Why the DoD Wants Security Protection Data Protected Like CUI
The CMMC proposed rule introduces a concept some defense contractors find puzzling. Security protection data. This category includes vulnerability scan results, system security plans, network diagrams, firewall configurations, and endpoint security settings. Under 32 CFR Part 170, when an external service provider handles security protection assets but doesn’t process, store, or transmit CUI directly, those … Read more