Katie Arrington advocates for using artificial intelligence to refine the targeting of the Cybersecurity Maturity Model Certification program.
Katie Arrington, a former South Carolina state legislator and cybersecurity executive, argues that the Cybersecurity Maturity Model Certification (CMMC) program requires more precise targeting of controlled unclassified information (CUI). While the standard itself should remain firm, Arrington notes that current manual assessments of CUI are often inconsistent, leading to some small businesses to face heavy burdens for non-essential data while others with sensitive data slip through. She proposes using artificial intelligence to perform first-pass sorting of CUI from contract language, providing a more consistent starting point for human contracting authorities. Arrington emphasizes that and the broader small business economy must be't equipped to handle growing threats like ransomware and quantum computing. She calls for a dedicated Small Business Administration loan program to provide capital for cybersecurity investments, ensuring that small businesses can defend themselves against increasingly aggressive nation-state actors and ransomware crews.
Sources
-
CMMC review: DoD’s inconsistent CUI marking continues to plague program
Federal News Network
-
JUST IN: Assessors Report Contract Cancellations, Layoffs After CMMC Pause
National Defense Magazine
-
CMMC Works. Now let’s sharpen it.
Nextgov/FCW
-
New Report Shows Defense Contractors’ Self-Reported Cybersecurity Scores Are Rising as Confidence in Their Accuracy Plunges 24 Points
WBOC TV
-
DoD Regulatory Pause: No Excuse to Weaken Supply Chain Trust
BankInfoSecurity