<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CDM Archives - Corsec Security, Inc.®</title>
	<atom:link href="https://sitdev.corsec.com/tag/cdm/feed/" rel="self" type="application/rss+xml" />
	<link>https://sitdev.corsec.com/tag/cdm/</link>
	<description>Corsec helps companies complete security certifications and validations like FIPS 140-2, Common Criteria, and listing on the DoDIN APL / UC APL.</description>
	<lastBuildDate>Mon, 07 Feb 2022 19:54:51 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>

<image>
	<url>https://sitdev.corsec.com/wp-content/uploads/cropped-Corsec-Logo-SiteMap-32x32.png</url>
	<title>CDM Archives - Corsec Security, Inc.®</title>
	<link>https://sitdev.corsec.com/tag/cdm/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>CDM: The Old and The New</title>
		<link>https://sitdev.corsec.com/cdm-the-old-and-the-new/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Wed, 13 Feb 2019 14:45:13 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[CDM]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[federal regulation]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=16809</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5><strong>The Continuous Diagnostics and Mitigation Program</strong></h5>
<p><span style="font-style: inherit !important; font-weight: inherit !important;">The Continuous Diagnostics and Mitigation (CDM) Program was originally a multiple award IDIQ released under the GSA Schedule 7o Blanket Purchase Agreement (BPA). It was</span> created to establish &#8220;a dynamic approach to fortifying the cybersecurity of government networks and systems.&#8221;</p>
<p>The program was<span style="font-style: inherit !important; font-weight: inherit !important;"> designed to provide the Department of Homeland Security and other federal agencies with the capabilities, resources, and tools to</span> 1.) Identify cybersecurity risks on an ongoing basis, 2.) Prioritize these risks based upon potential impacts, and 3.) Enable cybersecurity personnel to mitigate the most significant problems first.</p>
<p><span style="font-style: inherit !important; font-weight: inherit !important;">As threats changed, the CDM program offered federal agencies COTS tools to support technical modernization efforts. Additionally, CDM provided a structured methodology to allow for risk prioritization based on perceived impact, with the goal of mitigating the most significant risks, flaws, and bugs first. To do this, CDM used a four-phase process with an end goal of collecting and analyzing vulnerabilities data to make “strategic decisions regarding systematic cyber security risks across the entire Federal civilian enterprise.” </span></p>
<p><span style="font-style: inherit !important; font-weight: inherit !important;">Ultimately, CDM provided a means to address and react to threats as they occurred, which decreased vulnerabilities and mitigated the risk of network exploitation.</span></p>
<p><span style="font-style: inherit !important; font-weight: inherit !important;">Since its inception, the acquisition strategy for the CDM program changed. As stated, it originally was a DHS issued Blanket Purchase Agreements (BPA) under the GSA IT Schedule 70 contract, known and referred to as the CDM Tools/Continuous Monitoring as a Service (CMaaS) BPAs. These BPAs expired in August of 2018. </span></p>
<p><span style="font-style: inherit !important; font-weight: inherit !important;">To continue the mission and goals of the program, t</span><span style="font-style: inherit !important; font-weight: inherit !important;">he following two acquisition strategies were developed to allow Vendors to compete on projects that address the mission of CDM:</span></p>
<ul>
<li><span style="font-style: inherit !important; font-weight: inherit !important;"><strong>For Products </strong>(SW &amp; HW) – Issuance of a CDM Tools SIN (132-44) under the GSA IT Schedule 70</span></li>
<li><span style="font-style: inherit !important; font-weight: inherit !important;"><strong>For Services</strong> &#8211; Task Orders referred to as CDM Dynamic and Evolving Federal Enterprise Network Defense (DEFEND) under the GSA GWAC Alliant</span></li>
</ul>
<p><span style="font-style: inherit !important; font-weight: inherit !important;">The programs are still consistent with NIST and OMB guidance as well as fulfillment of the Federal Information Security Management Act (FISMA).</span></p>
<h5><strong>CDM Tools SIN (132-44)</strong></h5>
<p>The new SIN is organized into five subcategories based on CDM capabilities:</p>
<ol>
<li>Manage “What is on the network?”</li>
<li>Manage “Who is on the network?”</li>
<li>Manage “How is the network protected?”</li>
<li>Manage “What is happening on the network?”</li>
<li>Emerging Tools and Technology</li>
</ol>
<p>To be added to the CDM Tools SIN, Vendors must submit their product for qualification review. Prior to applying, vendors must first have their product listed on the DHS Approved Products List (APL), and second, be a current holder of the GSA Schedule 70 GWAC. Acceptance onto the APL is reviewed on a monthly basic &#8211; the process to being added can be found <a href="https://sitdev.gsa.gov/technology/technology-products-services/it-security/continuous-diagnostics-mitigation-cdm/continuous-diagnostics-mitigation-cdm-tools-special-item-number-sin-information-for-vendors">here</a>.</p>
<p>A current list of all vendors and products currently available for procurement under the CDM Tools SIN can be found <a href="https://sitdev.gsaelibrary.gsa.gov/ElibMain/sinDetails.do?executeQuery=YES&amp;scheduleNumber=70&amp;flag=&amp;filter=&amp;specialItemNumber=132+44">here</a>.</p>
<p>For help with requirements or other certification related concerns, please reach out and discuss with a Corsec expert &#8211; <a href="https://sitdev.corsec.com/contact-us/">Connect</a></p>
<p>&nbsp;</p>
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;">Stay Up to Date:</strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <span style="color: #0000ff;"><a style="color: #0000ff;" href="https://ww3.corsec.com/subscribe">Subscribe</a></span></p>
<p style="text-align: center;">###</p>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div>
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5 class="wpb_text_column wpb_content_element "><strong><a href="https://sitdev.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<div class="wpb_text_column wpb_content_element "><a href="https://sitdev.linkedin.com/company/corsec-security"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>
</div>
</div>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Content Delivery Network via cdn.corsec.com

Served from: sitdev.corsec.com @ 2026-05-30 23:18:43 by W3 Total Cache
-->