Certified CMMC Assessors click into place as just another cog in a much larger system that already exists. Every objective that a CCA examines must already be legally met by Organization Seeking Certification. CMMC introduced no new requirements on Federal contractors. When …
How To CMMC
-
-
Developing a Rubric to Assess Policies and Procedures for CMMC Compliance
People panic when it comes to policy and procedures and CMMC. Rightfully so. Compliance with NIST-SP-800-171 at a miminum requires fourteen different policies and fourteen different procedures. Probably More. In fact NIST recommends 39 different plans, policies, and procedures …
-
Can you Engineer Culture in your Systems?
As we try to create online communities focused on open learning we have to recognize the troubled history open source has had with diversity, equity, and inclusion. Some bias is implicit due to systematic discrimination. You need to be well off to work for free. Often though we …
-
Guide to Microsoft's Security and Compliance Rebranding
Many people might stare with wide eye confusion at the naming conventions Microsoft has used in rebranding. Some of the services used in the government and by government contractors have a new moniker. Yet when you think about the changes the logic makes sense in terms of keeping …
-
CCMC: Asset Categorization and Systems Security Engineering
Systems security engineering, establishing security by considering the problem, solution, and trustworthiness of all key components in a business, begins with stakeholder interest and the business outcomes. A business that cannot turn a profit cannot remain a business for long. …
-
CMMC: Systems Security Engineering and the Cloud
In systems security engineering requirements and constraints drive the design choices we make. They will send signals in a CMMC assessment. The constraints and requirements of an environment determines the type of evidence an assessor needs to verify. Organizations Seeking …
-
CMMC Assessment: In Systems Security Engineering the Environment Drives Evidence
From A Systems Security Engineering perspective, the environment will drive the evidence collected to ensure an organization seeking certification meets security requirements. For both the assessor and the contractor considering the impact of scope on how their systems gets …
-
CMMC, Asset Inventory, and Systems Security Engineering
table, th, td { border: 1px solid; } You cannot protect what you do not know you have. Systems security engineering, as a method to meet the security requirements of CMMC requires an Organization Seeking Certification (OSC) to provide the means to locate, identify, and log the …
-
System Security Engineering and CMMC
Every organization has a philosophy behind their system security plan. These may range from an idea that, “Compliance is not security,” to “DFARS is an unfunded mandate, “ or ” “CMMC did this to me.” Other organizations may have their SSP reviewed on a quarterly timeline, and …
-
Evaluating Organizations Seeking Certifcation: Document Based Requirements to Start a Conversation
You do not jump out of a plane without first making sure a parachute works. Yet many Organization Seeking Certification (OSC) want to make a leap of bling faith about their compliance to the practices in the Cybersecurity Maturity Model Certification. When an Organization Seeking …
-
CMMC and Asset Inventory
Asset Inventory will drive your compliance. Whether you rely on the shared responsibility of zero trust models or protect information at your boundaries, asset inventory drives your security. When determining the cost of both compliance and security asset inventory drives your …
-
How to Use the CMMC Level One Assessment Guide
Under the Cybersecurity Maturity Model Certification Program a level company who holds federal contract information must complete a self-assessment “with an accompanying senior company official affirmation” every year. Introduction to CMMC Level One CMMC Level One …
-
CMMC Assessment Procedures: When Is Enough Data Enough?
What Data Are In Scope? You are assessing against the 171 standard using the CMMC framework. While practices require data to be separated from authorized and unauthorized users and other controls require compliance with federal regulations you assess against the assessment …
-
Categorizing In-Scope FCI Assets using a CMMC Level One Self-Questionnaire
CMMC 2.0 did not change much for level one beyond moving to a self-assessment model rather than relying on a third party assessor. In fact many companies will end up hiring a Certified CMMC Professional to conduct their self-assessment. Level one, under the Cybersecurity Maturity …
-
Asset Categorization and CMMC
Many Certified CMMC Professional (CCP)will find the Configuration Management domain one of the trickiest for organization seeking certification to implement. Yet you have to ensure all employess have secure equipment from the starting line. By spelling out clear rules of the road …
-
Overview of CMMC 2.0
Ben Franklin once quipped, ““When you are finished changing, you are finished.” Nothing could ring more true in cybersecurity. Frameworks need to live and breath to respond to evolving threats. On November 4, 2021 the Department of Defense unveiled an update to the the …
-
No CMMC Hot Takes. Just Take the Time for Some Slow Reads
Inbox overflowing with email invitations to CMMC.20 webinars? Every consultant and software service promising to give you the most up to date info your company can not do without? You can do without. I offer no hot takes. Just some slow reads. If you really want to get prepared …
-
Cybersecurity: Did Bootcamps Break Us or Save Us
The cybersecurity awareness and training industry tops a billion dollars in revenue and will only grow as regulatory frameworks that require companywide learning programs spread. At the same time and given Higher Education’s inability to adapt or keep up in digital fields, …
-
We want to transform CyberSecurity Awareness and Training into an active learning process. For far too long we have assumed video-based quizzes work at the minimum and real training cannot happen because you need decades of experience to do Cyber.
Neither assumption rings true. Active learning leads to greater transfer and retention. This production-based method, where learners must do stuff with what they learn begins with questioning.
In my time working on Cybersecurity Maturity Model Certification courses, I have reviewed so much curriculum. Coched Provisional Instructors as they develop lesson plans and provided feedback to our instructors as we iterate on curriculum at Southern Connecticut State University.
Stop Asking Any Questions
Almost all the instruction I observe relies on direct intruction with little learner interaction. I see it in video based training and lectures where a highly talented Subject Matter Expers asks, “Any Questions” at the end of each segment or lecture.
Everyone has questions. No one will ask.
Instead a good teacher uses questions to elicit evidence of and scaffold knowledge growth. You can think of three types
- Literal
- Inferential
- Evaluative
Literal questions get answered with explicit, which means identifiable in the text, details. Inferential questions require students to combine information in a text, either explicitly or implied, and combine this with prior knowledge or another source. Evaluative questions ask you to combine implicit information with an opinion and may focus on why and how to fill is missing details.
As an instructor you need to plan your questioning well. You can use verbs from Bloom’s Taxonomy or Webb’s Depth of Knowledge, but you need to ask questions for learning to occur.
Helping Out CMMC Instructors
So, to help out the Instructors who utilize the CMMC curriculum we write we started to create a question guide for each of the 17 Domains. It includes a definition from NIST SP-800-162 and questions a Certified CMMC Professional can use to help an Organization Seeking Certification. We derive these from 162 as well.
We then include every assessment objective. CMMC courses mean nothing without Assessment Objectives. Next, we close with sample discussion questions. We hope these focus on pain points and common misconceptions. When an LTP or Provisional Instructor uses our material, you can know we provide you the tools to have active discussions,
Check out our Access Control Example
Featured Image “Question” by kevin dooley is licensed under CC BY
-
You are Doing Cyberscecurity Awareness and Training Wrong
Let me tell you how most of my pitch calls go when someone needs instructional design work for their company’s cybersecurity awareness and training. The customer typically says something along the lines of, “We just need a quick and dirty training, to check off the …
-
The Basics of Controlled Unclassified Information
When you cut through the marketing hype—and ignore all of the LinkedIn trolls predicting the doom of the Cybersecurity Maturity Model Certification (CMMC) program— you realize CMMC did not arise out of the blue. When you reasearch its history, you will find nothing especially new …
-
CMMC and Ethics
At a recent Town Hall, the Cybersecurity Maturity Model Certification Accreditation Board (CMMC-AB) CEO Matt Travis noted that "trust and confidence in the CMMC Ecosystem" is the shared responsibility of both the AB and the members of the community. In fact, Travis's call to …
-
CyberSecurity Begins with Awareness and Training
It always comes down to the humans. Even with the best security, the tiniest friction can cause all systems fail. That 2% of DNA separating us from chimpanzees really messes with your cyber hygiene. If you want security you need to focus on the biggest attack vector: people. The …
-
How do you use the Discussion Section of the CMMC Assessment Guides?
Great post from Alex Johnson on the difference between the discussion and requirements of CMMC practices. “I want to offer some information to those who may be struggling with understanding what options are available to you regarding the implementation of NIST SP 800-171 …
-
Inventory Matters
Inventory matters. As Sarah Spencer CEO of SolonTek notes, “You cannot protect what you cannot see.” “dandoodlescan065-inventory is waste” by Inha Leex Hale is licensed under CC BY Now, some people read the CMMC assessment guide for Level One and think, …
-
Prequisites for a DIBCAC CMMC Assessment
While we await the release of the CMMC assessment process from the AB, we can look to how the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) conducted Level Three assessments of Certified Third Party Assessment Organizations (C3PAO) to understand their …
-
How Long Does a CMMC Assessment Take?
I don’t know. You don’t know. Nobody knows. The scoping and final methodology guides have yet to hit the press as we await approval from the Department of Defense. Until then we guess, but with observable evidence in mind. The Defense Industrial Base Cybersecurity …
-
Controlled Unclassified Information Glossary
Need a Controlled Unclassified Information cheat cheet? Getting an acronym induced migraine? Look no further for relief than this handy-dandy CUI Glossary ripped, remixed, and reused verbatim from the Code of Federal Regulations. dictionary focus flickr photo by Cubosh shared …
-
Where do I Begin My CMMC Journey?
Stop looking for the easy button. Hang up on those who say, “Turn Key” Then get started, you may have more done than you think. Do not go to page one of the CMMC Assessment Guide Level Three and open up to page 10 and start with Access Control (AC.) 1.00.1 Limit …
-
Who took the Cake Marked CUI from the Fridge? CMMC and Data Ownership
We have all seen or felt the rage. You go into fridge to grab the gooey cooey chocolate volcano cake you labeled in the fridge and the shelf laughs back at you with an eerily empty cackle. Someone did not know who owned the cake. flickr photo by carolinerac shared under a …
-
What Practices and Assessment Objectives from CMMC apply to CUI?
Sometimes to get a job done you just need Data. In the Cybersecurity Maturity Model Certification program, with five levels of cyber hygeine, almost all the Domains, practicies, and assessment objectives implicity require you to follow the regulations for the authorized handling …
-
CMMC Process Assessments: Get better at Doing Business
Getting lost in the different requirements of the Cybersecurity Maturity Model Certification? Pull back the sheets and realize much of what we mean withe practices and processes revolve around doing business better. You do practices in cybersecurity. Verbs. Controls. Compliance. …
-
Is My Outsourced IT Provider in CMMC Scope?
Let’s ask the Department of Defense "Q7: Our Company has outsourced its IT support and systems to a third-party contractor. Are we still responsible for complying with DFARS clause 252.204-7012 and implementing NIST SP 800-171?” A7: Outsourcing your IT to another company …
-
What is Scope? A Jargon Free Explanation
Our current definition of Scope comes from 16th century mid Europe when the firearm spread across the continent. Scopo, aim in Italian, derived from the Greek word skopos for target. Skopos roots lie in the word Skeptesthai ‘look out.’ In terms of Cybersecurity Maturity Model …
-
Does CMMC apply to my company?
In the Defense contracting world we speak of primes, those who sign the contracts, and subs, subcontractors who get work on a prime contract. As you move up the supply chain everyone acts as both a prime and sub on various contracts. If you follow the Defense supply chain all the …
-
Three Goals of the Cybersecurity Maturity Model Certification Program
Yesterday the Office of the Under Secretary of Defense for Acquisition & Sustainment helped put their goals of Cybersecurity Maturity Model Ceritification (CMMC) in focus. In fact Jesse Salazar, Deputy Assistant Secretary of Defense for Industiral Policy, on the goals of the …
-
CMMC and the Customer Responsbility Matrix
Defense Contract Management Agency says all customer responsibility matrices must be complete prior to the start of their CMMC assessments. Yet only half the people know much about them. Why? Risk Management Framework If you come from a Risk Management Framework as traceability …
-
What is CMMC?
In 2019 the Department of Defense announced the creation of the Cybersecurity Maturity Model Certification (CMMC) to replace the self reporting of cyber hygiene which used to govern the DIB. The CMMC puts an end to self-assessment, and requires a third party assessor to verify …
-
Future of Cyberesecurity: CMMC and the DFARS Interim Rule
This post is co-written by Terry Lehman Nation Under Attack As American combat pilots scream across the sky flying an F-35, the finest fighter jet in the world, they may have to engage a Chinese cousin, the J-20. The NSA reported sophisticated cyber security attacks allowed the …