Katie Arrington: CMMC Seeks to Protect Companies Against Negligence

Katie Arrington, chief information security officer at the office of the assistant secretary of Defense for Acquisition and Sustainment and a 2020 Wash100 Award recipient, said the Cybersecurity Maturity Model Certification (CMMC) framework does not aim to punish companies for failing to anticipate cyber breaches like the SolarWinds hack but to protect them from negligence, Breaking Defense reported Friday.

“SolarWinds wasn’t normal. No one is going to take that against you and take your certification away against a nation-state actor penetrating in a way that has never been done before — absolutely not,” Arrington said at an AFCEA event.

In mid-December, the Cybersecurity and Infrastructure Security Agency released an emergency directive directing all federal civilian agencies to mitigate a compromise that threat actors are exploiting in SolarWinds’ Orion Network Management products. The breach was believed to be carried out by hackers from Russia.

CMMC seeks to help companies build a security baseline to compete for contracts with the Department of Defense and incentivize them for meeting expectations.

“If you get hit by something like SolarWinds, which everybody is going through right now, you’re not going to lose it over that. That’s something that the TTP was new. Nobody had planned for that,” said Arrington. “But if you come in, and there’s a cyber incident at your company and it happened because you weren’t deploying your multi-factor authentication, then you do run a risk.”

Share the Post:

Related Posts

5 Key Values of the Wash100 Award

The government contracting industry thrives on leadership, innovation and undeniable contributions to key missions. The Wash100 Award, established by Executive Mosaic in 2014, is an annual recognition of the GovCon...

Top 5 Most Popular Wash100 Winners of All Time

The 100 leaders named to the Wash100 every year by premier government contracting events and media company Executive Mosaic are all renowned members of the federal services ecosystem. But only...

Popular Vote Winner Judi Dotson On What Wash100 Means to Her

In 2024, Judi Dotson, president of the global defense sector at Booz Allen Hamilton, has earned a reputation for making Wash100 history. In March, she became the first Wash100 recipient...