• 14 days

    So they’re admitting their stuff is crap and that they expect for it to stay that way.

    • More like, the business are whining that security is hard and expensive; so, they shouldn’t be required to do it.

      While I’m no fan of checkbox security, CMMC was kinda like the sign in front of rollercoasters. Except instead of a minimum height, CMMC was saying, “your network must be at least this secure to hold CUI”.

      Seriously, I dealt with this stuff for years as a contractor for the US FedGov. It’s not rocket science. It’s not even hard. But, it does require that you document your shit and do a bit better than accepting the defaults. It won’t make your network secure. But if you are struggling to meet the basic controls, I guarantee that your security is bad.

      • 14 days

        CMMC is more about how well your processes work. Low level = more chaotic, stuff basically works but people have to scurry around and improvise when it breaks. Mid level = it can break but procedures for fixing it are documented and regular, and various good practices are followed to make it reliable. High level = can’t break, very rigorous standards. No attempt at certifying to any level at all = never mind, just wing everything.

        I wonder how much turning everything into piles of AI crap is involved with this.

        • Having worked with compliance across multiple industries, CMMC was created for very good reasons, but was poorly implemented, almost like it was being deliberately sabotaged (spoiler: it was).

          Our supply chain security is a joke in America and the big players have wanted it to stay that way this whole time. I do not think meaningful security standards can be adopted in a system with this level of blatant corruption.

          I’ve also had to do compliance for California Dept. Of Cannabis Control regulations. I’ve been telling people for years: If you want to do security theater, follow the NIST SP 800-171. If you want to do real security, follow CA Cannabis Control standards. I’m not joking.

          • The biggest issues I’ve had with CMMC is that it seems to have been designed without any consideration for software development.