DOD will start requiring contractors to meet cybersecurity standards next month

iStock 1061227424 scaled

The Department of Defense (DOD) will roll out its Cybersecurity Maturity Model Certification (CMMC) in January 2020 so that it can ensure contractors on government projects have the necessary cybersecurity practices in place to protect the controlled unclassified information (CUI) to which they are privy. The type of information the DOD is trying to protect includes data pertaining to critical infrastructure, nuclear, proprietary business information, procurement and acquisition. 

All DOD contractors must be certified through the third-party provider of their choice at the contractor’s expense. Certification levels range from basic to advanced, and in June 2020 contractors will start seeing references to CMMC requirements in Requests for Proposals. Some higher-level assessments may be performed by the DOD, the Defense Contract Management Agency or the Defense Counterintelligence and Security Agency.

The loss of CUI, the DOD said, poses risks to the United States’ economic security and national security, so the department is trying to better secure this information. The Executive Office of the President’s Council of Economic Advisers estimated in 2016 that malicious cyber activity cost the nation’s economy between $57 billion and $109 billion.

The DOD released the latest draft version of the CMMC for public review earlier this month. In that document, the DOD delves deeper into the levels of certification.

  • Level 1 – the contractor demonstrates basic cyber hygiene as defined by Federal Acquisition Regulation
  • Level 2 – the contractor demonstrates intermediate cyber hygiene and has established standard operating procedures, policies and plans for all its practices.
  • Level 3 – the contractor demonstrates good cyber hygiene and effective NIST SP 800-171 Rev 1 (Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations) security requirements and reviews its activities for adherence to policies and procedures.
  • Level 4 – the contractor demonstrates a substantial and proactive cybersecurity program, reviews activities for effectiveness and informs management of any issues.
  • Level 5 – the contractor demonstrates a proven ability to optimize capabilities in an effort to repel advanced persistent threats, standardizes its activities across all applicable business units and shares identified improvements. 

In addition, some areas that contractors will be required to address in the certification process are:

  • Access control policies
  • Identification and authentication procedures
  • Media protection strategies
  • Protecting physical access
  • System and communication protection
  • System and informational integrity

As construction industry contractors continue to take bigger steps toward technology adoption, cyberattacks are not the only issue that should concern them. A rise in the popularity of wearables โ€”  heart rate monitors, location trackers, fall and fatigue detectors โ€” and detect falls, and hard hat inserts that check for fatigue โ€”  has also raised questions about data collection and privacy. 

The Safety Equipment Association has started preliminary discussion around a standard that would protect worker privacy when it comes to wearables, but that process could take years. In the meantime, contractors should start thinking about “the potential for abuse and misuse,” attorney Michelle Schaap with Chiesa Shahinian & Giantomasi PC told Construction Dive earlier this year. “Any company that adopts these tools,” she said, “must consider all of the value-adds and the potential risks before implementing these new technologies.โ€

Source: Construction Dive

Similar Posts

  • Social distancing and site monitoring tech rapidly rolling out to US construction sites

    FacebookXRedditPinterestEmailLinkedInWhatsApp The coronavirus pandemic has shocked U.S. construction into needing to adopt new technologies to maintain social distancing and monitor jobsites remotely. Those adaptations, some construction leaders say, should have been adopted in the first place, before the pandemic forced contractors to implement them. The outbreak has also forced more connection between the site and office, as…

  • Technology Drives Innovation in the Construction Industry

    FacebookXRedditPinterestEmailLinkedInWhatsApp Construction technology is undoubtedly one of the most exciting pockets of innovation in todayโ€™s economy.  Funding in U.S.-based construction technology startups surged by 324 percent to nearly $3.1 billion in 2018, compared with $731 million in 2017, according to Crunchbase data.  Investment spans hardware, software, AI and other exciting technologies.  For too long, the…

  • Why we should be rebooting the future for more equal success?

    FacebookXRedditPinterestEmailLinkedInWhatsApp Businesses must remain alert for both future growth opportunities and potential threats. The dawn of advanced technology has enabled, and in many cases forced, quick mobilization into different growth areas, rapid industrialization and wide ranging global expansion. It has also brought profound change, such as improved healthcare, better access to finance and educational opportunities….

  • Office of Business Opportunity Collaborates with Law Firms to Provide Free Legal Advice to Small Businesses

    FacebookXRedditPinterestEmailLinkedInWhatsApp Small businesses impacted by the COVID-19 pandemic now have a resource for free legal advice, thanks to the Houston Small Business Legal Consultations (HSBLC) Program in collaboration with the City of Houstonโ€™s Office of Business Opportunity (OBO), Vinson & Elkins (V&E) and several private law firms. Through a network of volunteer attorneys, HSBLC will provide participants…

  • Dallas recognized for โ€˜Deal of the Yearโ€™ award

    FacebookXRedditPinterestEmailLinkedInWhatsApp The City of Dallas Office of Economic Development has won Business Facilitiesโ€™ 2019 Deal of the Year Bronze Award for Uber Technologiesโ€™ U.S. Administrative Hub. Uberโ€™s new hub, based at The Epic in Dallasโ€™ Deep Ellum neighborhood, will create 3,000 new jobs and more than $75 million in capital investment. Uber will provide a…