Would CMMC compliance block a SolarWinds-style attack? --

General News

Summary

In the wake of infiltration of government and private networks through SolarWinds software and the ransomware attack on Colonial Pipeline, lawmakers are looking to reduce the exposure of federal and critical infrastructure systems to hacks. However, the extent to which contractors may have to dig into their own pockets to obtain certification is a running concern -- so much so that Kathleen Hicks, the deputy secretary of defense, ordered a review of the program in March. That review is finished, according to Sen. Joe Manchin (D-W.Va.), speaking at a May 18 hearing of the Senate Armed Services Committees Cybersecurity Subcommittee, but the Defense Department’s recommendations are not complete. Rear Admiral William Chase, the deputy principal cyber advisor to the secretary of Defense, told senators that CMMC compliance wouldnt necessarily thwart a supply chain style attack used in the SolarWinds campaign, but it could enable detection. Prior to joining FCW, Mazmanian was technology correspondent for National Journal and served in a variety of editorial roles at B2B news service SmartBrief.

Classifications

industries
No industries detected
applications
Customer Service & Support

AskAI Classifications

Labels
IT Management Software Virtualization Management Software SaaS

Linked Companies

Hyper9
$1M to $5M
SolarWinds Worldwide LLC
$250M to $500M