SBIR-STTR Award

Model-Based Application of NIST Cybersecurity Standards
Award last edited on: 6/13/2022

Sponsored Program
SBIR
Awarding Agency
DOC : NIST
Total Award Amount
$500,000
Award Phase
2
Solicitation Topic Code
9.0
Principal Investigator
Richard Leboeuf

Company Information

WW Technology Group (AKA: WWTG)

4519 Mustering Drum
Ellicott City, MD 21042
   (410) 418-4353
   info@wwtechnology.com
   www.wwtechnology.com
Location: Single
Congr. District: 07
County: Howard

Phase I

Contract Number: 70NANB20H123
Start Date: 9/1/2020    Completed: 2/28/2021
Phase I year
2020
Phase I Amount
$100,000
The proposed innovation will use a model-based approach to streamline understanding and application of standards. NIST standards addressing cybersecurity, presented in the form of documents, spreadsheets, and database tools, provide thousands of complimentary and overlapping items for users to track. Significant effort is expended understanding the standards before attention can be focused on the system of interest. Model-based representations of both the standards and cyber-physical systems in a single tool will provide advantages over current costly and labor-intensive approaches. The tool will give stakeholders at all organizational levels access to the information specific to their domain, enable a better understanding of both the standards and the system, and be the basis for analyses and generation of certification artifacts. We will model NIST SP 800-53, NIST SP 800-53A, the NIST Cybersecurity Framework, NIST IR 8183, and the new Cybersecurity Maturity Model Certification (CMMC) standards and trace them to a cyber-physical system model. Analyses will be developed to automatically assess compliance gaps in the system relative to the standards. Stakeholder-specific reports with analysis results and recommendations will be generated automatically. The extensible tool will improve the efficiency of understanding and applying existing, evolving, and new NIST standards.

Phase II

Contract Number: 70NANB21H133
Start Date: 9/1/2021    Completed: 8/31/2023
Phase II year
2021
Phase II Amount
$400,000
The proposed innovation uses a model-based approach to streamline understanding and application of standards. NIST standards addressing cybersecurity, presented in the form of documents, spreadsheets, and database tools, provide thousands of complimentary and overlapping items for users to track. Significant effort is expended understanding the standards before attention can be focused on the system of interest. Model based representations of both the standards and cyber-physical systems in a single tool provide advantages over current costly and labor intensive approaches. The tool will give stakeholders at all organizational levels access to the information specific to their domain, enable a better understanding of both the standards and the system, and be the basis for analyses and generation of certification artifacts. We will model NIST SP 800-53, NIST SP 800-53A, the NIST Cybersecurity Framework, NIST IR 8183, and the new Cybersecurity Maturity Model Certification (CMMC) standards and trace them to a cyber-physical system model. Analyses will be developed to automatically assess compliance gaps in the system relative to the standards. Stakeholder-specific reports with analysis results and optimal recommendations will be