Blog
What is Cybersecurity Maturity Model Certification (CMMC) v1.0?
February 5, 2024|CMMC, Compliance
The Cybersecurity Maturity Model Certification (CMMC) is a framework designed by the United States Department of Defense (DoD) to ensure that defense contractors have the necessary controls to protect sensitive data, including Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
The CMMC framework integrates various cybersecurity standards and best practices into a comprehensive set of requirements for cybersecurity maturity across five levels, ranging from basic cyber hygiene to advanced. Each level consists of practices and processes that range from safeguarding information to protecting against Advanced Persistent Threats (APTs).
The CMMC framework is organized into 17 domains, each representing a high-level control area. These domains are:
- Access Control (AC): Manages access to information and systems.
- Asset Management (AM): Identifies and manages assets.
- Audit and Accountability (AU): Defines requirements for auditing and ensuring accountability.
- Awareness and Training (AT): Focuses on security awareness and training for personnel.
- Configuration Management (CM): Manages security configurations for technology and software.
- Identification and Authentication (IA): Ensures the proper identification and authentication of users.
- Incident Response (IR): Prepares for and responds to cybersecurity incidents.
- Maintenance (MA): Involves the maintenance of systems to ensure their security.
- Media Protection (MP): Protects media containing CUI, both paper and digital.
- Personnel Security (PS): Addresses security measures related to personnel.
- Physical Protection (PE): Focuses on physical security to protect against unauthorized access.
- Recovery (RE): Establishes resilience and recovery processes for systems.
- Risk Management (RM): Identifies, assesses, and manages cybersecurity risks.
- Security Assessment (CA): Assesses the security controls to ensure they are effective.
- Situational Awareness (SA): Provides awareness of cyber threats and vulnerabilities.
- System and Communications Protection (SC): Protects systems and communications.
- System and Information Integrity (SI): Ensures systems and data are accurate and free from unauthorized modification.
Each of these domains contains a set of practices and processes that contribute to the overall cybersecurity posture of a defense contractor, ensuring the protection of sensitive information against cyber threats. The specific requirements within each domain vary according to the CMMC level (1 through 5) a contractor needs to achieve, with higher levels requiring more sophisticated and comprehensive cybersecurity practices and processes.
What are the CMMC Maturity Levels?
The CMMC v1.0 framework categorizes cybersecurity best practices at five distinct maturity levels. Each level builds upon the requirements of the previous ones, increasing in complexity and rigor to provide a pathway for organizations to progressively enhance their cybersecurity posture. These levels are designed to safeguard CUI and FCI within the Defense Industrial Base (DIB).
Here's a breakdown of the CMMC maturity levels:
Level 1: Basic Cyber Hygiene
- Focus: Protect Federal Contract Information (FCI)
- Requirements: Implement 17 basic cybersecurity practices, akin to those outlined in Federal Acquisition Regulation (FAR) Part 52.204-21. It emphasizes the protection of FCI from unauthorized access and disclosure.
- Processes: At this level, the organization is expected to perform the specified practices. However, there is no process maturity requirement.
Level 2: Intermediate Cyber Hygiene
- Focus: Transition step in protecting Controlled Unclassified Information (CUI)
- Requirements: Introduces an additional 55 practices, for a total of 72. These practices start to incorporate a selection of the security requirements from NIST SP 800-171, as well as other cybersecurity best practices.
- Processes: Organizations are expected to document their policies and practices, demonstrating that they have established and documented standard operating procedures for cybersecurity.
Level 3: Good Cyber Hygiene
- Focus: Protect CUI
- Requirements: Adds 58 practices for a total of 130. This level encompasses all of the NIST SP 800-171 Rev 1 security requirements along with additional practices to mitigate threats.
- Processes: Requires that an organization establish, maintain, and resource a plan demonstrating the management of activities for practice implementation. This plan could include information on missions, goals, project plans, resourcing, required training, and involvement of relevant stakeholders.
Level 4: Proactive
- Focus: Protect CUI and reduce risk of Advanced Persistent Threats (APTs)
- Requirements: Introduces 26 more practices, for a total of 156. These practices enhance the detection and response capabilities of an organization to address and adapt to the changing tactics, techniques, and procedures (TTPs) used by APTs.
- Processes: At this level, organizations are required to review and measure practices for effectiveness. Additionally, they must take corrective action when necessary and inform higher-level management of status or issues on a recurring basis.
Level 5: Advanced/Progressive
- Focus: Protect CUI and reduce risk of APTs
- Requirements: Adds 15 practices, for a total of 171. This level focuses on protecting CUI from APTs through sophisticated cybersecurity practices and processes.
- Processes: Organizations must standardize and optimize process implementation across the organization. This means that the cybersecurity practices and processes are not only fully established but also consistently applied and improved upon throughout the organization.
CMMC's tiered model is designed to provide a clear pathway for defense contractors to enhance their cybersecurity measures systematically. The intent is to ensure that all companies within the DIB, regardless of size or function, can safeguard sensitive information effectively against evolving cyber threats.
Additional Information
On December 26, 2023, the Department of Defense published for comment a proposed rule for the Cybersecurity Maturity Model Certification (CMMC) 2.0 program at https://www.regulations.gov/docket/DOD-2023-OS-0063
Dept. of Defense CIO CMMC Resources - https://dodcio.defense.gov/CMMC/Resources/