Often times for small businesses it feels as if NIST-SP-800-171 does not scale down and the government built an overlay, meant for large organizations, from NIST-SP-800-53 to protect the confidentiality of Controlled Unclassified Information

For example small and micro-businesses often struggle with vulnerability scanning. They get overwhelmed and this risk management family leads to a high number or organizations failing their CMMC assessments.

Vulnerability Scanning and Fully Remote Companies

A one-person company has limited time, personnel, and technical resources but must still ensure that all in-scope systems and applications are scanned for vulnerabilities. The owner wears all the hats.

This means they serve as the system administrator, security officer, and compliance manager. To meet NIST SP 800-171 requirement 3.11.2, the owner must do a ton of work.

First they must identify every device and application within the CUI environment and determine an appropriate scanning method for each. Then automated vulnerability-management software continuously assesses the company’s managed endpoint and installed applications, while any servers, printers, or network devices receive supplemental scans or documented firmware and vendor-advisory reviews.

The company must define a manageable scanning frequency, such as continuous automated assessment with a documented monthly review. The owner also monitors approved vulnerability sources and performs or confirms additional scans when a newly identified vulnerability may affect the environment.

They need to scan reports, make applicability determinations, and mantain remediation records. These must get retained in a controlled folder or ticketing system. This approach allows the company to demonstrate that systems and applications get scanned at the defined frequency and when new vulnerabilities are identified, without requiring a large security staff or an expensive enterprise platform.

That still seems like a heavy lift for a one person company, fully remote, with a single in-scope laptop, and they struggle. What NIST-SP-800-171 specifically asks for is:

3.11.2 Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.

  • 3.11.2[a] the frequency to scan for vulnerabilities in organizational systems and applications is defined.
  • 3.11.2[b] vulnerability scans are performed on organizational systems with the defined frequency.
  • 3.11.2[c] vulnerability scans are performed on applications with the defined frequency.
  • 3.11.2[d] vulnerability scans are performed on organizational systems when new vulnerabilities are identified. 3.11.2[e] vulnerability scans are performed on applications when new vulnerabilities are identified.

That seems overwhelming

Can I do It Alone?

Assuming a very small, fully remote company has only company-managed Windows endpoints, Microsoft 365 GCC High, Intune, no servers, no network printers, no custom applications, and Defender for Endpoint Plan 2, doing vulnerability management internally is practical.

Defender automates discovery and scanning, but the company must still operate and document the vulnerability-management process. Microsoft confirms that Plan 2 includes continuous monitoring, vulnerability and configuration assessment, software inventory, prioritization, and remediation tracking.

What Must I do

What the company must do itself can seem daunting, but with Defender P2 add on and Defender Vulnerability Management add-on you can manage vulnerability scans.

Define the scope

Maintain an inventory of every in-scope endpoint and application. Reconcile it against Defender’s device and software inventories monthly. Investigate missing, inactive, or improperly onboarded devices.

Once you introduce printers, custom applications, or servers vulnerability scanning gets much more burdensome and a 1-3 person company should rely on farming out the work to a third party.

Define the scanning frequency

A reasonable procedure could state:

Defender Vulnerability Management continuously assesses enrolled endpoints and supported installed applications. The Security Administrator formally reviews results monthly. Additional applicability reviews and reassessments are performed when newly identified vulnerabilities may affect organizational systems or applications.

This addresses the frequency element of 3.11.2[a]. The company should avoid saying only “Defender scans continuously” without defining the formal review and new-vulnerability process. So beyond verifify Defender operates you must:

At least monthly, confirm:

  • Every in-scope endpoint is onboarded.
  • Devices are actively reporting.
  • Defender sensors are healthy.
  • Vulnerability intelligence is updating.
  • No endpoint has disappeared from reporting.
  • Software inventory corresponds to approved applications.
  • Intune and Defender integration remains enabled.
  • Review and prioritize findings

The owner must review:

  • Critical and high-severity vulnerabilities.
  • Vulnerabilities with known exploits.
  • CISA Known Exploited Vulnerabilities.
  • Vulnerabilities affecting CUI endpoints.
  • Unsupported or end-of-life software.
  • Findings that have remained open beyond the company’s remediation target.

While NIST-SP-800-171 doe snot requite The CISA KEV Catalog, it provides an appropriate prioritization source.

Address application-coverage gaps

Defender identifies vulnerabilities in supported installed applications, but not every detected application is necessarily vulnerability-assessed. Microsoft explains that software without a supported CPE may appear in inventory without vulnerability information. Microsoft software inventory documentation.

For unsupported applications, the company must do one of the following:

Monitor new vulnerabilities

Defender continuously receives vulnerability intelligence, but the company should document how it responds to important new vulnerabilities. A lightweight process means you:

  • Subscribe to CISA KEV and relevant Microsoft notifications.
  • Determine whether the affected product and version exist.
  • Confirm Defender has reassessed the affected endpoints or perform a supplemental version check.
  • Record whether the vulnerability is applicable.
  • Create a remediation record when applicable.
  • Remediate and verify

Scanning alone does not satisfy 3.11.3. The company must patch, upgrade, uninstall, mitigate, or formally manage each material finding based on risk.

Defender findings can be converted into remediation activities and Intune security tasks, although creating a remediation request does not itself install the fix.

Retain evidence

You must also aave a monthly evidence package containing:

  • Current device inventory.
  • Vulnerable-devices or vulnerability export.
  • Security recommendations.
  • Open and completed remediation activities.
  • Newly identified vulnerability reviews.
  • Exceptions and false-positive determinations.
  • Evidence that remediated findings cleared.
  • Monthly review record identifying the reviewer and date.

Defender’s vulnerable-device report can show historical trends, but organizations should export and retain their own assessment evidence

Is Outsourcing Cheaper?

If you do not have the skills to correctly set up and maintain Defender does the question really matter? Still you can do a cost benefit analysis

Owner’s effective hourly value Internal cost at 4–6 hours/month
$75/hour $300–$450
$100/hour $400–$600
$150/hour $600–$900

Outsourcing becomes attractive to a fully remote 1-3 person shop when:

  • The owner lacks Defender or vulnerability-analysis experience.
  • Monthly reviews get missed.
  • The provider produces assessor-ready evidence.
  • The service includes remediation assistance
  • Billable hours surpass the cost of farming out work

Outsourcing does not eliminate company effort. The owner must still approve disruptive changes, accept risks, verify the provider’s work, and ensure all assets and applications are covered.

For CMMC, a provider accessing Defender data or performing security functions may process Security Protection Data and become an External Service Provider within the assessment scope. The relationship, services, and responsibilities must then be documented in the SSP, service description, and customer responsibility matrix. 32 CFR § 170.19.

A one-person company should rely on a hybrid solution for best value. The owner performs the monthly Defender review and routine remediation, while a qualified provider conducts a quarterly review and is available for significant vulnerabilities. This keeps recurring costs lower while providing independent technical support and stronger assessment evidence

For a fully remote Windows company, Microsoft Defender for Endpoint Plan 2 provides an adequate vulnerability-scanning platform because its endpoint agent assesses laptops wherever they have internet access. The company can then outsource operation of the Microsoft vulnerability-management process to an MSP or MSSP

What to outsource

The strongest arrangement would require the provider to:

  • Confirm weekly that all in-scope endpoints are active and reporting.
  • Review critical, high, exploitable, and CISA KEV vulnerabilities.
  • Review newly identified system and application vulnerabilities within a defined period, such as one business day for critical notices.
  • Determine whether affected products and versions exist.
  • Create and track Defender or Intune remediation tasks.
  • Identify software that Defender inventories but cannot vulnerability-assess.
  • Review vendor advisories for unsupported software.
  • Verify that updates or mitigations cleared the findings.
  • Maintain false-positive, exception, and risk-acceptance records.
  • Produce a monthly vulnerability-management package.
  • Notify the owner immediately when remediation requires downtime, application removal, licensing, or risk acceptance.
Service model Owner effort in a normal month
Provider only reviews and reports; owner remediates 2–4 hours
Provider triages, creates tasks, tracks remediation, and prepares evidence 1–2 hours
Provider also administers Intune remediation 0.5–1.5 hours

If you do not know how Microsoft Defender works, or your billable hours surpass the cost of spending six hours a month on scanning you should outsource. If you have the skills, or willing to learn, a hybrid approach provides the lowest price point.

“You will never walk alone…” flickr photo by Thomas Leuthard flickr.com/photos/th… shared under a Creative Commons (BY 2.0) license