone.com/wp-content/uploads/professional-it-company.jpg" alt="Cybersecurity Regulation" width="300" height="201" /></a>It’s important</strong> to keep in mind that primary contractors of the DoD are responsible for the performance of their subcontractors; this includes subcontractors’ ability to comply with NIST SP 800-171. Primary contractors don’t always communicate things such as cybersecurity regulation to their subcontractors, but you may be liable if your subcontractors aren’t meeting the regulations.</p>
<p>You can avoid penalties and help lessen your liability by <em>communicating</em> the NIST SP 800-171 requirements to your subcontractors before the deadline to give them a chance to meet the regulation before it’s too late.</p>
<p>&nbsp;</p>
<h3></h3>
<h3>Contractors and Limited Cybersecurity Staffing</h3>
<h3></h3>
<p><a href="https://www.solvereone.com/wp-content/uploads/professional-cybersecurity-it-team.jpg"><img loading="lazy" decoding="async" class="alignright wp-image-5038 size-full" src="https://www.solvereone.com/wp-content/uploads/professional-cybersecurity-it-team.jpg" alt="cybersecurity team" width="300" height="201" /></a>Cybersecurity <em>professionals tend to be limited</em> in the world today, where daily threats are commonplace. While it’s a challenge to keep staff on hand to help with your cybersecurity regulation needs, you are responsible for this task as a government contractor.</p>
<p>You can create a balance of employees, tools, and<a href="https://www.solvereone.com/it-security-consultant-northern-virginia.html"> resources to meet your cybersecurity</a> needs. Know that the DoD won’t make an exception just because you may be having trouble finding an appropriate provider, so be sure to secure cybersecurity staff as soon as possible.</p>
<p>Are you ready for the new cybersecurity regulation? You can analyze the scope of your CDI to determine what needs to happen before the deadline. Working with a provider can accelerate the process, and remember that <em>non-compliance won’t come</em> without consequences. You can achieve compliancy before the deadline to uphold your contracts!</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
