• Journal of Internet Computing and Services
    ISSN 2287 - 1136 (Online) / ISSN 1598 - 0170 (Print)
    https://jics.or.kr/

A Research on RC3(RMF-CMMC Common Compliance) meta-model development in preparation for Defense Cybersecurity


Jae-yoon Hwang, Hyuk-jin Kwon, Journal of Internet Computing and Services, Vol. 25, No. 1, pp. 123-136, Feb. 2024
10.7472/jksii.2024.25.1.123, Full Text:
Keywords: Cybersecurity Audit, Compliance, RMF, CMMC

Abstract

The U.S. Department of Defense, leading global cybersecurity policies, has two main cybersecurity frameworks: the Cybersecurity Maturity Model Certification (CMMC) for external defense industry certification, and the Risk Management Framework (RMF) for internal organizational security assessments. For Republic of Korea military, starting from 2026, the Korean version of RMF (K-RMF) will be fully implemented. Domestic defense industry companies participating in projects commissioned by the U.S. Department of Defense must obtain CMMC certification by October 2025. In this paper, a new standard compliance meta-model (R3C) development methodology that can simultaneously support CMMC and RMF security audit readiness tasks is introduced, along with the implementation results of a compliance solution based on the R3C meta-model. This research is based on practical experience with the U.S. Department of Defense's cybersecurity regulations gained during the joint project by the South Korean and U.S. defense ministries' joint chiefs of staff since 2022. The developed compliance solution functions are being utilized in joint South Korean-U.S. military exercises. The compliance solution developed through this research is expected to be available for sale in the private sector and is anticipated to be highly valuable for domestic defense industry companies that need immediate CMMC certification.


Statistics
Show / Hide Statistics

Statistics (Cumulative Counts from November 1st, 2017)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article
[APA Style]
Hwang, J. & Kwon, H. (2024). A Research on RC3(RMF-CMMC Common Compliance) meta-model development in preparation for Defense Cybersecurity. Journal of Internet Computing and Services, 25(1), 123-136. DOI: 10.7472/jksii.2024.25.1.123.

[IEEE Style]
J. Hwang and H. Kwon, "A Research on RC3(RMF-CMMC Common Compliance) meta-model development in preparation for Defense Cybersecurity," Journal of Internet Computing and Services, vol. 25, no. 1, pp. 123-136, 2024. DOI: 10.7472/jksii.2024.25.1.123.

[ACM Style]
Jae-yoon Hwang and Hyuk-jin Kwon. 2024. A Research on RC3(RMF-CMMC Common Compliance) meta-model development in preparation for Defense Cybersecurity. Journal of Internet Computing and Services, 25, 1, (2024), 123-136. DOI: 10.7472/jksii.2024.25.1.123.