To download a copy of the paper click here:
The current state of information security in the United States is horrendous. Massive data breaches and other incidents are regularly in the headlines. Much of the compromised information does not even belong to the entities suffering the incidents. Instead, it has been entrusted to them by one or more disclosing entities.
Most disclosing entities are at their vendors’ mercy. They do not have the information or knowledge necessary to properly evaluate the receiving entity’s security claims. Disclosing entities need an objective means through which they can be assured that the receiving entity can properly safeguard the information the disclosing entity wishes to entrust to them.

The United States government has been wrestling with this same issue for a number of years
as part of its Controlled Unclassified Information (“CUI”) program. Under this program, the
government has established a minimum set of safeguarding requirements, referred to as
NIST SP 800-171, that must be in place before the government can share CUI with a
contractor or other non-federal entity.
The United States Department of Defense (“DoD”) learned the hard way that merely asking non-federal entities whether they have the minimum safeguarding requirements in place was not effective. Studies and DoD’s own investigations revealed that over two thirds of commercial non-federal entities did not even have in place some of the core requirements.
To help ensure that CUI is properly safeguarded when shared with vendors, DoD created the CMMC program. Under the CMMC program, specially trained, independent third parties validate vendors’ claims that they comply with the minimum safeguarding requirements. If a vendor meets the requirements, the third party issues a certificate to the vendor.
Almost all of DoD’s 75,000+ vendors that handle CUI will soon be required to have a CMMC certification before DoD will sign a contract with them. By leveraging NIST SP 800-171 + CMMC certifications, DoD will gain significant confidence in their vendors’ ability to properly safeguard sensitive information that is shared with the vendor.
Given the significant leverage other federal agencies have, and the similar leverage state and local governments have, in their procurements, it is easy to see how the same program could be implemented, and would be beneficial to, the entire spectrum of Governmental entities.
To aid those entities as they evaluate NIST SP 800-171 + CMMC, the CUI Institute has published “CMMC: A National Imperative.”
Available below, this paper includes a summary of the histories of the CUI and CMMC programs and a discussion of their relevance to other Governmental entities. It also includes a discussion of issues DoD faced with, and quashes common misconceptions and arguments against, the adoption of NIST SP 800-171 + CMMC. The paper further provides an analysis how Governments can adopt NIST SP 800-171 + CMMC as the minimum standard for evaluating the adequacy and sufficiency of any receiving entity’s information security program and how existing laws, regulations and government policies should be amended to, and any new laws or regulations should, adopt NIST SP 800-171 + CMMC.
The paper is released under the open source CC-BY license, meaning it can be freely shared with legislators, regulators, and anyone else you think would benefit from reading it.
To download a copy of the full paper, click here:
