
Managing supply chain security is a monumental task for the Ministry of Defence (MoD). It does this through the Defence Cyber Certification (DCC), set out in Defence Standard 05-138. This framework takes a pragmatic, risk-based approach to supplier requirements; you don’t need to apply the same requirements to banana vendors as you do on ballistic missile manufacturers.
There are four different variants based on assessed Cyber Risk Profile (CRP); levels 0 to 3. These align to different risk levels, arising from the different criticalities of the contracted services, which the framework refers to as the Function, and the secrecy or sensitivity of the data handled during the delivery of the Function. The CRP for a given Function is stated in the Security Aspects Letter (SAL) or other contract documentation.
Every level requires a Cyber Essentials or Cyber Essentials Plus certification as a baseline. This is one of the many hints that this standard was drafted in close collaboration with the National Cyber Security Centre (NCSC).
This baseline matters because the market is growing rapidly; the government is aiming to spend 3% of GDP on defence by the end of this parliament, representing additional spending in the tens of billions. To access this money, you will need DCC compliance.
While undoubtedly some of this additional money will go to existing suppliers, this is an incentive for many smaller companies to join the defence supply chain to build and expand their businesses.
Here is what we at Cydea have learned preparing our clients for the Defence Cyber Certification.
There is an asset management focus within this certification. If you do not know what you have, not only can you not secure it, you cannot scope the certification properly. For Level 1 of the certification and higher, there is a requirement for automated asset inventory systems;
A comprehensive and well-organised policy set will speed up the certification preparation process. This is for two reasons. The first is that it can make a gap analysis comparatively quick and easy. The second is that it provides easy reference for assessors when they are looking through both technical and non-technical practices;
Identifying a few broader uplifts, like a more advanced control, to cover several more bespoke requirements can mean reaching this standard more quickly and cheaply. For example, an advanced EDR system from a tenant license upgrade can help achieve requirements 3201, 3108, 3203 and 3200 for some businesses, and also meet 2409 through device management systems bundled into this upgrade. This could be cheaper than procuring endpoint protection and device management separately;
Every defence supplier and service they provide to customers is different, and the approach to satisfying requirements needs to take their operations into account. For example, information processors and professional services will have different data and personnel security requirements to manufacturers. One size will not necessarily fit all.
Think about what comes after DCC; while you’re planning this security programme, are there any other changes you can make to support your organisation’s growth which align to your DCC-focused security programme? What other frameworks, like the CMMC or even ISO 27001, are your other public sector clients looking for?
Understanding the level you need to achieve usually means you have a contract you are in the running for.
There are some scenarios in public sector contract work which can be chicken-and-egg, and this is one of them. To attain the contract, you (theoretically) need to achieve a given level of the framework. To know which level you need to attain, you need to be in the running to bid on the contract.
The control uplift required to attain this standard can be expensive, so it has to be worth the tradeoff.
Depending on the level mandated in the contract, there may be a number of technical controls you have not yet implemented which the standard requires, especially if your organisation is a small or medium enterprise. This is especially true for levels 2 and 3, where monitoring requirements, active threat hunting, and multi-layered technical controls are focused:
- Level 0: 3 controls
- Level 1: 101 controls
- Level 2: 139 controls
- Level 3: 144 controls
The tradeoff that businesses must consider is whether the value of the contract and projected follow-on work from that contract justifies the expenditure on a DCC-compliant security programme.
Once you understand the level you need to achieve, a gap analysis provides the roadmap to achieve the standard.
Understanding the costs involved means you must first understand gaps between your current cyber security programme and the one the DCC requires. You may want to work with an external partner, like Cydea, to understand these gaps quickly and accurately and understand your next steps in detail. The gap analysis involves understanding your technical controls, key operations, and policy suite, and anticipating what a certification body will look for to meet each requirement.
Building business cases and managing your security programme will help get your organisation to your goal.
The business can cost this programme in terms of people and money required, allowing an informed cost-benefit analysis. If the primary objective of your programme is to achieve the DCC, then the primary actions to prioritise are the ones to close the gaps.
Resource-effective cyber security programmes do at least one of the following:
- Improve efficiency;
- Bring cyber security risk below risk appetite;
- Comply with a law or regulation;
- Attain a certification which an organisation believes will increase its competitiveness or win business.
The DCC sits firmly in the last category, but it’s best to still identify opportunities to manage risk and improve efficiency through any DCC-focused security programme.
How Cydea Can Help
Navigating the DCC can be daunting, especially for smaller organisations without a dedicated cyber team or prior defence experience. We can help you to simplify the process:
- Cyber Essentials: We leverage our deep experience with CE and CE+ to secure your mandatory compliance foundation quickly.
- Control Mapping: We can support you to interpret how the specific requirements apply to your specific environment with our Risk Platform.
- Expert Advice: Much like audit preparation, we provide hands-on advice to ensure your policies and systems pass the formal certification.
Get in touch with Cydea today to fast-track your readiness and secure your place in the defence supply chain.
Photo by Seongtaek Chee on Unsplash