As a small organization creating a security plan knowing where to begin can feel overwhelming. Especially when you must also protect the confidentiality of Controlled Unclassified Information within your cybersecurity program.

Do not open up NIST-SP-800-171a and begin at 3.1.1. If you begin by creating a System Security Plan you will fail. NIST-SP-800-171 can not serve as your cybersecurity framework. CMMC does not work as a cybersecurity program.

Instead begin by focusing on how you want to do business and start to mitigate the biggest risks to your business.

Auto-generated description: A table lists ten high-risk tasks related to inventory, tracking, security, and policy implementation for managing and protecting business assets, with milestones and ownership assigned to Me across various quarters and deadlines.

  • Inventory
  • Access Control
  • Backups

Start to write down how you will get things done. Basically you create a Standard Operating Procedure for doing your inventory or testing your backups.

Many people find the documentation requirements to meet NIST-SP-800-171 overwhelming. That happens when you try to put in a foundation after building the house.

Instead look at your SOPs as lego blocks that you will utilize to create a cybersecurity program

You stack these SOPs into your NIST-SP-800-171 plans that can align to NIST-SP-800-171.

Begin by creatign a baseline. What do you already do? It may not have enough meat on the bones to meet 171 requirements, but you have a place to begin. Then revise your SOP so it meets the requirements.

A quick an easy template to follow would include:

  • Purpose: Write one or two sentences explaining why this task is done.
  • Scope: State who should do the task and when to use the guide.
  • Tools / Resources: List the software, logins, or hardware required.
  • Steps: Write numbered actions using active verbs (like click, save, or open).
  • Definition of Success: Describe what the final correct result looks

You want a document you will find useful to getting things done.

Then as you build your Procedures you will have source materials for creating the Plans to ensure your cybersecurity program meets NIST-SP-800-171. Here your LLM or large language model, commonly referred to as artificial intelligence can help out immensely. When you have your lego pieces all collected ask your LLM to create a plan to stack them together.

It helps if you feed a policy to the LLM with your SOPs and ask for it to “Create an Identification and Authentication” plan that incorporates your SOPs while meeting the regulations set forth in a policy. I have always said having 14 policies that regurgitate your intent to meet specific control families does not serve a small business, but that did not account for LLMs. The policies provide the guardrails to ensure your plans stay in compliance when creating generative content.

Now start stacking your documentation and your CMMC journey will help you do business better.