DEC 04, 2020 | US
Industry Groups Weigh In on CMMC Costs, Guidelines for Assessment As Pentagon Interim Rule Takes Effect
Inside Cybersecurity, December 4, 2020
By Sara Friedman
Industry groups across a wide range of sectors are asking the Defense Department to provide more details on how its new cyber certification program will impact government contractors.
Depending on the type of product or service, DoD vendors may already be subject to assessment, certification, or direction under a number of existing initiatives across DOD and the Federal Government,” BSA | The Software Alliance wrote to the Pentagon, referring to the General Service Administration’s FedRAMP program, DoD’s Cloud Computing Security Requirements Guide (SRG) and audits from the Defense Contract Management Agency.
“Moreover, many vendors may obtain certifications against internationally recognized standards that attest to security controls covered by the CMMC,” BSA said. “It is unclear how CMMC certification, above and beyond these existing obligations, would improve the Department’s confidence in the security practices of such vendors.”
Original Posting: https://insidecybersecurity.com/daily-news/industry-groups-weigh-cmmc-costs-guidelines-assessment-pentagon-interim-rule-takes-effect
关于 BSA
The Business Software Alliance (www.bsa.org) 是全球软件行业的主要倡导者,旨在代表该行业,向政府和国际市场发声。其成员包括全球最具创新力的公司,这些公司制定的软件解决方案,不但能够刺激经济,还能提升现代生活的品质。