Cybersecurity, Privacy, & AI

Trending Now
OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns • Cyber-attacks Against State Water Supplies Continue—12 to Date • A Crucial Cybersecurity System Is Getting a Closer Look From Congress • Why Federal AI Governance Must Be Built for Continuous Change • NATO and an AI Startup Can Now Name and Track Software Vulnerabilities

Civilian Vendor Cybersecurity Certification Would Look Very Different From DoD

Gorodenkoff | Shutterstock

The Defense Department is working on a new Cybersecurity Maturity Model Certification policy that will require its vendors to confirm their own systems have strong enough cybersecurity to protect the department’s secrets. A civilian agency counterpart to that would look very different from what the Pentagon is developing, says deputy federal CIO Margie Graves.

A similar program would be useful in the civilian space but would require a much different framework, according to Graves. “We, as a civilian community, cannot adopt DOD rubrics writ-large,” she said. “But there are some aspects of the civilian agencies – I would say, [the Homeland Security and Justice departments] and others in the law enforcement among them – that are similar. We could actually learn from the framework that’s being set up with DOD on that issue.”

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.