CHAPTER 4: CMMC IMPLEMENTATION
The whole point of the CMMC process goes back to the original requirement of DFARS 52.204-7012 – to provide ‘adequate security’.
But what is adequate security? In the past the legislation would have created a set of controls as adequate security. This has changed. This test of adequate security is now known as the risk-based standard and is in line with most modern cybersecurity legislation around the world. It is similar to the EU’s General Data Protection Regulation (GDPR) Article 32, which requires anyone who processes the information of EU residents to “implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.”30
About 20 US states have similar requirements. ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access