This month’s release of the much-anticipated CMMC 2.0 left many of us in the world of cybersecurity shaking our heads. We have been working diligently with the defense industrial base for several years now, even before the CMMC was created, to stop the bleeding of our defense secrets to our adversaries. As a veteran and a Patriot, I, along with many other Americans, take this very serious problem personally.
They say that pictures speak a thousand words, so here are just a few to illustrate my point. These are American weapons systems, vs. their Chinese and Russian copies.
American Humvee vs. China’s “Hanma”. There are at least three companies in China known to be building Humvee clones.
American F-22 Raptor, vs. Russian T-50:
Look familiar? It’s not our venerated B2 Bomber or the RQ 170 Sentinel. This is China’s “Skyhawk Drone”:
The blatant theft of American IP (Intellectual Property) isn’t limited to just military tech, either. Here are Chinese copies of the Ford F-150 and the Chevrolet Colorado:
Even worse than these shameless copies, is the outright counterfeiting of American products. Some of these counterfeits are so good that they are nearly indistinguishable, even to the company that designed them. A cursory Internet search speaks volumes:
These are just a few examples of stolen/copied American technology – there are dozens and dozens more. All of those weapon’s systems above were designed and developed at the toil and treasure of U.S. taxpayers, only to save our strategic competitors years of time and BILLONS of dollars in R&D. There are about 300,000 total companies who participate in the DIB (Defense Industrial Base), and MOST of them are smaller companies that have very poor or even no cybersecurity. I know this because I have personally assessed many dozens of them. I even worked with some VERY large, international and/or publicly traded companies who do not take cybersecurity seriously and will not spend money on it.
300,000 companies make for one very large cybersecurity problem, so a little background is in order here. After all, this is a massive problem – imagine the Marshall Plan of IT. The first brick in the foundation for solving the DIB’s cybersecurity issue was laid via Executive Order 13556 – Controlled Unclassified Information, signed by President Obama November 4th, 2010 – over 11 years ago now.
It was this EO that laid down the tracks for NIST Special Publication 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations.” As of December 2015, DFARS 225.204-7012 required DoD contractors to implement NIST 800-171 “as soon as practical, but no later than December 31, 2017” – nearly 4 years ago as of this writing. While this was a step in the right direction and many of the large prime contractors complied willfully, there was no enforcement mechanism at all, and contractors were permitted to “self-certify”. Also, DFAR’s is a supplement to the FAR (Federal Acquisition Regulation) which consists of 37 chapters, with Chapter 1 alone having over 2,000 pages. Many contractors were not even aware of EO 13446 or NIST 800-171, so they made no attempt to comply. Like safety, cybersecurity is a cost center with no direct ROI so cost-conscious companies are simply not going to comply without enforcement.
That is where the CMMC (Cybersecurity Maturity Model Certification) came in. Version 1.0 of the CMMC was released less than a year ago – January 31st, 2020, with the hard-charging, take no prisoners Katie Arrington at the helm as CISO. In June of 2021, Arrington was placed “on leave in connection with a suspected unauthorized disclosure of classified information from a military intelligence agency.” Stringing someone up for unauthorized disclosure is like ticketing someone for jaywalking – literally anyone can be accused of this, and many including myself suspected an ulterior motive. After dismissing Arrington, the CMMC was placed on hold pending an internal Pentagon review, and the results were a CMMC that now looked less like Mr. T. and more like Pee-wee Herman.
Snarkiness aside, let’s talk about why the CMMC 2.0 is such a major step backward over CMMC 1.0. In an open letter to President Biden, the CMMC Information Institute has already covered 2.0’s failings very succinctly, so I am going to just summarize their five-page letter here.
In simple terms, the CMMC 1.0 would do for Cybersecurity what OSHA does for safety – give it teeth. CMMC 2.0 is like getting rid of OSHA’s inspectors to save money and expecting worker safety to improve. Cybersecurity is expensive, but like safety programs, it is simply the cost of doing business. Unless we want to continue getting robbed blind or get our warfighters killed using our own technology, CMMC 2.0 needs to be rethought.
Jason McNew
Senior Engineer, Cybersecurity Risk and Compliance, Appalachia Technologies