Most compliance work goes into proving security, not improving it. That isn’t because the rules are unreasonable. Regulators, customers, and cyber insurers are right to expect organizations to implement hundreds of technical and administrative controls, monitor their environments, respond to incidents, and prove that all of it works. The problem is the cost of delivering it. The Pentagon’s own estimate puts a small contractor’s CMMC level 2 compliance at roughly $105,000 over three years. That … More →
Read the original article:
