{
  "version": "https://jsonfeed.org/version/1",
  "title": "How To CMMC on J. Gregory McVerry",
  "icon": "https://cdn.micro.blog/DoctorMac/avatar.jpg",
  "home_page_url": "https://www.drmacscybersecuritybrief.com/",
  "feed_url": "https://www.drmacscybersecuritybrief.com/feed.json",
  "items": [
      {
        "id": "http://doctormac.micro.blog/2022/11/28/certified-cmmc-assessor.html",
        "title": "Certified CMMC Assessor: Spinning the Wheels of Trust in Much Bigger Systems",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2022/4cf58d7db4.jpg\" width=\"400\" height=\"600\" alt=\"\">\n<p>Certified CMMC Assessors click into place as just another cog in a much larger system that already exists.</p>\n<p>Every objective that a CCA examines must already be legally met by Organization Seeking Certification. CMMC introduced no new requirements on Federal contractors. When people often complain about the cost of CMMC they do not mean the actual assessment but refer more to meeting the requirements a CMMC assessment measures.</p>\n<p>After the continued exfiltration of data and failed self assessments A third party validation of the system security plan was added to increase the trustworthiness of systems designed to process, store, and transmit Controlled Unclassified Information.</p>\n<p>According to NIST  a system is a series of elements or components that together have a shared identity working towards a goal within the constraints of a specific environment and the requirements of the outcome.</p>\n<p>Organization Seeking Certification engineer security in their systems through systems security engineering. Originally the Government placed trust in organizations seeking certification. However recent evidence calls into doubt the trustworthiness of self reporting. The lack of trust in System Security Plans in turns cast doubt on the trustworthiness of the overall security engineered into a system.</p>\n<p>So through CMMC a third party assessment was added to assess trustworthiness and increase trust in the supply chain.</p>\n<h2 id=\"trust-and-trustworthiness\">Trust and Trustworthiness</h2>\n<p>A CCA serves as the verification and validation method to assure with confidence that federal contractors protect the confidentiality of Controlled Unclassified Information. A CCA verifies the trustworthiness of the evidence an organization seeking certification includes in their System Security Plan. You validate that their tests to ensure the trustworthiness of their systems proves the Organization Seeking Certification</p>\n<p>Trust is a belief that an entity meets certain expectations and can\nbe relied upon. The terms belief and can imply that trust may be granted to an entity whether the entity is trustworthy or not. A trustworthy entity is one for which sufficient evidence exists to its claimed trustworthiness.</p>\n<h2 id=\"verification-and-validation-of-the-system-security-plan\">Verification and Validation of the System Security Plan</h2>\n<p>As a Certified CMMC Assessor you verify and validate that an Organization Seeking Certification meets the security requirements of NIST-SP-800-171. In order for a System Security Plan to be trustworthy the OSC must have a  demonstrated ability to satisfy expectations of protecting Controlled Unclassified Information</p>\n<p>Since trustworthiness is something demonstrated, you verify and validate the evidence that supports a claim or judgment of the CMMC practices being met.</p>\n<p>As a Certified CMMC Assessor you also serve  a dual role of trust. As a trained assessor the Government can put trust in your assessment. As a Certified assessor the Organization Seeking Certification can trust your credentials. Trust is value judgment based on authority and evidence.</p>\n<p>In terms of Cybersecurity Maturity Model Certification program this means you examine the SSP and validate each CMMC practice to ensure there is sufficient evidence of trustworthiness in the claims being made by the Organization Seeking Certification.</p>\n<p>A CCA validates the trustworthiness of each claim  an Organization Seeking Certification makes about meeting the security requirements assessment of NIST-SP-800-171 to protect the confidentiality of Controlled Unclassified Information.</p>\n<p>This means the verification and validation of each assessment objective. As an assessor you have to make sure the evidence is sufficient and adequate enough to ensure that each of the 110 security requirements has enough depth and breadth that the claims made in the System Security Plan can be trusted.</p>\n<p>Your role in the system is to increase the assurance that the Nation’s controlled Unclassified Information gets protected. According to NIST,</p>\n<p>Assurance is a complex and multi-dimensional property of the system that builds over time. Assurance must be planned, established, and maintained in alignment with the system throughout the system life cycle.</p>\n<p>In your roles of dual trust as a CCA you help to build assurances in the overall supply chain system. You also verify  the evidence an OSC includes in a System Security Plan and validate how an organization establishes the trustworthiness of these claims in the trustworthy context.</p>\n<h2 id=\"trustworthy-context\">Trustworthy Context</h2>\n<p>The trustworthiness context  involves decision making and evidence based demonstrations that a system security plan can be trusted to protect the confidentiality of Controlled Unclassified Information. The Organization documents how they develop and maintain their assurances of meeting the security requirements of NIST-SP-800-171 and how they demonstrate how the assurance is satisfied. A CMMC Certified Assessor verifies and validates the System Security Plan as a  decision-making context.</p>\n<p>When the Organization Seeking Certification writes how they meet the security requirements of each NIST-SP-800-171 objective they create an assurance case. This demonstrates how they cover the objective with enough depth and breadth to ensure we can trust the assurance case.</p>\n<p>As a CCA you will verify and validate the evidence in System Security Plans with a variety of quality. An effective SSP  acts as an assurance case playbook. First a claim is derived from from security objectives Then the OSC connects to and documents credible and relevant evidence that substantiates the claims. Often the evidence get validated through ongoing testing and good system development life cycle practices. Basically Say What you do, explain how you do it, and prove it gets done. Have an assurance case for every assessment objective.</p>\n<p>Organizations with strong cyber hygiene present a compelling assurance case for all 325 objectives in NIST-SP-800-171.The result provide a statement that adequate security has been achieved and driven by stakeholder needs and expectations. Strong Systems Security Engineering helps to strengthen security and reduce the effort on validating and verifying assurance cases.</p>\n",
        "date_published": "2022-11-28T13:14:28-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2022/11/28/certified-cmmc-assessor.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://doctormac.micro.blog/2022/07/19/developing-a-rubric.html",
        "title": "Developing a Rubric to Assess Policies and Procedures for CMMC Compliance",
        "content_html": "<p>People panic when it comes to policy and procedures and CMMC. Rightfully so. Compliance with NIST-SP-800-171 at a miminum requires fourteen different policies and fourteen different procedures. Probably More. In fact NIST recommends 39 different plans, policies, and procedures for 171 compliance.</p>\n<p>While policy and procedures are not explicitly assessed by CMMC practices a majority of assessment artifacts imply the need for policy and procedures through explicit mention of document based specifications.</p>\n<p>Yet few people write policy and procedures. Even less do it well.</p>\n<p>To help you in creating compliant policy I have developed a series of &ldquo;self-assessment&rdquo; checklists for each Domain of CMMC.</p>\n<h2 id=\"why-policy\">Why Policy</h2>\n<p>Policy defines the governance of the systems you engineer to protect the confidentiality of Controlled Unclassified Information. Let us examine configuration management.</p>\n<p>Overall configuration management policy communicate senior management’s expectations to the company. A good policy, regardless of domain must have specific, measurable, and confirmable\nobjectives. Policies providea top-down approach to  define what is required and what is not permitted with configuration management.</p>\n<p>While policy defines the objectives for what must get done, procedures describe how the policy\nobjectives get met through specific actions and results. Configuration Management procedures\ndescribe the methodology and tasks for each activity that supports implementation of Configuration Management policy.</p>\n<p>As a company meeting CMMC requirements you should document your configuration management policy and procedures  during your planning phase. In fact NIST-SP-800-171 requires you to regulary review all policies and procuedres.</p>\n<h3 id=\"what-makes-a-good-congifuration-management-policy\">What makes a Good Congifuration Management Policy</h3>\n<p>You can not check CMMC Assessment guides for help with writing configuration managment. You will not find your answers in NIST-SP-800-171, but 171 will tell you where to look,</p>\n<p>In the back of NIST-SP-800-171 you will find Appendix E. This lists all the security controls the government assumes you do or controls they assume only apply to the federal government. These controls came from NIST-SP-800-53.</p>\n<p>The very first base control of every family in NIST-SP-800-53 is policy and procedures. If you look at NIST-SP-800-53a you can find a list of requirements for compliant policy. This provides a wonderful tool for you to assess your current policy.</p>\n<p>As a tool however it is hard to read.</p>\n<h3 id=\"why-a--configuration-management-policy-rubric\">Why A  Configuration Management Policy Rubric</h3>\n<p>Self-assessment works in improving technical writing skills. We know from decades of research that theese metacognitive, or thinking about thinking, guides help to improve outcomes.</p>\n<p>To design these rubrics I went through the objectives of each Policy and Procudure for each Family in NIST-SP-800-53. This information is required but not assessed for NIST-SP-800-171 nor assessed for CMMC but required evidence for a CMMC assessment.</p>\n<h4 id=\"organization-defined-parameters\">Organization Defined Parameters</h4>\n<p>In order to be technology agnostic and provide a more holisitic approach NIST rarely defines rules around roles, events, and freqencies. Instead your policy and procedures must have clear organization defined parameters that get enforced in policy and procudures</p>\n<p>In NIST-SP-800-53a these ODPs get explicitly defined and displayed in a table with the requirements but off set with grey shading. These requirements are just NFOd in NIST-SP-800-171.</p>\n<p>The Requirements in NIST-SP-800-53a  then spell out what should go into each policy</p>\n<img src=\"https://cdn.uploads.micro.blog/29546/2022/9fcdc043eb.png\" width=\"600\" height=\"757\" alt=\"screenshot of first page of CM1 in NIST-SP-800-53\" />\n<p>I tried to take this information and turn it into a checklist a company can use to evaluate their configuration management policy.</p>\n<p><a href=\"https://jgregorymcverry.com/Configuration_Management_Rubric.xlsx\">Check it out the checklist</a></p>\n",
        "date_published": "2022-07-19T18:24:11-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2022/07/19/developing-a-rubric.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://doctormac.micro.blog/2022/07/11/can-you-engineer.html",
        "title": "Can you Engineer Culture in your Systems?",
        "content_html": "<p>As we try to create online communities focused on open learning we have to recognize the troubled history open source has had with diversity, equity, and inclusion. Some bias is implicit due to systematic discrimination. You need to be well off to work for free.</p>\n<p>Often though we have seen countless explicit attacks such as Gamergate or even death threats against those doing Open Source Intelligence work to fight right wing extremism online.Before you can even begin to create an online community focused on open learning you need trust.</p>\n<p>For many we never engineered safety into the online communities we create and curate.\nSystems Security Engineering Approach to Culture</p>\n<p>Creating a Community as Your Curriculum (Cormier, 2008) takes a systems approach to engineering trustworthiness into the spaces you design. You can also think about your classroom culture, and the overall culture of your school as a system. in fact, our educational system is nested within this much larger system that many parents and students do not rightfully trust. By choosing a framework to develop an innovate and healthy online community you in turn reduce the threats to the members of your group that will do the learning work You also help build a better world.</p>\n<p>&lt;img src=&ldquo;<a href=\"https://longthoughts.jgregorymcverry.com/lib/exe/fetch.php?w=400&amp;tok=eba82c&amp;media=screen_shot_2022-07-06_at_12.12.00_pm.png\">https://longthoughts.jgregorymcverry.com/lib/exe/fetch.php?w=400&amp;tok=eba82c&amp;media=screen_shot_2022-07-06_at_12.12.00_pm.png</a> width=&ldquo;60%&quot;&gt;</p>\n<p>Once a framework is chosen systems engineering requires a set of iterative steps.</p>\n<pre><code>Collect baseline data\r\nIdentify goal you will engineer\r\nAcknowledge and identify blockers and variables of interest\r\nDevelop a solution to address the goal without negatively impacting other systems\r\nMonitor the progress. Evaluate variable of interest.\r\nIterate on the process\r\n</code></pre>\n<p>When engineering for community we have to everyone recognize the cultural importance of safety. When trying to increase the overall hygiene of online communities you curate ,and thus engineer better trust in your system, you must first focus on the trust of potential and existing community members</p>\n<p>Dr. Kimberly Young-McLear, who won the 2017 Captain Niels P. Thomsen Innovation Award Winner for “Cultural Change for leveraging social media for large-scale disaster response.: has created the framework for a healthy and innovative workplace.\nPsychological Safety</p>\n<p>Psychological safety is paramount to good community culture. Dr, Young-McLear defines psychological safety as, “a service culture where all members have the confidence to serve as their authentic selves where self-knowledge, initiative, creativity, and self-empowerment are rewarded in an environment of interpersonal risk-taking.”</p>\n<p>The Internet has not always been a welcoming place as demonstrated in current news stories about harassment and stalking. Unrepresented populations need to feel safe in your community no matter their role. Online spaces improve when systematically marginalized groups of people share their perspectives and contribute to organizational solutions without fear of marginalization, retaliation, bullying, or discrimination. This can not happen without psychological safety.</p>\n<p>The model Dr. Young-McLear created integrates survivors of sexual assault, harassment, and racism. Marginalized groups are often ignored or for reporting incidents of abuse. The Web reflects our reality. The internet has never been a safe place for all. We must all work to create a places, online and in person where everyone feels safe and valued. This will increase the trustworthiness you engineer into your online community.\nMoral Courage</p>\n<p>Engineering an innovative and healthy environment also requires moral courage. This means all community members must feel compelled toward action to intervene against any culture or practice that inhibits the safety of any of our members. member of your organization must report violations of laws, policies, or your company&rsquo;s mission, vision, and core values. Talk to potential members who have faced racism and discrimination in the past. Encourage a speak up culture.\nCultural Competencies</p>\n<p>As you engineer an innovative and healthy workspace focus on growing key cultural competencies in your online communities</p>\n<pre><code>Valuing diversity\r\nHaving the capacity for cultural self-assessment\r\nBeing conscious of the dynamics inherent when cultures interact\r\nHaving institutionalized cultural knowledge\r\nHaving developed adaptations to service delivery reflecting an understanding of cultural diversity\r\n</code></pre>\n<p>Developing cultural competence systematically within a workforce requires subject-matter expertise and involvement by systemically marginalized groups. Over time as you grow your community may need to rely on experts in race, gender, gender identity, sexual orientation, religion, ethnicity, education, and ob position. In terms of addressing the systemically marginalized in online learning can look at the language used, the discourse patterns of leaders, and do recruitment outside of 24 hackathon events\nInclusion</p>\n<p>According to Dr. Young-McLear inclusion is “individuals perceiving acceptance within the organization, as well as the ability to bring unique contributions to the workplace. Once your organizers have done the hard work of building psychological safety, moral courage, and cultural competencies feelings of inclusion will increase.</p>\n<p>We need more voices in for our online environments to thrive. We need communities explicitly inclusive to those who have faced trauma. Inclusion helps with both recruitment and retention. More importantly it makes your company safer. Research has shown diverse teams make better decisions.\nDiversity and Equity</p>\n<p>Diversity and equity share traits but have different impacts on the learning spaces you design. Diversity in the workplace means workers who are different from each other or come from different backgrounds. Diversity can involve constructs such as race, gender, age, etc. You need to think in terms of cultural, physical, and cognitive diversity.</p>\n<p>Only when your online spaces invest in diversity and equity can we hope to improve efforts to recruit, retain and members from systematically marginalized groups into technology. Diversity work often involves doing personal work more than outreach. Do not ask marginalized communities to put in extra effort to help you overcome their oppression.\nMission Readiness and Innovation</p>\n<p>Once the foundation of psychological safety, moral courage, cultural competence, and diversity and equity get engineered into your systems the overall mission readiness of your online space may improve. Then innovation will follow. No matter the focus of your online community when people feel safe and there is a healthy exchange of free ideas innovation thrives.</p>\n",
        "date_published": "2022-07-11T09:43:33-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2022/07/11/can-you-engineer.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2022/05/11/guide-to-microsoft.html",
        "title": "Guide to Microsoft's Security and Compliance Rebranding",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2022/8f5ae1f72d.jpg\" width=\"600\" height=\"450\" alt=\"\" />\n<p>Many people might stare with wide eye confusion at the naming conventions Microsoft has used in rebranding. Some of the  services used in the government and by government contractors have a new moniker.</p>\n<p>Yet when you think about the changes the logic makes sense in terms of keeping compliance and security engines purring.</p>\n<p>Microsoft has a long established partnership with the Cybersecurity Maturity Model Certification community.</p>\n<p>In fact for the last five years, going back to when the System Security Plans (SSP) did not have their trustworthiness verified by a third party,  the Seattle based company has retooled much of their information architecture to help the Government transition to the cloud and away from on-premises and boundary based protections.</p>\n<p>Microsoft has also created new tools to help with security and compliance. These efforts have lead to a rebranding of services companies will use for CMMC. Microsoft wanted to make a distinction between services for security and those for compliance.</p>\n<p>When you consider the Risk Management Framework (NIST-SP-800-37 and 39) that form the backbone of the 171 security requirements we think about a business at three levels:</p>\n<ul>\n<li>Level One: Governance and Organization</li>\n<li>Level Two: Business Processes</li>\n<li>Level Three: Technical and Business Systems</li>\n</ul>\n<p>At each of the three level different assets, which include people, will have privileged and non-privileged roles. This means a user can access something at a specific tier other users can not access.</p>\n<p>In terms of the IA (information architecture) a company deploys they need to consider the Microsoft tools they choose for compliance and those they choose for security.</p>\n<h2 id=\"microsoft-azure-and-microsoft-365\">Microsoft Azure and Microsoft 365</h2>\n<p>The compliance and security services that Microsoft offers will cut across two different  cloud platforms that people often confuse, Microsoft Azure and Microsoft 365. They each have different security and compliance needs and impact what controls a customer inherits from Microsoft or more like a Managed Service Provider. Microsoft 365 is a Service as a Software cloud (SaaS). This means all of your tools like Microsoft Office, Microsoft PowerPoint, and Visio. An organization seeking certification has limited responsibility with SaaS tools. You need to control access and training but Microsoft handles almost all the other security requirements.</p>\n<p>Microsoft Azure is more an Infrastructure as a Service (IaaS) or Platform as a Service (PaaS) depending on how an organization seeking certification deploys the service. Usually with IaaS a company does not control all their hardware or need to purchase the hardware. PaaS get used when you establish hybrid environments or create an enclave, for Controlled Unclassified Information, for example.</p>\n<p>Azure also gets used when Managed Service Providers, or security providers build apps in the cloud. For the end user the tool is a SaaS cloud model , outside of Microsoft, but for the company designing the tool they use Azure as a PaaS.</p>\n<p>As Microsoft focused on improving their services for CMMC they identified assets in both Microsoft 365 and Azure that an organization may use for security and those tools that will get used for compliance. These tools were rebranded and sorted into two different buckets.</p>\n<h2 id=\"security-and-compliance\">Security and Compliance</h2>\n<p>When  working on services that provide security to a Microsoft cloud deployment companies will work with the Microsoft 365 Defender portal. As part of a cloud first approach Microsoft has stopped the level of bifurcation between branding of their services. <strong>Azure Security Center is now Microsoft Defender for Cloud</strong> and <strong>Microsoft 365 Security Center is now Microsoft 365 Defender</strong></p>\n<p>When working on services that provide governance, risk management, compliance (GRC)services, a cloud user will access the  Microsoft Purview Compliance portal.</p>\n<style type=\"text/css\">\n.tg  {border-collapse:collapse;border-spacing:0;}\n.tg td{border-color:black;border-style:solid;border-width:1px;font-family:Arial, sans-serif;font-size:14px;\n  overflow:hidden;padding:10px 5px;word-break:normal;}\n.tg th{border-color:black;border-style:solid;border-width:1px;font-family:Arial, sans-serif;font-size:14px;\n  font-weight:normal;overflow:hidden;padding:10px 5px;word-break:normal;}\n.tg .tg-0lax{text-align:left;vertical-align:top}\n</style>\n<table class=\"tg\">\n<thead>\n  <tr>\n    <th class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Current name</span> </th>\n    <th class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">New name</span> </th>\n  </tr>\n</thead>\n<tbody>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Azure Purview</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview </span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Azure Purview portal</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview governance portal</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft 365 compliance</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft 365 compliance center</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview compliance portal</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Azure Purview Data Catalog</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview Data Catalog</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Azure Purview Data Insights</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview Data Estate Insights</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Azure Purview Data Map</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview Data Map</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Azure Purview Data Sharing</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview Data Sharing</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Azure Purview Data Use Management</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview Data Use Management</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft 365 Advanced Audit</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview Audit (Premium)</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft 365 Basic Audit</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview Audit (Standard)</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Office 365 Advanced eDiscovery</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview eDiscovery (Premium)</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Office 365 Core eDiscovery</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview eDiscovery (Standard)</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft 365 Communication Compliance</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview Communication Compliance</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Compliance Manager</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview Compliance Manager</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Customer Key for Office 365</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview Customer Key</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Double Key Encryption for Office 365</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview Double Key Encryption</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Office 365 Customer Lockbox</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview Customer Lockbox</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Office 365 Data loss prevention</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview Data Loss Prevention</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft 365 Information Barriers</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview Information Barriers</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Information Protection</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview Information Protection</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Information Governance</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview Data Lifecycle Management</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft 365 Insider Risk Management</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview Insider Risk Management</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Privileged Access Management in Microsoft 365</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview Privileged Access Management</span> </td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Records Management in Microsoft 365</span> </td>\n    <td class=\"tg-0lax\"> <br><span style=\"color:#2F2F2F\">Microsoft Purview Records Management</span> </td>\n  </tr>\n</tbody>\n</table>\n<p>Do not let new naming conventions confuse you. The rebranded services from Microsoft provide the same catnip we have all come to love when dealing with Cybersecurity Maturity Model Certification.</p>\n<p>Img credit: <a title=\"Confused\" href=\"https://flickr.com/photos/slava/1167335643\">Confused</a> flickr photo by <a href=\"https://flickr.com/people/slava\">slava</a> shared under a <a href=\"https://creativecommons.org/licenses/by/2.0/\">Creative Commons (BY) license</a></p>\n",
        "date_published": "2022-05-11T09:24:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2022/05/11/guide-to-microsoft.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2022/04/24/ccmc-asset-categorization.html",
        "title": "CCMC: Asset Categorization and Systems Security Engineering",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2022/12fe4022dd.png\" width=\"600\" height=\"450\" alt=\"\" />\n<p>Systems security engineering, establishing security by considering the problem, solution, and trustworthiness of all key components in a business, begins with stakeholder interest and the business outcomes.</p>\n<p>A business that cannot turn a profit cannot remain a business for long. This remains the greatest risk to the system and drives decision making. Business owners have assets, people, technology, and facilities with value that have costs, bring in revenue and that present risk. A risk-based approach must get applied to protect these assets.</p>\n<p>We must consider security as a tangible asset, and not a cost constraint  in a system we engineer. How we engineer security into the requirements of other assets depends on how we categorize the asset and the risk it faces.</p>\n<h3 id=\"assets-and-risk-management-framework\">ASSETS AND RISK MANAGEMENT FRAMEWORK</h3>\n<p>Systems security engineering utilizing a risk management framework require us to consider assets at three levels.</p>\n<img src=\"https://cdn.uploads.micro.blog/29546/2022/4d44b3c889.png\" width=\"600\" height=\"362\" alt=\"three tier system of RMF\" />\n<p>As an organization meets the security requirements of NIST-SP-800-171 they make continuous improvement in the organization’s risk-related activities across three different tiers. Tier one is the organizational level and sets the governance necessary to engineer secure systems. It includes the organization risks of profit and loss and decisions about investment in security as an asset.</p>\n<p>In tier 2 the work gets done. It represents the mission/business processes a business relies on. This also includes how Controlled Unclassified Information, and all data moves through a system. Processes must be in place to meet security requirements. At this tier you deploy Inventory and Asset Management System and  the reference architecture built to a baseline.</p>\n<p>Tier three represents the information systems that enable the business processes to occur based on the governance and risk established. This includes many of the continuous systems that exist throughout their life cycle. Security requirements that align to the risk set in tier and utilizing the processes of tier two get met in order to protect assets that move through an information system.</p>\n<p>Assets, anything with defined value, will exist at all three tiers. Security requirements, constraints, and in-scope assets of a CMMC assessment will exist across all three tiers.</p>\n<p>By utilizing Systems Security Thinking from a risk management framework an organization seeking certification can engineer Inventory and Asset Management systems that help to increase the trustworthiness of asset categorization through automation and continuous monitoring.</p>\n<h3 id=\"asset-categorization-and-cmmc\">ASSET CATEGORIZATION AND CMMC</h3>\n<p>Organizations who engineer security using proactive and reactive loss prevention will not only have better security, but they also control the cost and ease of a CMMC Assessment.</p>\n<p>The goal of systems security thinking is to develop immutable architecture through baseline enforcement, moving access controls more from the boundary to the asset identity, and deploying continuous monitoring through automation and machine-based scanning.</p>\n<p>Design based thinking requires establishing a baseline and we begin with inventory and asset categorization. Once security-based solutions for asset inventory get engineered a company should begin on asset categorization. In fact systems security engineering, and not just a NIST-SP-800-171 assessment, rely on asset categorization:</p>\n<p>This means proactively planning and designing to prevent the loss of an asset that you are not willing to accept; to be able to minimize the consequences should such a loss occur; and to be in an informed position to reactively recover from the loss when it does happen.</p>\n<p>For CMMC Level 1, only assets classified as FCI are considered in scope.</p>\n<p>CMMC Level 2 assessments are conducted when an organization transmits, stores, or processes CUI. Often these organizations also have FCI. If an organization, for example, uses two different enclaves – one for FCI and one for CUI – then they will need two different assessments. If the FCI and CUI get comingled in the same system, an OSC should seek a single assessment from a C3PAO.</p>\n<p>A Certified CMMC Professional,  can help companies with complex systems and small budgets save money if they can categorize assets as either in-scope or out-of-scope. A CCA will want to understand how asset categorization fits within an organizations Inventory Asset Management policies and procedures. There are specific controls that require any authorized user to be tracked and for attempts at unauthorized access to get logged.</p>\n<p>More importantly, in a CMMC assessment not all assets fall in scope. The scope of the people, technology, and facilities will change at the three different tiers of risk management. At each level you will have users with more privileges than others. You will have assets that require greater protections. Policies need to be accounted for in level one, reference architecture at level two and fine grain security requirements down to the last endpoint at level three. Any assets in the system must get categorized, the security requirements identified,  and their life cycle documented.</p>\n<p>This requires serious counting and then organizing what gets counted.</p>\n<p>Sometimes an organization’s assets are such that it is more economical to grow the scope so that the entire company is a controlled environment rather than trying to limit the scope to one or more enclaves. This holds especially true for many small manufacturers who cannot add separation between CUI assets and normal business practices, such as by using an Enterprise Resource Planning (ERP) tool.</p>\n<p>A CCP, will  work with companies to develop their asset inventory to provide details of the assets the company owns. This can cover a range of asset types, from tangible fixed assets such as property and equipment, to intangible assets such as intellectual property. An assessment team member, CCP, CCA, or Leader assessor will use the asset inventory and categorizations to verify the scope of the environment and to scope the assessment.</p>\n<p>But within the asset categorization you must think behind the wall. Physical asset management systems can tell you the location of a computer, but cannot answer questions like:</p>\n<p>“What operating systems are our laptops running?”</p>\n<p>“Which devices are vulnerable to the latest threat?”</p>\n<p>Effective ITAM solutions, driven by asset categorization, tie physical and virtual assets together, and provide management with a complete picture of what, where, and how assets are used. ITAM enhances visibility for security analysts, which leads to better asset utilization and overall system security.</p>\n<p>People, technology, and facilities can be in scope as any of the five asset categories at the three tiers of the system. At tier one policies inform the configuration management. The authorized holder of the CUI will have a privileged role. People with incident response and disaster recovery will also have privileged roles. Elevated assets often fall in scope.</p>\n<p>At tier two you need to categories any configuration management procedures of in scope assets. Baselines, reference architecture, and threat monitoring procedures exist at this level. Privileged users will collect data about risk to assets and pass that up to in scope people in tier one.</p>\n<p>At tier three all the people, facilities, and technology that make up your system need to meet the security requirements. Most of the assets categorized for a CMMC assessment will exist at this level. This includes every endpoint, training records, key physical and logical boundaries. You may have systems to separate out of scope assets from CUI.</p>\n<img src=\"https://cdn.uploads.micro.blog/29546/2022/8ea11ad9d3.png\" width=\"600\" height=\"800\" alt=\"asset categorization across three tiers\" />\n<p>In security systems engineering the in scope assets exist at mainly at level one, the procedures to secure those assets exist at level two. The data about the current state of the asset and its lifecycle get pushed back up to threat monitoring at level two. If an adverse risk is noted the policies and regulations categorized in tier one kick in.</p>\n<p>As an organization engineers asset categorization into their Inventory and Asset Management systems they need to consider if the labeling will happen manually, automatically, or at provenance  of the asset. Manual means someone physically has to enroll and de-enroll an asset from the system. Even with automation good security practices require manual authorization for an asset to first connect to a system. Your key boundaries will also exist and need protection at the third tier. People who maintain the security and all in scope users will need specific training. None of this can happen without categorizing assets based on risk.</p>\n<p>In terms of determining the scope of a CMMC assessment we must think about five types of assets.</p>\n<ul>\n<li>Control Unclassified Information Assets-Assets that process, store, or transmit CUI.</li>\n<li>Security Protection Assets-Assets that provide security functions or capabilities to the contractor’s CMMC assessment scope even if these assets do not store or transmit CUI.</li>\n<li>Contractor Risk Managed Assets-Assets that can, but are not intended to, process, store, or transmit CUI because of security policy, procedures and practices in place.</li>\n<li>Specialized Assets-Assets that may or may not process, store, or transmit but are out of scope of CMMC beyond documenting risk mitigation in the SSP through security policy, procedures and practices.</li>\n<li>Out of Scope Assets-Assets that cannot process, store, or transmit CUI.</li>\n</ul>\n<h4 id=\"controlled-unclassified-information\">CONTROLLED UNCLASSIFIED INFORMATION</h4>\n<p>Controlled Unclassified Information assets make up the heart of a CMMC assessment. Any asset categorization system should attempt to identify CUI to ensure it meets the security requirements spelled out in DFARS.</p>\n<p>NARA has identified many categories of CUI but a contractor in the Defense space will mainly handle controlled technical information, critical infrastructure security information, naval nuclear propulsion, and unclassified controlled nuclear information.</p>\n<p>If the contractor sells a commercial off the shelf product it is not Controlled Unclassified Information. COTS can still come with export controls and be considered ITAR and need to meet security requirements from the State Departmnt but this would be out of scope of a CMMC assessment.\nNext an organization seeking certification needs to determine if the data gets created, processed, transmitted, or stored is the result of a contract with the  DFARS 252.204-7012 clause. Without this clause you do not handle CUI on behalf on  a Defense contract. If you receive CUI as a result of a contract without this clause you have no security or incident reporting requirements.</p>\n<p>Most CUI will not get labeled. The data labeled or unlabeled, by being controlled unclassified information, is controlled by some federal law or regulation. Your next step is to examine any assets with limited distribution statements of that is considered ITAR. Any ITAR or data marked for limited access because of a contract with the 7012 clause is almost always CUI.</p>\n<p>Asset categorization must pay particular attention to CUI assets if an organization is trying to use enclaves or to keep out of scope assets separated from CUI. You will want to categorize the people who have authorized access to the CUI. You also need to count the things that protect CUI</p>\n<h4 id=\"security-protection-assets\">SECURITY PROTECTION ASSETS</h4>\n<p>We must also consider the Security Protection Assets (SPA). These are all of the cybersecurity hardware and software a company uses and pays for to protect their systems. A CCA may fail an Organization Seeking Certification if SPAs go unaccounted and thus unpatched.\nYour cybersecurity, or SPA inventory should:</p>\n<ul>\n<li>Gather data from any source that provides detailed information about assets</li>\n<li>Correlate that data to generate a view of every asset and what is on it</li>\n<li>Continually validate every asset’s adherence to the overall security policy</li>\n<li>Create automatic, triggered actions whenever an asset deviates from that security policy</li>\n</ul>\n<p>Automated asset management has significant advantages over manual asset inventory. Mainly, all your data lives in one place rather than in a variety of spreadsheets, clipboards, or bar code systems. Warranties, receipts, user manuals, STIGS, and baseline configurations get stored in one place.  As a CCP, you should help a company inventory all of the important documentation required for all five types of CMMC asset categories.</p>\n<p>An Assessment Team member, whether a CCP or a CCA , will assess if an organization uses asset inventory software, or build procedures into their existing systems. They will check on the ability to schedule maintenance automatically. A CCA will make sure Patching gets included in the lifecycle of a SPA.</p>\n<p>For example, in environments that use a commercial cloud organization may use configuration management tools. These cloud services allow you to write, manage, and compile to create a Desired State Configuration (DSC). The inventory features built into  built into these tools allows for tracking of virtual machines hosted in commercial clouds, on-premises, and other cloud environments. As part of Inventory and Asset Management lifecycles  assets get tracked using these scripts. This asset therefore provides security protection to CUI assets and gets categorized as in scope. If you mess with the scripts that count and categorize assets a threat can hide their tracks.</p>\n<p>Many inventory software systems, especially mobile device management tools, allow privileged users to perform remote updates and inspections of IT assets. You can inventory devices such as laptops or tablets. This saves the IT staff valuable time and resources. Most manual inventory processes end up hurting the company’s bottom line because the IT staff could be better using their time in support of the IT infrastructure. Other organizations may have no IT staff at all.</p>\n<p>Inventory software helps to reduce loss through theft of valuable assets via physical verification and tagging of fixed assets. This, in turn, helps to protect the confidentiality of CUI – the goal of the CMMC program. Asset inventory software can produce the most accurate inventory. Discrepancies get identified and resolved quicker and cheaper than by manual methods. CCPs may want to consider doing assessments and contracts especially around the automation of ITAM.</p>\n<h4 id=\"contractor-risk-managed-assets\">CONTRACTOR RISK MANAGED ASSETS</h4>\n<p>Contractor Risk Managed Assets can process, store, or transmit CUI but an organization plans to keep CUI out of these assets. This requires an inventory of the security policy, procedures, and practices in place to protect these assets NIST-SP-800-171 is neither a framework or a security plan. A CMMC assessment only verifies that you meet the security requirements of NIST-SP-800-171 to protect the confidentiality of CUI. You will need a risk based security plan to categorize CRMA.  Contractor Risk Managed Assets are not required to be physically or logically separated from CUI Assets.</p>\n<p>They are part of the  CMMC Assessment Scope. These assets just get managed using the contractor’s risk-based information security policy, procedures, and practices that sit above CMMC in the tier one of the system. If properly categorized CRMA and are not assessed against CMMC practices.</p>\n<p>Facilities may often fall under contractor risk managed access as ab organization may not own the building or utilities coming inside. A conference room, for example, may hold meetings that process CUI. This CUI then gets locked away and protected by one physical barrier. The lockbox is inscope but the conference room is a risk managed asset.</p>\n<h4 id=\"specialized-assets\">SPECIALIZED ASSETS</h4>\n<p>Specialized assets may or may not process, store, or transmit Controlled Unclassified Information. If they do handle CUI the asset must provide a very specialized function. It should configured to do just that one function and if possible be physically or logically separated from in scope systems. Internet of Things, Operational Technology, Restricted Information systems, Government property, and test equipment get excluded.</p>\n<p>An asset categorization system must account for specialized assets. The security plan must detail how an organization accounts and controls the risk to the asset. In essence specialized assets require tailoring from a Risk Management Framework from NIST-SP-800-37 and 39 using Systems Security Engineering in NIST-SP-800-160. When you have a highly specialized asset you tailor a set of controls if the asset can not not meet the required security baseline.</p>\n<h4 id=\"out-of-scope-assets\">OUT OF SCOPE ASSETS</h4>\n<p>Out of scope assets do not handle CUI. They are not in scope of a CMMC assessment. Your asset categorization however should account for any asset. Remember an asset is defined as anything with value. If something has worth and organization should count it.\nAdversaries want to steal your IP and PII as much, if not more, than Controlled Unclassified Information</p>\n<h3 id=\"helping-companies-with-asset-categorization\">HELPING COMPANIES WITH ASSET CATEGORIZATION</h3>\n<p>A CCP or CCA need to work with your clients on identifying data flow within their companies and understanding how this data flow impacts the five asset categories of a CMMC assessment. This will be essential when scoping the assessment.</p>\n<p>An implentor will want to work with clients to leverage their existing expertise and systems for inventory to help them automate IT Asset Management. A Certified CMMC Assessor will want to work with organization that have effective asset categorization.</p>\n<p>On Microsoft Systems a CCA will often analyze evidence collected using Azure Automation. Asset categorization and Inventory Asset Management may occur Microsoft Defender. In Apple environments people may use a third party vendor such as JAMF to only install approved apps.  Other organizations may drive their inventory through a SIEM and vulnerability scanning.</p>\n<p>Long term, once the risk based analysis is completed, the assets inventoried and categorizes Systems Security Engineering will drive us to a baseline and reference architecture. Categorizing assets across the lifecycle of deployment enables this goal. At the same time good reference architecture will help to automate asset categorization.</p>\n<hr>\nThis is the sixth post on a series on using NIST-SP-800-160 Systems Security Engineering to meet the requirements of SC.L2-3.13.2 – SECURITY ENGINEERING\n<blockquote>Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.</blockquote>\n<p>First post: <a href=\"https://www.drmacscybersecuritybrief.com/2022/04/13/evaluating-organizations-seeking.html\">Evaluating Organizations Seeking Certifcation: Document Based Requirements to Start a Conversation</a></p>\n<p>Second Post: <a href=\"https://www.drmacscybersecuritybrief.com/2022/04/18/system-security-engineering.html\">CMMC and Systems Security Engineering</a></p>\n<p>Third Post: <a href=\"https://www.drmacscybersecuritybrief.com/2022/04/20/cmmc-asset-inventory.html\">CMMC and Asset Inventory</a></p>\n<p>Fourth Post: <a href=\"https://www.drmacscybersecuritybrief.com/2022/04/22/cmmc-assessment-in.html\">CMMC Assessment: In Systems Security Engineering the Environment Drives Evidence</a></p>\n<p>Fifth Post: &lt;a href=&ldquo;<a href=\"https://www.drmacscybersecuritybrief.com/2022/04/23/cmmc-systems-security.html%3ECMMC\">https://www.drmacscybersecuritybrief.com/2022/04/23/cmmc-systems-security.html&gt;CMMC</a>: Systems Security Engineering and the Cloud&gt;</a></p>\n<p>Img Credit: CMMC Asset scoping a remix of &ldquo;Five fire buckets and one fire extinguisher&rdquo; flickr photo by cowbite <a href=\"https://flickr.com/photos/cowbite/820720997\">https://flickr.com/photos/cowbite/820720997</a> shared under a Creative Commons (BY-SA) license by jgmac1106 shared under a Creative Commons (BY-SA) license</p>\n",
        "date_published": "2022-04-24T19:53:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2022/04/24/ccmc-asset-categorization.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2022/04/23/cmmc-systems-security.html",
        "title": "CMMC: Systems Security Engineering and the Cloud",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2022/d953818799.jpg\" width=\"600\" height=\"398\" alt=\"\" />\n<p>In systems security engineering requirements and constraints drive the design choices we make. They will send signals in a CMMC assessment. The constraints and requirements of an environment determines the type of evidence an assessor needs to verify. Organizations Seeking Certification and Certified CMMC Assessors will more than likely have to deal with many environments that utilize cloud deployments.</p>\n<h2 id=\"what-is-the-cloud\">What is the Cloud?</h2>\n<p>According to NIST cloud computing enables, “ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) ,“ and that these resources take minimal configuration by the users.</p>\n<p>The Federal Government, using this definition for their cloud migration efforts defined five key characteristics of cloud environments.</p>\n<ul>\n<li>on-demand service-Employees can access from any device</li>\n<li>broad network access-Employees can access anytime or anywhere</li>\n<li>resource pooling,-Employers share servers and infrastructure</li>\n<li>rapid elasticity-Can scale to almost unlimited users</li>\n<li>measured service-A third party maintains the system</li>\n</ul>\n<p>Cloud computing provides a developer agnostic pathway to building controlled environments, meaning there are multiple solutions in a variety of forms  of deployment. According to according to NIST this includes:</p>\n<ul>\n<li>Private Cloud- Provisioned for a single organization.</li>\n<li>Community Cloud-A cloud provisioned for specific groups of users withn a company</li>\n<li>Public cloud-provisioned for general community use and not used in business setting often</li>\n<li>Hybrid Cloud-A combination of any two above</li>\n</ul>\n<h3 id=\"cloud-security-requirements\">Cloud Security Requirements</h3>\n<p>The shared services layer introduced into the system will impact the security engineered into the system and the assessment procedures used by a Certified CMMC Assessor. This service layer depends on the cloud service model used by the organization.</p>\n<p>According to CISA’s  Cloud Security Technical Reference Architecture the service model will determine security requirements.</p>\n<img src=\"https://cdn.uploads.micro.blog/29546/2022/cfa0234b2b.png\" width=\"600\" height=\"399\" alt=\"cloud services managed service matrix\" />\n<p>NIST defines four services models as illustrated in the figure from CISA’s  Cloud Security Technical Reference Architecture:</p>\n<ul>\n<li>On-Premsises</li>\n<li>Infrastructure-as-a-Service</li>\n<li>Platform-as-a-Service</li>\n<li>Software-as-a-Service</li>\n</ul>\n<p>Regardless of the service model all cloud environments must get engineered to meet the same basic security requirements as spelled out in Federal law and regulation.</p>\n<h3 id=\"shared-responsibility-matrix\">Shared Responsibility Matrix</h3>\n<p>An assessor, in conversation with the OSC, must determine what and who is in scope. The majority of security requirements these assets introduce will all get documented in a shared responsibility matrix. An assessor will want to verify the FedRAMP equivalency seeing a document that outline who manages what security requirement if the cloud assets store, transmit or process unencrypted CUI.  All cloud deployments, regardless of the service model, require a shared responsibility matrix for a CMMC assessment.  Any FedRAMP authorized CSP must submit a responsibility matrix as part of their authorization package. Many organizations use that document to build their CMMC 171 SRM.</p>\n<h4 id=\"nist-sp-800-171\">NIST-SP-800-171</h4>\n<p>These service models influence the security requirements engineered into a system and move the shared responsibility of meeting the requirements from the Organization managing them to the vendor managing the requirements. Regardless of the shared service layer engineered into the system the Organization Seeking Certification is always responsible for documenting and meeting the requirements.</p>\n<h4 id=\"export-control\">Export Control</h4>\n<p>If an organization holds export-controlled data under ITAR or EAR new security requirements get introduced. This data requires data sovereignty for the cloud or must meet encryption requirements inside of a controlled environment and then remain encrypted the entire time in the cloud. Meaning never available in a readable format to anyone until downloaded and unencrypted back in the controlled environment. Only the organization and not the vendor should hold the keys to the data. Any vendor support must get restricted to US persons.</p>\n<h4 id=\"fedramp-moderate\">FedRAMP-Moderate</h4>\n<p>Cloud services, based on DFARS 252.204-7012(b)(2)(ii)(D), that store, process, or transmit Controlled Unclassified Information must meet the FedRAMP Moderate baseline or its equivalent. Thus if an organization uses a cloud service to support security such a s a SIEM, that tool does not need FedRAMP Moderate equivalency because it does not store, process, or transmit CUI.</p>\n<h4 id=\"incident-reporting\">Incident Reporting</h4>\n<p>In scope cloud service providers that store, process, or transmit CUI must also meet the incident reporting requirements of DFARS 252.204-7012(c-g). Any incident must get reported to the Department of Defense within 72 hours and images of the system must get preserved for 90 days. The DoD may want access to the equipment. This means a Cloud vendor must accept the contractual flow down of DFARS 252.204-7012</p>\n<p>A CMMC assessment only verifies the trustworthiness of 171 security requirements. It is not a DFARS or EAR compliant assessment. That being said an assessor may verify if your Incident Response Plan meets DFARS requirements. If your policy and plans state you are in compliance with other security requirements  the assessor will verify the procedures and evidence to ensure &ldquo;you say what you do and do what you say.&rdquo;</p>\n<h3 id=\"cloud-environmental-constraints\">Cloud Environmental Constraints</h3>\n<p>Migrations take time if an organization thinks they may hold CUI in the future. A Prime contractor may demands compliant environment regardless if they flow CUI down to an organization in a contract. In these situations an OSC should consider a compliant cloud environment given the time migration takes. Time is often the toughest constraint in systems security engineering.</p>\n<p>Regardless of deployment, cloud often refers to connecting to servers maintained by other organizations. How an organization utilizes the cloud depends on stakeholder needs and system constraints. A company inherits, or shares much of the security responsibility with a cloud vendor. This often gets represented in a shared responsibility matrix.</p>\n<p>Thus an Organization Seeking Certification and a Certified CMMC Assessor will need to understand how employees connect to the cloud based infrastructure. Security requirements around encryption are very specific in CMMC. The baseline policies must apply constraints on users in how they access the cloud. You must also determine if a managed service provider is in scope and if they have access to the CUI stored in the CSP.</p>\n<p>The world of IT, or Information Technology, has faced monumental shifts in the last three decades. We have moved from fixing a spool on a dot matrix printer to proving audit logs on endpoint detection.</p>\n<p>From a Systems Security Engineering perspective, this changing relationship between IT companies and members of the Defense Industrial Base introduces to requirements and constraints on security of your business.</p>\n<p>When creating a system for the way Controlled Unclassified Information flows through your networks an Organization Seeking Certification must understand the difference between key partners. Incorrect decisions could leave a third party and their systems in-scope of your assessment. This not only greatly increases costs but puts data at greater risk. The service models depend upon the people behind them.</p>\n<h4 id=\"csp-msp-mssp-what-is-the-difference\">CSP, MSP, MSSP What is the difference?</h4>\n<p>Utilizing NIST definition of cloud based computing we know that cloud solutions cut across five characteristics, three service models, and four deployments</p>\n<style type=\"text/css\">\n.tg  {border-collapse:collapse;border-spacing:0;}\n.tg td{border-color:black;border-style:solid;border-width:1px;font-family:Arial, sans-serif;font-size:14px;\n  overflow:hidden;padding:10px 5px;word-break:normal;}\n.tg th{border-color:black;border-style:solid;border-width:1px;font-family:Arial, sans-serif;font-size:14px;\n  font-weight:normal;overflow:hidden;padding:10px 5px;word-break:normal;}\n.tg .tg-0pky{border-color:inherit;text-align:left;vertical-align:top}\n</style>\n<table class=\"tg\">\n<thead>\n  <tr>\n    <th class=\"tg-0pky\">   <br>Characteristics   </th>\n    <th class=\"tg-0pky\">   <br>Service   Models   </th>\n    <th class=\"tg-0pky\">   <br>Deployments   </th>\n  </tr>\n</thead>\n<tbody>\n  <tr>\n    <td class=\"tg-0pky\">   <br>On-demand   self-service<br>   <br>Broad   network access<br>   <br>Resource   Pooling<br>   <br>Rapid   Elasticty<br>   <br>Measured   Service   </td>\n    <td class=\"tg-0pky\">   <br>Software as   a Service<br>   <br>Platform as   a Service<br>   <br>Infrastructure   as a Service   </td>\n    <td class=\"tg-0pky\">   <br>Private   Cloud<br>   <br>Community   Cloud<br>   <br>Public   Cloud<br>   <br>Hybrid   Cloud   </td>\n  </tr>\n</tbody>\n</table>\n<p>This defines the software, but what about the people? CMMC-AB and NIST go out of their way not to define the difference between Cloud Service Provider, Managed Service Provider, and a Managed Security Service Provider. The scoping guidance refers to all external service provider the same and the NIST page lists the definition of Clous Service Provider as none.</p>\n<img src=\"https://cdn.uploads.micro.blog/29546/2022/8a8960c3b5.png\" width=\"600\" height=\"335\" alt=\"screenshot of NIST gloassary page\" />\n<p>NIST-SP-171-800 and CMMC scoping rely on a data centric model and the vendor delivering services does not change the security requirements. The people you choose to work with do change the evidence collection needs to meet the requirements and do introduce new constraints.</p>\n<p>As an Organization Seeking Certification you need to consider these requirements and constraints as you evaluate partners. An Assessor will need to evaluate the requirements and contraints of an environment when developing assessment procedures.</p>\n<h4 id=\"what-is-a-cloud-service-provider\">What is a Cloud Service Provider?</h4>\n<p>A cloud service provider gives you access to computing networks and servers that they own and maintain. Google Docs SaaS  that Google provides as a cloud service provider. Microsoft is a cloud service provider with different levels of security.</p>\n<p>CSPS have their own requirements when it comes to establishing the trustworthiness in the system an Organization Seeking Certification throws. The evidence you must collect will change. Afterall Cloud Services Providers manage SaaS (Software as a Service), PaaS (platform as a service) or IaaS (infrastructure as a service) for users. This introduces new requirements and constraints to your system security engineering.</p>\n<p>A cloud service provider hosts all of your data and thefore must meet the requirement of protecting CUI while in transit and at rest. Some types of CUI must require the data get stored in the United States. There are even requirements for cloud computing spelled out in Defense Federal Acquisition Regulation Supplemental.</p>\n<h4 id=\"what-is-a-managed-service-provider\">What is a Managed Service Provider?</h4>\n<p>The contrast between MSPs and cloud services providers revolves around access control. MSPs manage and maintain technology that you own or license, whereas CSPs offer access to technology that they own.  MSPs may manage both on-premises and cloud-based infrastructure for their customers. The MSP, however, does not own or control the underlying cloud infrastructure that stores your data or Controlled Unclassified Information.</p>\n<p>MSPs also have their own requirements when it comes to developing evidence for compliance with CMMC Practices. They often act as IT Departments for companies that do not have them. An MSP acts as a partner and they may handle important tools such as Active Directory, data backup, anti-virus, and other IT functions. All of these fall in scope in a CMMC assessment.</p>\n<p>Whether an MSP falls in scope of your assessments will depend on the services they provide. Some my partition systems but through asymmetric key encryption never have access to any credentials or assets. Other MSPs may have physical access to networks and a company may treat these technicians as in scope employees. The service level agreements and shared responsibility matrices will drive your security requirements.</p>\n<h4 id=\"what-is-a-managed-security-service-provider\">What is a Managed Security Service Provider?</h4>\n<p>A managed security services provider (MSSP) provides oversight of specific security tools. These tools may not store or access CUI but they protect assets that do fall in scope. An MSSP focuses security services, such as firewalls, virus protection, and intrusion detection, They may provide a SIEM, or Security information and event management. MSSPs often specialize in a particular area, such as managed firewall service providers.</p>\n<p>According to the CMMC Level Scoping Guide “Security Protection Assets are part of the assessment scope and are required to conform to applicable CMMC practices, regardless of their physical or logical placement.”</p>\n<p>The scoping guidance spells out that an MSSP falls in scope for all-applicable CMMC practices. Yet the same can be true of a CSP or MSP as well.</p>\n<p>As you apply systems security engineering to meet the requirements of a CMMC assessment you must evaluate your partners. Examine the service level agreements you have, consider the time of deployment and migrating between a cloud or service provider. You need to choose compliance partners when evaluating vendors.</p>\n<h3 id=\"what-is-hybrid\">What is Hybrid?</h3>\n<p>A hybrid deployment combines onprem servers with cloud-based servers. Some organization may want to keep control of servers that store credentials for cloud computing. Others may have out of scope on prem servers they maintain but provision a private cloud for employees authorized to handle Controlled Unclassified Information.</p>\n<p>A hybrid cloud infrastructure may connect to a public cloud platform from a trusted third-party provider. Hybrid deployments may also utilize a private cloud partitioned on premises. A company may utilize hosted private cloud provider and allow employees to connect to the servers. A CMMC Assessor will often find an in-scope managed service provider may maintain the hybrid environment.</p>\n<h4 id=\"hybrid-environmental-requirements\">Hybrid Environmental Requirements</h4>\n<p>Like all environments the hybrid cloud must meet the same security requirements. The use of the hybrid environment just changes the metrics and evidence used to ensure the security requirements of NIST-SP-800-171.</p>\n<p>The people who maintain the environment introduce evidentiary requirements. Any on-prem deployment of tools will need a focus on the privileged users who can access those tools. Hybrid deployments can either introduce the most complicated requirements to document or help an organization shrink their scope by utilizing a cloud-based service. They are difficult to maintain but can provide benefits to those who take advantage of increased on-prem solutions with the scalability of cloud services.</p>\n<p>For example, you will need to think about the access to both the logical and physical barriers that store servers. A company will need to make sure their inventory disposal polices align with the requirements set out in the Media Protection domain. Many smaller companies may try to utilize a hybrid approach managed by an MSP. Some organizations keep their access control logs and Identify Managament systems onprem and data in the cloud. This will impact the evidence collected to demonstrate security requirements get met.</p>\n<p>An MSP may or may not be in-scope or have access to your Controlled Unclassified Information in an unencrypted state. If they provide security to systems that protect CUI either on-prem or in the cloud you will need to show how the MSP handles the applicable security requirements they manage.</p>\n<h4 id=\"hybrid-environmental-constraints\">Hybrid Environmental Constraints</h4>\n<p>Hybrid environments can bring all the environmental constraints of on-prem or cloud deployments while leaving a managed service provider in scope. On the other end of the spectrum hybrid environments in a private cloud using asymmetric keys for authorization can shrink a company’s scope down to a few assets.</p>\n<p>The difficulty in maintaining hybrid environments introduce many constraints. First you need to make the relationship and boundaries visible in all your data flow and network diagrams. Cost and time always act as constraints in systems security engineering. In hybrid solutions you may have to support two disparate solution who do not &ldquo;talk computer together.&rdquo; This introduces bespoke coding and architecture that presents a new threat vector. If these systems have data interoperability constraints even more challenges get introduced.</p>\n<p>At the same time Hybrid solutions can often help small businesses who may have only limited exposure of CUI in their on-prem environment. So if a manufacturer only had two to three machines that process CUI they may utilize a hybrid environment to share controlled technical information with remote employees. The CUI gets encrypted before it goes to the remote employee. The remote employee only works on a local device not connected to their network. They rencrypt the file before sending back within the onprem physical boundary.</p>\n<p>Hybrid environments managed by high quality MSPs can provide flexibility, reduced cost, and the ability to scale.</p>\n<h3 id=\"what-is-on-prem\">What is On-Prem?</h3>\n<p>An on-premises environment, often on-prem for short, means all in scope software and systems exist withing the physical and logical boundaries of an organization. The organization seeking certification is responsible for managing, maintaining, and supporting all systems and the security of the assets who access those systems to process, store, or transmit Controlled Unclassified Information.</p>\n<h4 id=\"on-prem-environmental-requirements\">On-Prem Environmental Requirements</h4>\n<p>On-Premises environments can bring the same regulatory and security requirements of Cloud and Hybrid deployments but the organization is responsible for managing all the security requirements of the software and hardware. The vendor has no responsibility.</p>\n<p>The network diagrams and data flow diagrams will dictae what evidence a Certified CMMC Assessor must collect to assess on-prem environments. An IT department or External Service Provider must maintain layers security, encryption, and protection of key boundary points.</p>\n<p>On-Prem, however, is not a unified deployment. Companies may have multi-site environments that connect to these systems. Overall on-site staff or contracts must maintain all software, hardware, access control, and physical security. This introduces specific evidence requirements for a CMMC assessment.</p>\n<h4 id=\"on-prem-environmental-constraints\">On-Prem Environmental Constraints</h4>\n<p>A company maintains all the servers, firewalls, and routers. The necessary resources create a sever constraint on maintenance. The cost of deprecating equipment may have advantages to cloud environments.  The over reliance on Managed Service Providers that maintain IT systems may increase the scope of security requirements.</p>\n<p>NIST-SP-800-171 approach to security relying on logical and physical boundaries meets the constraints of on-rem deployments for many companies. However recent security guidance and costs often drive businesses towards the cloud.</p>\n<p>Considering the ease of compliance for on-prem deployments may influence the design decisions and organization seeking certification makes. Other companies may choose on-prem solutions out of sheer size of their organization. A Certified CMMC Assessor will need to pay attention to the privileged access users have to key boundaries that protect physical access to servers. Organization who utilize on-prem solutions, will also need to detail who maintains the security updates to any of these assets. Most importantly they will have a reference architecture that explains the separation techniques that protect CUI.</p>\n<h3 id=\"right-fitting-your-cloud-deployment\">Right Fitting your Cloud Deployment</h3>\n<p>Almost all organizations will have some element of cloud in their systems. From a  Systems Security Engineering persepective each service model impacts the requirements and constraints a company must consider in their risk based awareness plan and daily operations.</p>\n<p>Systems Security Engineering broadcasts that an organization takes their security requirements serious regardless of the contrainsts they face.</p>\n<hr>\n<p>This is the fifth post on using NIST-SP-800-160 Systems Security Engineering to meet the requirements of SC.L2-3.13.2 – SECURITY ENGINEERING</p>\n<blockquote>Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.</blockquote>\n<p>First post: <a href=\"https://www.drmacscybersecuritybrief.com/2022/04/13/evaluating-organizations-seeking.html\">Evaluating Organizations Seeking Certifcation: Document Based Requirements to Start a Conversation</a></p>\n<p>Second Post: <a href=\"https://www.drmacscybersecuritybrief.com/2022/04/18/system-security-engineering.html\">CMMC and Systems Security Engineering</a></p>\n<p>Third Post: <a href=\"https://www.drmacscybersecuritybrief.com/2022/04/20/cmmc-asset-inventory.html\">CMMC and Asset Inventory</a></p>\n<p>Fourth Post: <a href=\"https://www.drmacscybersecuritybrief.com/2022/04/22/cmmc-assessment-in.html\">CMMC Assessment: In Systems Security Engineering the Environment Drives Evidence</a></p>\n<p>Img Credit: <a title=\"lost in transmission\" href=\"https://flickr.com/photos/kajjers/2697837044\">lost in transmission</a> flickr photo by <a href=\"https://flickr.com/people/kajjers\">savoryexposure</a> shared under a <a href=\"https://creativecommons.org/licenses/by-sa/2.0/\">Creative Commons (BY-SA) license</a></p>\n",
        "date_published": "2022-04-23T11:44:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2022/04/23/cmmc-systems-security.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2022/04/22/cmmc-assessment-in.html",
        "title": "CMMC Assessment: In Systems Security Engineering the Environment Drives  Evidence",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2022/7e808cf9aa.jpg\" width=\"600\" height=\"391\" alt=\"\" />\n<p>From A Systems Security Engineering perspective, the environment will drive the evidence collected to ensure an organization seeking certification meets security requirements.</p>\n<p>For both the assessor and the contractor considering the impact of scope on how their systems gets deployed will be the largest driver in the cost of engineering a system and meeting security requirements.  An Organization Seeking Certification must collect to meet the 320 objectives of a CMMC assessment. Assessors will need to consider the environment and the separation techniques used when deciding on what assessment procedures to use.</p>\n<p>Systems rely on the separation of physical and logical boundaries to ensure only those with a legal and authorized need access Controlled Unclassified Information. In fact, when designing controlled environments as part of our systems we must consider the environmental constraints of each possible deployment.</p>\n<p>The security requirements for storing, processing, or transmitting CUI for any deployment are the same. The requirements for export-controlled data are the same regardless of the environment. Incident reporting requirements are the same no matter the system an OSC engineers.</p>\n<p>You have a CMMC assessor come and verify the trustworthiness in your meeting the security requirements of NIST-SP-800-171. The environments used in the system will have an impact on the evidence used to justify a rating. The assessment procedures used by a certified CMMC assessor will change based on the environment.</p>\n<p>By analyzing constraints and requirements across the life cycle of a contract, thus utilizing systems security engineering, an organization identifies the type of evidence a Certified Assessor may collect to verify the trustworthiness of the System Security Plan based on their deployment</p>\n<h2 id=\"environmental-constraints-and-separation-techniques\">Environmental Constraints and Separation Techniques</h2>\n<p>When engineering a system an organization must consider how Controlled Unclassified Information does or does not move through logical and physical boundaries. Utilizing separation, or “system architecture design concept that can provide physical/logical isolation of assets that process, transmit, or store CUI from assets not involved with CUI” an organization can protect CUI from unauthorized disclosure.</p>\n<p>When an OSC accounts for different environments and their constraints they collect the unique evidence needed to demonstrate the security requirements get met.</p>\n<h2 id=\"where-do-in-scope-facilities-exist\">Where Do In Scope facilities Exist?</h2>\n<p>Modern deployments range from on-premises where an organization maintains responsibility for all software, equipment, and physical to cloud based software-as-a-service platform where the organization maintains only limited control over domains such as access control and the vendor handles all other security requirements.</p>\n<p>Unless organizations utilize separation, techniques and keep all CUI in a system with security measures such as DMZ , layered boundary protections, and air gapped systems or an organization keeps an entire system in scope an assessor will be working with cloud environments.</p>\n<p>“Cloud Smart,” rather than “Cloud First” was initiated in 2017 as a result of the Report to the President on Federal IT Modernization.  Cloud Smart emphasizes the three pillars of security, procurement, and workforce. These three principles work in systems security engineering while also introducing specific requirements and constraints to the environment.</p>\n<p>The biggest impact Cloud has on a CMMC assessment is introducing a shared services layer to the environment. As soon as an organization uses a cloud vendor for in-scope services or uses security tools in the cloud they share the security requirements and must document who and how they get met across the organization. The CSP is not assessed during a CMMC assessment, but the assessor will need to establish the trustworthiness of shared responsibility.</p>\n<p>These requirements and constraints have an impact when assessing organizations. As you engineer a system that meets the security requirements of NIST-SP-800-171 you need to determine your environment and consider the constraints and requirements across the lifecycle of your deployment.</p>\n<hr>\n<p>This is the fourth post on using NIST-SP-800-160 Systems Security Engineering to meet the requirements of SC.L2-3.13.2 – SECURITY ENGINEERING</p>\n<blockquote>Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.</blockquote>\n<p>First post: <a href=\"https://www.drmacscybersecuritybrief.com/2022/04/13/evaluating-organizations-seeking.html\">Evaluating Organizations Seeking Certifcation: Document Based Requirements to Start a Conversation</a></p>\n<p>Second Post: <a href=\"https://www.drmacscybersecuritybrief.com/2022/04/18/system-security-engineering.html\">CMMC and Systems Security Engineering</a></p>\n<p>Third Post: <a href=\"https://www.drmacscybersecuritybrief.com/2022/04/20/cmmc-asset-inventory.html\">CMMC and Asset Inventory</a></p>\n<p>img credit: <a title=\"Drive\" href=\"https://flickr.com/photos/astarothcy/317433677\">Drive</a> flickr photo by <a href=\"https://flickr.com/people/astarothcy\">astarothcy</a> shared under a <a href=\"https://creativecommons.org/licenses/by-sa/2.0/\">Creative Commons (BY-SA) license</a></p>\n",
        "date_published": "2022-04-22T12:24:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2022/04/22/cmmc-assessment-in.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2022/04/20/cmmc-asset-inventory.html",
        "title": "CMMC, Asset Inventory, and Systems Security Engineering",
        "content_html": "<style>\ntable, th, td {\n  border: 1px solid;\n}\n</style>\n<img src=\"https://cdn.uploads.micro.blog/29546/2022/971fa5a225.jpg\" width=\"600\" height=\"400\" alt=\"\" />\n<p>You cannot protect what you do not know you have.</p>\n<p>Systems security engineering, as a method to meet the security requirements of CMMC requires an Organization Seeking Certification (OSC) to provide the means to locate, identify, and log the inventory of assets. Organizations must also engineer methods to verify the trustworthiness of data and provide it as evidence during a CMMC assessment. This closed feedback loop helps to strengthen the hygiene of an organization seeking certification.</p>\n<p>Yet asset inventory, from a lens of systems security engineering means, more than just counting computers. It does not end at endpoints. Inventory refers to more than even physical  or logical boundaries. Management involves more than logging. You also must assess the risk these assets face. Taken together, like any element in a system, asset management requires a security first philosophy.</p>\n<p>Many, if not all, of the CMMC domains require you to do inventory. Any time you define, identify, or list items as part of an assessment objective under a practice, good inventory matters. Basically, don’t just think about counting the things that plug into the wall. You also need to count and manage all the assets that move data in between the walls, buildings, and networks.</p>\n<p>Companies need to apply and understand the design principles behind asset management. If an organization takes an interdisciplinary approach to asset inventory, managing anything with value, as part of overall business success rather than seeing cybersecurity see it as an IT problem the company can begin to apply systems thinking.</p>\n<p>By applying systems security engineering to asset inventory an organization will automate many of the elements that go into good inventory, create processes for Inventory and Asset Management (IATM), design IATM from a security first principle, and account for each stage of the asset lifecycle.</p>\n<h2>Systems Security Thinking</h2>\n<p>Inventory, emerges from a system. It requires technical and non-technical processes to come together.</p>\n<p>System engineering thinking refers to interacting elements that achieve a business goal or stated purpose. Anyone who has owned or worked in a business knows how critical inventory systems are for overall success.</p>\n<p>If an organization places security as central to their systems thinking, where they consider the implication of any asset or system across its lifecycle the company has focused on the principles of system security engineering.</p>\n<p>No specific CMMC practice requires companies to adopt system security engineering but in reality collecting the real time records of all the assets a company has in scope would be difficult without relying on these principles. The amount of data needed to ensure the trustworthiness of an environment handling CUI is too much for any manual attempt. Further the data collected as part of IATM influences every aspect of security such as access control.</p>\n<p>NIST-SP-800-160 SYSTEMS SECURITY ENGINEERING: A Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems lays out ways to apply security to all assets and processes throughout a business goal.</p>\n<table>\n<tbody>\n<tr>\n<td>\n<p>Problem</p>\n</td>\n<td>\n<p>Solution</p>\n</td>\n<td>\n<p>Trustworthiness</p>\n</td>\n<td>\n<p>Analyze</p>\n</td>\n</tr>\n<tr>\n<td>\n<p>Identify and plan for enabling systems for IATM</p>\n<p>Define metrics of success</p>\n<p>Identify CMMC practices impacted by inventory</p>\n<p>Update SSP</p>\n</td>\n<td>\n<p>Develop IATM Policy</p>\n<p>Create baseline for enabling systems</p>\n<p>Deploy enabling systems</p>\n<p>Create a lifecycle for any asset</p>\n<p>Identify stakeholder assets and asset categorization</p>\n<p>Apply security metadata tagging</p>\n<p>Develop a RACI model for any asset and enabling system or process</p>\n<p>Update SSP</p>\n</td>\n<td>\n<p>Develop a scenario on how IATM system should work.</p>\n<p>Compare and identify assets from data collected during vulnerability scans</p>\n<p>Create traceability of inventory</p>\n<p>Update SSP and POAM</p>\n</td>\n<td>\n<p>Analyze how enabling systems can further automate IATM</p>\n<p>Analyze impact on reference architecture if any systems got updated, removed, or added</p>\n<p>Update SSP and POAM</p>\n</td>\n</tr>\n<tr>\n<td>\n<p>Continuous Feedback Loop</p>\n</td>\n<td>\n<p>Continuous Feedback Loop</p>\n</td>\n<td>\n<p>Continuous Feedback Loop</p>\n</td>\n<td>\n<p>Continuous Feedback Loop</p>\n</td>\n</tr>\n</tbody>\n</table>\n<p>Systems security engineering puts a security baseline as a goal for stakeholders who own a system. A system consists of different elements or assets and the assets and elements that support the system. While you can count by hand good inventory requires system security engineering.</p>\n<h3><strong>What Goes into Inventory?</strong></h3>\n<ul>\n<li> Unique Identifier-Each asset needs its own name</li>\n<li> Platform type-Windows, Mac, Server</li>\n<li> Asset Categorization-Type of CMMC asset per scoping guidance</li>\n<li> Owner of asset-who is the non-privileged or privileged user of asset</li>\n<li> Admin of asset-Privileged employee or a third party through shared responsibility</li>\n<li> The applications and processes that manage the inventory of this asset</li>\n<li> Network Connections-ways the asset connects</li>\n<li> Regulations-Laws that govern this asset</li>\n<li> Practices/Controls Met-CMMC practices that protect the asset</li>\n<li> Assets role in business</li>\n<li> Contractual Availability-Any rules that spell out access to asset</li>\n  <li> Assigned Maintenance-Who maintains asset or third party relationship</li>\n<li> Link to Maintenance Plan</li>\n</ul>\n<p>Asset inventory needs to be a living document fed by automation and cared for with good policy and procedures. An Organization needs a system to automate asset discovery. They need to collect up to date information on your assets, such as patching or log-ons. Some assets, like computer programs, may come with a software bill of materials that contain important information that gets automated.</p>\n<p>In other words a successful CMMC assessment requires that organizations understand and utilize IT Asset Management from a systems security engineering mindset.</p>\n<h2>What is IT Asset Management (ITAM)?</h2>\n<p>IT Asset Management (ITAM) applies systems  security engineering principles to manage the life cycle of inventory and the entities responsible for ownership. Key aspects of ITAM programs include:</p>\n<p>· <strong>Asset inventory</strong> – Getting a comprehensive inventory of all hardware, software, and network assets</p>\n<p>· <strong>License management</strong> – Ensuring all assets are running properly licensed software</p>\n<p>· <strong>Lifecycle management</strong> – Deciding which assets should be decommissioned, managing the software licenses on these assets, and updating the inventory</p>\n<p>· <strong>Patch management</strong> – Ensuring the latest security patches are in place on all systems that need them, and understanding which systems have existing vulnerabilities that must be mitigated if no patches exist</p>\n<p>Properly conducted, IT Asset Management will help drive cybersecurity hygiene. You must understand an organization’s topography to understand the flow of Federal Contract Information and Controlled Unclassified Information. A Certified CMMC Assessor scoping an assessment will work with clients to answer the question: “Do you know where CUI resides and how the data flows through your organization?”</p>\n<p>Manual inventory will fail when you consider that you must count your inventory, manage any license, track the lifecycle of equipment, make sure users keep equipment patched, and know who “owns” each asset. When companies attempt to track this manually the data gets stale.</p>\n<p>Instead IATM requires a living document based on principles of security system engineering. This living document informs vulnerability scans and attempts to access by non-authorized users.</p>\n<h3>IATM and System Security Thinking</h3>\n<p>A living document takes engineering. A systems security thinking approach to IATM requires planning and designing to prevent the loss of an asset. You must understand how to handle and recover from an incident or loss. A CMMC Assessor will want to know if an organization approaches security from a system thinking approach. A CMMC Certified Professional providing consulting services need to embed security first thinking in the design of the systems they create with an OSC.</p>\n<p>In essence you cannot have system security thinking without applying design principles to IATM. At any given time, an Organization Seeking Certification needs to know the users connected to a system and the processes connected on behalf of those users. Patch management logs must be up to date. An OSC needs to track assets from purchase to disposal.</p>\n<h3>ITAM and Asset Lifecycle</h3>\n<p>Applying system security thinking to IATM requires you to consider security starting at blocking drip campaigns from vendors, to product evaluation, through acquisition, lifecycle management, knowledge management and more. Each in scope asset for a CMMC assessment includes business processes around agreements and acquisitions, project specific processes, technical requirements, and technical processes. In a typical lifecycle, an asset lifecycle includes the following phases:</p>\n<ul>\n<li> Enrollment</li>\n<li>Operation</li>\n<li>End-of-life</li>\n</ul>\n<p>NIST-SP-800-160 lays out concepts, development, staging, production, deployment, code review, and support. For a developer contractor asset lifecycle can include code or repos. This requires a different approach to asset lifecycle than an an industrial environment where Operational Technology gets run by specialized assets with an out of date operating sytem. Other in scope organizations may provide services or support staff to the Government. The requirements and constraints of the environments will impact asset lifecycle.</p>\n<p>The asset lifecycle while going through the three stages will focus much more heavily on the people assets. In industrial environments asset lifecycles must also include all of the out of scope operational technology and include how a company secures those assets.</p>\n<h4>Enrollment</h4>\n<p>No matter the constraints of different environments constraints enrollment may involve manual activities performed by IT staff such as assigning and tagging the asset with a serial number and barcode, loading a baseline IT image, assigning the asset to an owner, and, finally, recording the serial number as well as other attributes into a database.</p>\n<p>An admin should manually authorize assigning an asset to an owner. Many Mobile Device Management (MDM) devices or corporate buying programs, such as those through Apple, help to automate the enrollment process and might also include primary location, hardware model, baseline IT image, and owner. This could also mean giving employees access to a code repo or a Kanban board by a project manager. As Certified CMMA Assessor you will collect evidence that makes the relationship between, IATM, asset life cycles, and access control quite evident.</p>\n<h4>Operations</h4>\n<p>As the asset goes through the operations phase, changes can occur. Such changes could include introduction of new or unauthorized software, the removal of certain critical software, or the removal of the physical asset itself from the enterprise.</p>\n<p>When applying system security thinking to IATM we know the changes to an asset must get tracked and recorded. Therefore, asset monitoring, anomaly detection, reporting, and policy enforcement must occur in services, developer, or industrial environments. Tracking change logs is in fact a requirement for Level Two Certification. Systems thinking and asset lifecycles is critical to security and IATM.</p>\n<p>A CMMC Certified Assessor will often rely on systems that monitor change logs and lifecycle data using installed agents that reside on the asset, as well as network-based monitoring systems that scan and capture network traffic. These monitoring systems collect data from and about the assets and send periodic reports to an analytics engine. Each monitoring system sends reports with a slightly differing emphases on aspects of these enterprise assets. Reports get collected regarding installed and licensed software, vulnerabilities, anomalous traffic (e.g., traffic to new sites or drastic changes in the volume of traffic), and policy enforcement status. Once again we have specific CMMC practices that require the collection and reduction of this dats.</p>\n<h4>End-of-Life</h4>\n<p>As an asset reaches the end of its operational life, it goes through activities within the end-of-life phase. These will differ based on the constraints of the in-scope environment. For devices across most organization this includes returning the asset to IT support for data removal. As a CCA you need to know who is responsible for overseeing the decommission of a device. Often organizations may not have an IT department, and this gets conducted by Human Resources or the CEO.</p>\n<p>The unique identifier such as a serial number then gets removed from registration database and other associated databases such as your asset inventory. Finally, the asset is prepared for physical removal from the enterprise facility.</p>\n<p>A CCP or CCA must know the CMMC practices associated with the end of life stage of the asset lifecycle. Especially for CUI assets. The Media Protection domain spells out specific requirements for the destruction of CUI in order to comply with CFR 32 Part 2002, the federal regulation defining CUI.</p>\n<h2>Planning for the Future: Configuration as Code</h2>\n<p>As a company engineers their IT Asset Management system they will want to automate this process as much as possible. For example, this may mean writing a Powershell script to inventory software and checking the current state of patches. Another script may get written to limit roles allowed to specific Teams meetings. Other companies may automate inventory utilizing their vulnerability scanner to count authorized devices.</p>\n<p>Evidence collected through IATM also gets created through the system. A major goal of engineering for automated inventory is to create evidence of trustworthiness of the people and processes with authorized access to CUI. By understanding the practices that secure each asset IATM automates the collection of evidence needed to verify the procedures in a System Security Plan.</p>\n<p>Both the automation of inventory and the collection of data benefit from system security engineering and make up an important process in the overall risk plan of an organization. Overall organizations should move to configuring IATM processes through baseline configurations. configuration as code allows those assets assigned DevOps  roles to monitor and control configuration discrepancies. These efforts all come together in a reference architecture an organization builds to meet the requirements of NIST-SP-800-171 and constraints of the business environment.</p>\n<p>The more we move to a zero trust model that authorizes at the asset level and not the boundary level through configuration as code the more secure we will all be. You still need to count what you protect. Just automate the process as much as possible.</p>\n<hr>\n<p>This is the third post on using NIST-SP-800-160 Systems Security Engineering to meet the requirements of SC.L2-3.13.2 – SECURITY ENGINEERING</p>\n<blockquote>Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.</blockquote>\n<p>First post: <a href=\"https://www.drmacscybersecuritybrief.com/2022/04/13/evaluating-organizations-seeking.html\">Evaluating Organizations Seeking Certifcation: Document Based Requirements to Start a Conversation</a></p>\n<p>Second Post: <a href=\"https://www.drmacscybersecuritybrief.com/2022/04/18/system-security-engineering.html\">CMMC and Systems Security Engineering</a></p>\n<p>image credit: <a title=\"Logistics Specialist Seaman William Swan, from Virginia Beach, Virginia, assigned to the aircraft carrier USS Gerald R. Ford (CVN 78), inventories repairable parts.\" href=\"https://flickr.com/photos/usnavy/49177588228\">Logistics Specialist Seaman William Swan, from Virginia Beach, Virginia, assigned to the aircraft carrier USS Gerald R. Ford (CVN 78), inventories repairable parts.</a> flickr photo by <a href=\"https://flickr.com/people/usnavy\">Official U.S. Navy Imagery</a> shared under a <a href=\"https://creativecommons.org/licenses/by/2.0/\">Creative Commons (BY) license</a></p>\n",
        "date_published": "2022-04-20T10:50:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2022/04/20/cmmc-asset-inventory.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2022/04/18/system-security-engineering.html",
        "title": "System Security Engineering and CMMC",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2022/7b8bf4de02.jpg\" width=\"600\" height=\"401\" alt=\"three Greek philosopher busts\" />\r\n<p>Every organization has a philosophy behind their system security plan.</p>\n<p>These may range from an idea that, “Compliance is not security,” to “DFARS is an unfunded mandate, “ or ” “CMMC did this to me.”</p>\n<p>Other organizations may have their SSP reviewed on a quarterly timeline, and they have biweekly security meetings to analyze any changing threats or to address open items in a plan of action. Even with no full time IT staff the CEO may have made security a central system principle. Another organization may be moving their technology to designs based zero-trust architecture.</p>\n<p>These leaders made a philosophical choice.</p>\n<p>The organizations they lead have designed a security program explicitly or implicitly utilizing the principles laid out “NIST-AP-800-160 Systems Security Engineering Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems” published by NIST.</p>\n<h2 id=\"philosophy-and-cybersecurity\">Philosophy and Cybersecurity</h2>\n<p>Choosing a design  such as zero trust and then applying systems thinking  is a philosophical choice. Apathy, or willful ignorance, is also a philosophical choice. Both will impact the assets and opportunities for an organization.</p>\n<p>When evaluating whether to adopt or change a computing environment to meet the requirements of NIST-SP-800-171  a company needs to consider the impact to business outcomes at every stage of the system lifecycle and the processes that lead to profits.</p>\n<p>A large company with contracts across many different federal agency may choose a hybrid deployment where users access assets in the cloud, servers and software somewhere else,  but any software handling authorization runs “onprem,” a server located at the business and maintained by IT.</p>\n<p>Another company may sell software and they connect to a cloud through VDI. No matter the deployment each company must meet the same security requirements. Everyone must demonstrate compliance with NIST-SP-800-171 through a CMMC assessment. Applying systems thinking ensures that when a system or asset gets authorized, we can trust the security.</p>\n<h3 id=\"systems-thinking\">Systems Thinking</h3>\n<p>Systems thinking is a lifecycle approach to examine each stage as contributing to an overall goal. Usually this goal is a business output that should result in a profit after margins get considered. Systems thinking leads to the  development of  a common mindset for any system.</p>\n<p>Systems thinking drives outcome-oriented results and utilizes an iterative engineering process to deal with the complexity of business. Systems engineering, driven by this thinking, is data- and analytics-driven to create metrics to inform decision making. When comparing cloud, on-prem, or hybrid environments, for example, a company needs to consider the impact on all other systems within the organization.</p>\n<p>In turn, regardless of choice in environment, we must consider how any asset impacts security while also embedding requirements at each stage of the asset or system’s lifecycle.</p>\n<h3 id=\"system-security-engineering\">System Security Engineering</h3>\n<p>Systems Security Engineering, when layered on top of engineering systems, creates a “system of systems” that helps to increase the “trustworthiness” that an organization meets the 320 security requirements in the 110 practices of NIST-SP-800-171.</p>\n<p>Basically the security concerns of any system and the assets that make up those system get integrated into the technical and nontechnical processes. Security becomes part of the philosophy built into all systems. This in turn leads institutionalizing of security and the use of security as a proactive contributor, and not just a cost, to the business outcomes.</p>\n<h3 id=\"lifecycle-of-system-security-engineering\">Lifecycle of System Security Engineering</h3>\n<p>Regardless of the chosen computing environment a design philosophy requires an organization to establish a lifecycle for their System Security Plan. Like any system the SSP, which lays out how you meet the security requirements of NIST-SP-800-171.</p>\n<p>Through engineering thinking we move the security of a system to an asset from a problem to a solution state while increasing the trustworthiness through deployment.  At each stage an organization analyzes the security impacts to understand the security requirements, collect relevant data, align to business outcomes, and ensure fidelity for deployment.</p>\n<p>A company’s risk-based security plan, acts as a system of systems on systems that integrate with all other systems in a business. Within that system the trustworthiness of evidence that the security requirements of NIST-SP800-171 get tracked in the SSP, or system security plan.</p>\n<p>The SSP needs to be seen as a living document that reflects the security design philosophy while producing evidence of trustworthiness. An organization should consider the SSP and Plan of Action and Milestone on an organizationally defined timeframe such as six months.</p>\n<p>When the time period elapses the system gets evaluated against the security requirements of NIST-SP-800-171 and a POAM gets published and triaged. Once the CMMC rule goes live in DFARS the allowable time on the POAM will not exceed 180 days and can only apply to a limited number of practices.</p>\n<h2 id=\"the-system-security-plan\">The System Security Plan</h2>\n<img src=\"https://cdn.uploads.micro.blog/29546/2022/b3cf76c5cf.png\" width=\"600\" height=\"450\" alt=\"ssp through stages of problem, solution, trustworthiness, and analyze\" />\r\n<p>The SSP must act as a tool in the feedback loop of systems security engineering. You begin by first collecting all the security requirements of different assets. What laws and regulations govern these requirements? You then map, in the instance of complying with 171, how CUI data flows your system and create separation between in scope and out of scope assets. This is the problem context.</p>\n<p>Once organizations have an understanding of assets they can then build out a reference architecture and complete an SSP and  POAM. You implement technical solutions through policy and procedure that align to your design philosophy. This is the solution context</p>\n<p>Following an initial publishing, or an update of the SSP and POAM if a new system is introduced the closed feedback loop kicks in. Having a C3PAO come in to complete a third party assessment adds the trustworthiness component to systems security engineering.</p>\n<h3 id=\"system-security-engineering-and-compliance\">System Security Engineering and Compliance</h3>\n<p>No CMMC practice or assessment objective from NIST-SP-800-171a requires you to utilize system security engineering in efforts to comply with DFARS requirement. Yet companies who apply a security first principle from acquisition security tools to verification of customer receipt will have an easier time working with a C3PAO on a CMMC assessment.</p>\n<p>System security engineering by its nature creates evidence of persistent and habitual application of CMMC practices. Having a plethora of evidence to choose from will help a C3PAO evaluate an OSC on any number of practices.</p>\n<p>System Security Engineering requires organizations to consider their outcomes and constraints. Organizations then create policy to ensure regulation while planning and allocating resources for deployment. The baseline architecture, risks, and mitigation plans get communicated to in-scope people trained as part of the system.</p>\n<p>We can not assess for best practice in cybersecurity. Cloud, on-prem, or hybrid. No one solution rules them all. Instead, we need to engineer for better practices given the local environments and contracting restraints.</p>\n<p>When security becomes a first principle in this cycle everyone wins.</p>\n",
        "date_published": "2022-04-18T09:49:11-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2022/04/18/system-security-engineering.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2022/04/13/evaluating-organizations-seeking.html",
        "title": "Evaluating Organizations Seeking Certifcation: Document Based Requirements to Start a Conversation",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2022/889b697252.jpg\" width=\"600\" height=\"400\" alt=\"\" />\n<p>You do not jump out of a plane without first making sure a parachute works. Yet many Organization Seeking Certification (OSC) want to make a leap of bling faith about their compliance to the practices in the Cybersecurity Maturity Model Certification.</p>\n<p>When an Organization Seeking Certification (OSC) contacts a Certified Third Party Assessor Organization (C3PAO) they will not immediately accept ytheir business. Having someone pay for an assessment when a five minute phone interview can evaluate readiness, or lack there of,  of an organization would lead to unethical profits. Assessments are a tandem jump between the C3PAO and and the OSC. Both parties have a vested interest in knowing the parachute opens and covers all in-scope assets.</p>\n<p>A C3PAO evaluates an organization as much as a OSC evaluates the assessment team they hire.</p>\n<h2>Where should an OSC expect a C3PAO to begin?</h2>\n<p>Scoping. The C3PAO needs to scope the assessment which means they need to understand how you scope your networks and systems and how CUI flows through the assets, people, technologies, and facilities,  that make up your systems.</p>\n<p>For example a C3PAO needs to understand the difference between virtual and physical locations of your assets. Do you have servers, &ldquo;on prem&rdquo; or do employees connect to an enterprise cloud? Can employees share and hold CUI on mobile devices? Do employees at home store and transmit CUI?</p>\n<p>All of these questions impact the annual cost of your engineering and non-engineering costs each year. They determine the cost of a CMMC assessment. In fact no assessment should occur without knowing the difference between the logical and physical locations where in scope and out of scope assets exist.</p>\n<h2>What documents should I have ready?</h2>\n<p>As an OSC you must have a system security plan. You can not have an assessment without one. Yet your documentation needs stretch beyond the SSP. In fact to even begin a CMMC scoping conversation an Organization seeking certification should have the following document based specifications:</p>\n<ul>\n<li>Network Diagrams</li>\n<li>Data Flow Diagrams</li>\n<li>Reference architecture</li>\n<li>Asset Inventory</li>\n<li>Access Control Policies</li>\n</ul>\n<p>These documents will not only explain the difference between your physical and logical techniques of separation used to protect CUI but also identify the owners and maintainers of the assets. As an OSC you  can limit the numbers of assets in scope and reduce the cost of the assessment.</p>\n<p>NIST SP 800-171 Rev 2, which states:</p>\n<blockquote>those organizations may limit the scope of the security requirements by isolating the designated system components in a separate CUI security domain. Isolation can be achieved by applying architectural and design concepts (e.g.,implementing subnetworks with firewalls or other boundary protection devices and using information flow control mechanisms). Security domains may employ physical separation, logical separation, or a combination of both.</blockquoute>\n<p>Basically when considering the logical and physical locations we always want to make sure the separation of assets legally authorized to process CUI. Logical boundaries, &ldquo;set is physically (wired or tirelessly) connected to another asset or set of assets, but software configuration prevents data from flowing along he physical connection path.&rdquo;</p>\n<p>Your data flow diagram will demonstrate how Controlled Unclassified Information moves through your system. This will help you understand how to develop a more detailed network diagram.</p>\n<p>The  network diagram would show all the firewalls that route traffic and only allow authorized assets to connect to the system. An  access control policy identifies the authorized people with a matrix of role based access or other ways of user separation. We include an asset inventory to identify authorized devices. The asset inventory needs to track the software development life cycle of the device and includes information about the device owner and maintainer.</blockquote></p>\n<h2>Why do these documents matter?</h2>\n<p>These documents prove a state of readiness for a CMMC assessment, but your really need to think of them as part of your life cycle approach to proving you implement the 110 security requirements of NIST-SP-800-171.</p>\n<p>Basically you need to develop a systems engineering approach. In fact the most subjective of almost all of the security practices in CMMC revolves around security engineering.</p>\n<h3>SC.L2-3.13.2 – SECURITY ENGINEERING</h3>\n<p><strong>Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.</strong></p>\n<p>ASSESSMENT OBJECTIVES NIST SP 800-171A</p>\n<p>Determine if:</p>\n<ul>\n<li>a architectural designs that promote effective information security are identified;</li>\n<li>b software development techniques that promote effective information security are identified;</li>\n<li>c systems engineering principles that promote effective information security are identified;</li>\n<li>d identified architectural designs that promote effective information security are employed;</li>\n<li>e identified software development techniques that promote effective information security are employed; and</li>\n<li>f identified systems engineering principles that promote effective information security are employed.</li>\n</ul>\n<p>Adjectives and adverbs add a degree of scale to assessment objectives but also subjectivity. What does &ldquo;effective&rdquo; mean? How do we demonstrate to an assessor, as an organization seeking certification we identify and deploy &ldquo;effective information&rdquo; security, techniques, and principles?</p>\n<p>It begins with the document based artifacts that will have specifications proving you identify and deploy effective practices. &ldquo;Effective information&rdquo; architecture relies on technical information but also good project management. For example moving your security plan to a six month or annual cycle where you revisit the SSP and POAM while triaging not met practices during monthly meetings helps to support the technical understanding necessary.</p>\n<p>So many examples of effective information practices exist. So do many more ineffective examples. Of course you must establish security policies, you may develop layered protections so multiple boundaries protect key  architecture. Some organizations place controls as the foundation for their design. Everyone must incorporate security requirements into the system development life cycle. In other words has a devices passed end of life for security patches. Reference architecture contains your network diagrams that delineate physical and logical security boundaries. It will list all the key security assets that protect key boundaries.</p>\n<p>You also need to consider in scope people when developing a systems engineering plan. For example anyone with privileged access, meaning they control security of assets or perform functions on systems others can not need different training on how to deploy secure software. Other employees may do risk awareness training and perform threat models to mitigate risk.</p>\n<p>To provide enough evidence for the depth and breadth for the assessment objectives of this practice you basically need to demonstrate that you have system architecture policy that can act like a guide and explains the architecture. You will include, for example, if you deploy different networks to logically separate in-scope and out of scope assets.</p>\n<h3>SC.L1-3.13.5 – PUBLIC-ACCESS SYSTEM SEPARATION</h3>\n<p><strong>Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.</strong></p>\n<p>ASSESSMENT OBJECTIVES [NIST SP 800-171A]</p>\n<p>Determine if:</p>\n<ul>\n<li>a publicly accessible system components are identified; and</li>\n<li>b subnetworks for publicly accessible system components are physically or logically separated from internal networks.</li>\n</ul>\n<p>Network diagrams will docmument  to a CMMC Certified Assessor that an OSC should provide the necessary logical and physical separation of in-scope and out of scope assets.</p>\n<p>Controlled Unclassified Information takes an authorized legal need to access, store, or transmit. You can not just give access to the public to the CUI nor to the networks on where it gets transmitted and stored. In fact separating public accessible systems, like a company website or public wifi from the servers storing encrypted Federal Contract Information is a level one control. Remember the practices are cumulative . A CCA will assess all level one and level two practices for a Level 2 assessment.</p>\n<p>Often companies will use a cloud enclave for CUI to keep the data stored away from the public. Other companies will create a DMZ, a demilitarized zone, or subnetworks. An OSC may have one subnetwork for employees, one for the public, and one for in-scope employees to transmit and store CUI.</p>\n<p>By providing a C3PAO with a network diagram you provide readiness for your assessment. This also provides evidence that would speak to the  breadth of your your security requirements. A CCA would add to the depth of the coverage by interviewing the people who protect the boundaries.</p>\n<h3>CM.L2-3.4.5 – ACCESS RESTRICTIONS FOR CHANGE</h3>\n<p><strong>Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.\nASSESSMENT OBJECTIVES [NIST SP 800-171A]</strong></p>\n<p>Determine if:</p>\n<ul>\n<li>a</li> physical access restrictions associated with changes to the system are defined;\n<li>b</li> physical access restrictions associated with changes to the system are documented;\n<li>c</li> physical access restrictions associated with changes to the system are approved;\n<li>d</li> physical access restrictions associated with changes to the system are enforced;\n<li>e</li> logical access restrictions associated with changes to the system are defined;\n<li>f</li> logical access restrictions associated with changes to the system are documented;\n<li>g</li> logical access restrictions associated with changes to the system are approved; and\n<li>h</li> logical access restrictions associated with changes to the system are enforced.\n</ul>\n<p>In fact a CCA will assess how an Organization Seeking Certification restricts access to people who can make critical changes to your system.</p>\n<p>Basically in order to have the system engineering in place for an assessment an organization should harden physical security at a uniformed layer. What must any employee or guest do to enter the building. You will need to monitor who comes in and control how they enter. If someone needs access to areas where systems changes can be made you need Follow them while they are there, and document why they are there. These steps must be spelled out in policy and procedures ahead of time. .</p>\n<p>So your access control policy, a key document in getting a conversation started with a C3PAO should, &ldquo;Define, identify, and document qualified individuals authorized to make physical and logical changes.&rdquo; This could include employees or managed service providers whp have access to the organization’s hardware, software, software libraries, or firmware</p>\n<p>Overall before you begin an assessment you need to demonstrate that you implement physical access control that prohibits unauthorized users from gaining physical access to an asset. You may use a key card or key pad entry to enter a server room. Your access controls should not allow regular users to log into security software. Some companies may use software that has  automation with management workflow rules that define tasks such as seeking approval to change a server. A common technique is to use multiple boundaries such as only allowing patched from a specific IP management system but still requiring a manager to authorize execution.</p>\n<p>The network diagram, asset control policy, and asset inventory will all help a C3PAO understand the difference between the logical and physical controls of an OSC&rsquo;s location. These documents will demonstrate how separation gets protected with access control.</p>\n<p>An Organization seeking certification not only must demonstrate their scope and network to a C3PAO but they should also explain how they perform system maintenance control on a system.</p>\n<h3>MA.L2-3.7.2 – SYSTEM MAINTENANCE CONTROL</h3>\n<p><strong>Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.</strong></p>\n<p>ASSESSMENT OBJECTIVES [NIST SP 800-171A]</p>\n<p>Determine if:</p>\n<ul>\n<li>a tools used to conduct system maintenance are controlled;</li>\n<li>b techniques used to conduct system maintenance are controlled;</li>\n<li>c</li> mechanisms used to conduct system maintenance are controlled; and</li>\n<li>d personnel used to conduct system maintenance are controlled.</li>\n<p>These tools do not store or process CUI assets on a system but do &ldquo;diagnostic and repair actions on those systems.&rdquo; Viruses and malware get introduced all the time through bad patching or remote management maintenance tools.</p>\n<p>Companies have flexibility in implementing these requirements but this control illustrates how important asset inventory is when starting a conversation with a C3PAO. You can not approve maintenance tools without knowing what maintenance tools you need.</p>\n<p>Once you know the tools you need you should include the who is in charge of the maintenance and link to a document tracking the software development life cycle, basically when di you add the software, the version, operating system, controls it meets, business function it plays, when it gets updated, and when the software is no longer supported.</p>\n<h2>Scoping Matters</h2>\n<p>The four controls highlighted demonstrate how document based artifacts help to provide the breadth of evidence you utilize to demonstrate you meet the requirements of an objective. Yet these documents also provide a jumping off point for a C3PAO to evaluate an organization seeking certification.</p>\n<p>If a company has not documented the differences between the logical and physical locations of their assets than they can not get a CMMC assessment.</p>\n",
        "date_published": "2022-04-13T13:05:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2022/04/13/evaluating-organizations-seeking.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2022/04/11/cmmc-and-asset.html",
        "title": "CMMC and Asset Inventory",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2022/0f4d52cb9d.jpg\" width=\"600\" height=\"313\" alt=\"\" />\n<p>Asset Inventory will drive your compliance. Whether you rely on the shared responsibility of  zero trust models or protect information at your boundaries, asset inventory drives your security. When determining the cost of both compliance and security asset inventory drives your scoping.</p>\n<p>Asset Inventory Matters.</p>\n<p>You can not protect what you do not count.</p>\n<h2>What should good asset inventory be an inventory of?</h2>\n<p>Before we get there consider your process. How will you count the stuff you want to protect? Once a company gets over 5-10 employees mandatory inventory hurts. A lot. Not only is it time consuming but the data quickly falls out of date.</p>\n<p>Asset inventory needs to be a living document fed by automation and cared for with good policy and procedures. You need a system to automate asset discovery.  You need to collect up to date information on your assets, such as patching or log-ons. Some assets, like computer programs, may come with a software bill of materials that contain important information that gets automated.</p>\n<p>Before you count stuff you must figure out how you will count it but you need to be strategic. For example a company may use their vulnerability scanner to identify assets connected to a system or they may use a spreadsheet and inventory scanners. Just develop a plan that helps to automate as much as possible while considering the many different practices of CMMC.</p>\n<h3>What Goes into Inventory?</h3>\n<ul>\n<li>Unique Indentifier-Each asset needs its own name</li>\n<li>Platform type-Windows, Mac, Server</li>\n<li>Asset Categorization-Type of CMMC asset per scoping guidance</li>\n<li>Admin of asset-Maybe employee or a third party through shared responsibility</li>\n<li>The applications and processes that manage the inventory of this asset</li>\n<li>Network Connections-ways the asset connects</li>\n<li>Regulations-Laws that govern this asset</li>\n<li>Practices/Controls Met-CMMC practices that protect the asset</li>\n<li>Assets role in business</li>\n<li>Contractual Availability-Any rules that spell out access to asset</li>\n<li>Assigned Maintenance-Who maintains asset or third party relationship</li>\n<li>Link to Maintenance Plan</li>\n</ul>\n<p>As <a href=\"https://www.linkedin.com/in/jill-lawson-a520273b/\">Jill Lawson</a> notes you will want to expand the CUI assets to a greater extent and include links to a CUI Management plan:</p>\n<blockquote> that identifies what CUI or CTI is being protected, who has access to it, where is resides at rest, how to dispose it, and the process of notifying the KO if a risk of aggregation of the CUI arises </blockquote>.\n<p>A CUI policy is one of the delta twenty practices that got cut from CMMC 2.0 and is listed as an NFO, an Appendix E of NIST-SP-800-171. As in the government assumes this is something you do. As an NFO control that means, while not assessed it is an expectation that you meet this for compliance with DFARS-7012.</p>\n<p>Source: NIST SP 800-40r4 Guide to Enterprise Patch Management Planning:Preventive Maintenance for Technology</p>\n<p>img: <a title=\"Counting\" href=\"https://flickr.com/photos/129833146@N07/15799162729\">Counting</a> flickr photo by <a href=\"https://flickr.com/people/129833146@N07\">anno.malie</a> shared under a <a href=\"https://creativecommons.org/licenses/by/2.0/\">Creative Commons (BY) license</a></p>\n",
        "date_published": "2022-04-11T11:58:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2022/04/11/cmmc-and-asset.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2022/03/06/how-to-use.html",
        "title": "How to Use the CMMC Level One Assessment Guide",
        "content_html": "<p>Under the Cybersecurity Maturity Model Certification Program a level company who holds federal contract information must complete a self-assessment &ldquo;with an accompanying senior company official\naffirmation&rdquo; every year.</p>\n<h2>Introduction to CMMC Level One</h2>\n<p>CMMC Level One helps to ensure the contractor meets the basic safeguarding requirements for  Federal Contract Information (FCI) specified in FAR Clause 52.204-21. Others can then have added trust to a companies system to protect sensitive data.</p>\n<p>Most companies will keep their entire system secure beyond the baseline of the seventeen requirements of NIST-SP-800-171 included in the level one assessment guide. Level one provides you a staring line and not a finish line.</p>\n<p>In fact, &ldquo;a CMMC Level 1 self -assessment, the assets that process, store, or transmit FCI are considered in scope and should be assessed against the CMMC Level 1 practices.&rdquo; Yet any basic risk based cybersecurity plan should meet the level one baseline.</p>\n<p>FCI is such an umbrella term for any data generated as part of a federal contract most companies will not have level one enclaves. Some companies, those with cleared environments, may have some staff that only need access to FCI. Large multinational corporations may have level one business entities to act as a boundary between divisions that hold Controlled Unclassified Information with export controls and international divisions. Yet for the most part companies should assume their entire system, all the peopl, processes, and technology that get the contract done, fall in a level one scope.</p>\n<h2>Reading the Assessment Guide</h2>\n<p>The CMMC Level One Self-Assessment guide includes an overview of the level one assessment practice, the assessment criteria you use, key operational definitions to use during an assessment, and then a description of each assessment practice and a list of all assessment objectives for each practice.</p>\n<img src=\"https://cdn.uploads.micro.blog/29546/2022/adc0b569f1.png\" width=\"600\" height=\"800\" alt=\"\" />\n<p>When reading the assessment guide you need to understand the role of the assessment criteria. CMMC uses the NIST CMMC definition of an <strong>assessment procedure</strong>. This procedure consists of an <strong>assessment objective</strong> which gets met by using assessment methods that connect to assessment objects, or evidence, to justify the assessment finding. A CMMC practice gets met when all assessment objectives get met. This means your self-assessment needs an assessment procedure for each objective at level one. That means you need 59 assessment procedures. Each procuedure will have 2-3 assessment objects. So in your self-assessment you need to document 120-180 pieces of evidence.</p>\n<p>You choose the methodologies based on which provides the most adequate depth to the assessment objectives. If your examination of document based artifacts, or specifications, will provide the greatest depth focus on that methodology. This focus allows  you to apply greater rigor through a more comprehensive examination of the assessment object. Yet in our example of using document based artifacts the access control policy may not change between a basic and a comprehensive examination. You increase the rigor of the examination and not the amount of evidence.</p>\n<p>Yet you ensure the sufficiency us your evidence by also including coverage from other methodologies. You may not put as strong a focus on assessment objects for other methodologies but you want to ensure you have a preponderance of qualitative and/or qualitative evivence so anyone who read your assessment finding would agree.</p>\n<p>You also ensure the sufficiency of your coverage by deciding on how representaive the evidence is to the assessment objective across the sample. This means you must decide on how your sample sample size. Some times, such as an approved software list, you may include them all. When examining testing data of routers and switches a basic examination may include a representative sample, a more focused examination would triangulate the the asessment finding using other evidence. Finally a comprehensive examination may include checking the settings or procedures for each component.</p>\n<p>If you struggle with deciding on the adaquecy of your depth and the sufficiency of the coverage of your evidence go back to the CMMC assessment practice statement. What is the intent? What evidence best shows you meet this intent for the assessment objective? What methodology? Focus there.</p>\n<img src=\"https://cdn.uploads.micro.blog/29546/2022/c90717657f.png\" width=\"600\" height=\"800\" alt=\"screenshot of annotated pdf\" />\n<p>When reading the CMMC Level One Self-Assessment Guide remember the only prescriptive requirements are the CMMC practice and the determining statements of the assessment objectives that let you know if a practice is met or not met</p>\n<p>References:</p>\n<p><small>CMMC Level 1 Self-Assessment Guide pages are shared by the  CMMC-AB usimng a CMMC-BY license.</small></p>\n",
        "date_published": "2022-03-06T13:55:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2022/03/06/how-to-use.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2022/03/04/what-data-is.html",
        "title": "CMMC Assessment Procedures: When Is Enough Data Enough?",
        "content_html": "<h2>What Data Are In Scope?</h2>\n<p>\nYou are assessing against the 171 standard using the CMMC framework. While practices require data to be separated from authorized and unauthorized users and other controls require compliance with federal regulations you assess against the assessment objectives in the CMMC Assessment Guides.\n</p>\n<p>\nYou do not perform an Assessment of the sovereignty and provenance of data. You will not look for ITAR spillage. This is an assessment against the CMMC practices using the assessment objectives from 171a.\n</p>\n<p>\nYou do not check systems to see if an Organization Seeking Certification followed through on the Incident Reporting requirements. This is not an assessment of compliance with DFARS 7012.\n</p>\n<p>\nNow an assessor will check to see if an access control policy or if a chosen product would meet the requirements of keeping unauthorized users in compliance with export control regulations. If your CUI policy mentions 72 hour reporting requirements than An assessor may check the procedures to ensure organizationally defined times in an incident response plan would meet DFARS requirements as evidence you do what you say.\n</p>\n<p>\nAll of this gets defined in scope. This is not a NIST-SP-800-171a assessment nor a NIST-SP-800-53a assessment. It is a CMMC assessment using the CMMC Level 1 or 2 Scoping and Assessment guides. Any Organization Seeking Certification will have the right to demand they must only comply with the NIST-SP-800-171 standard as presented in the assessment guide. You can not fail, someone, nor do you even assess, if they meet the NFO controls of NIST-SP-800-171 . You perform a CMMC assessment. Period. The conditions of this assessment get finalized during scoping assessments.\n</p>\n<h3>Scoping Matters</h3>\n<p>\nWhat data and systems are in scope gets settled during a scoping pre-assessment. For a level 1 self assessment it is just best to assume your entire system falls in scope given the broad categorization of Federal Contract Information.\n</p>\n<p>Once you know the systems and assets in scope a Certified CMMC Professional can start to help an Organization collect, or they can help as a member of an assessment team. In fact, at this time, a CCP can qualify to take a CCA exam after completing three assessments as a meber of a team.\n</p>\n<h2>\nWhat is an Assessment?\n</h2>\n<p>\nCMMC draws from NIST-SP -800-37 for a definition of Assessment: \n</p>\n<blockquote>The testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization</blockquote>\n<p>\nLet us unpack this a little bit.\n</p>\n<p>First their are the security requirements for the information system or organization. For CMMC this includes the requirements in NIST-SP-800-171.\n</p>\n<p>\nThen you have a desired outcome. This is the governance evidence. Where does the OSC have it written down what should happen. This maybe company policy or software defaults. It maybe in a shared responsibility matrix it may reside in a service level agreement.\n</p>\n<p>\nNext, working backwards, comes \"implemented correctly.\" Here you are checking if the procedures will do what the policy says the company will do. This could be reference architecture or implementation guidelines. Step by step guidelines to ensure the control operates as intended.\n</p>\n<p>\nThen you may interview people to see if they do the do or watch a company test something such as a passowrd lock out after an organization defined number of password attempts.\n</p>\n<p>\nA CMMC assessment never involves any penetration testing. Leave your lockpicks and honeypots at home. A CMMC never involves a CCP running any data discovery tools or analyzing audit logs for potential breeches. A CCP collects or evaluates evidence to make sure audit logs meet the security requirements of 171. This means knowing which secuirty requirements are applicable to which controls.\n</p>\n<h2>What is Applicability?</h2>\n<p>You don't check to see the last time a cloud based MFA tool attended its last training session. Role based training requirements are not applicable to tokens nor to your key boundaries. Now to people who have privileged access the tools keeping data separated at the boundary? Role based training requirements are applicable.\n</p>\n<p>When you conduct a CMMC scoping assessment the CCP and OSC will review the assets. All the assets in the end get scored against 110 requirements but many might get marked as not applicable.\n</p>\n<p>NIST-SP-171a rules break down to each requirement having enough depth and coverage. If any security requirement of a CMMC practice falls in scope than you must meet the rest of the requirements to provide enough depth to ensure the practice gets met.\n</p>\n<p>Once a security requirement falls in scope all the security requirements of that CMMC practice fall in scope.\n</p>\n<p>For example let's take the Maintenance domain. MA.L2.-3.7.5 requirements have you protect CUI when machines go for off site repair. If you simply replace and do not send computers off site for repair this practice and all its assessment objects would get marked not applicable.\n</p>\n<p>If however you allow CUI stored on mobile devices a CCP may look for evidence that employees do not take devices into repair shops for such things as cracked screens. Now all of the determining statements of  MA.L2.-3.7.5 assessment objectives are applicable. \n</p>\n<p>Some Organizations Seeking Certification may seek a variance for specific controls from the 171 baseline. This would mean that  they need to use offsite repair for devices with CUI but for some reason can not meet all the assessment objectives of MA.L2.-3.7.5 . In this case, they would need to ask and receive a variance from the Department of Defense CIO.\n</p>\n<p>\nA CMMC assessor will never test if the variance gets followed. This is not a DFARS assessment. The requirements for a variance are not in NIST-SP-800-171. You may though use a document proving a variance exists as an assessment object to meet the adequacy and sufficiency requirements of the CMMC Assessment Process\n</p>\n<h2>What is an Assessment Procedure</h2>\n<img src=\"https://cdn.uploads.micro.blog/29546/2022/c69455509c.jpg\" width=\"600\" height=\"443\" alt=\"\" />\n<p>\nAs assessment procedure gets broken down into a few parts to ensure the accuracy of the information. This includes the determining statement. This is the assessment objective of what the evidence must show is getting met. This determines traceability of accuracy of the evidence. Without accuracy the depth of the CMMC practice can not get guaranteed.\n</p>\n<p>\nYou link this content to the evidence. This evidence makes up the assessment objects. You must collect enough objects to ensure the determining statements get covered sufficiently. This helps to ensure the breadth of the practice get met.\n</p>\n<p>\nIn terms of assessment objects they come in three flavors:\n</p>\n<h3>What is an Assessment Object?</h3>\n<ul>\n<li>specifications-Document based artifacts that explain, explicitly or implicitly (never leave anything to inference int he system security plan), how the determining statements get met. This includes, \"policies, procedures,security plans, security requirements, functional specifications, architectural designs\" (CMMC, 2022, pg 7).</li>\n<li>mechanisms-the stuff and equipment that makes up your systems. An assessor, for example may check how your patching and update mechanisms work on your antivirus software.</li>\n<li>activities-stuff people have to do to protect systems. This could include holding a table top exercise as part of risk awareness, bimonthly meetings to review the SSP, or your back up plans.</li>\n<li>People who do the activities to ensure the mechanisms meet the specifications. </li>\n</ul>\n<h3>What Are The Assessment Methodologies?</h3>\n<p>\nIn terms of gathering assessment objects you utilize three methodologies. The methodology rounds out the third and final part of the assessment procedure.\n<ul>\n<li>Examine-Touching assessment objects. Usually specifications and document based artifacts such as policies and procedures. This includes HR documents, Acceptable Use Policies, System Security Plans, etc</li>\n<li>Interview-Talking to assessment objects, but call them people. You can have discussions with individuals or groups for clarification, to suss out if procedures get followed, or to collect more evidence.</li>\n<li>Test This means watching the results of an activity or mechanism get performed under specific conditions. For a CMMC assessment this means an in-scoped individual will engage in the activity or mechanism. At no time does a CCP or an Assessor really need access to the CUI stored on a system. You will not test any systems.</li>\n<h2>When is Enough Evidence Enough?</h2>\n<p>\nCyberDi uses a claim, connect, action approach to considering if we have sufficient evidence to meet the breath of coverage necessary for each determining statement or assessment objective. You make a claim against a practice of not or met. You then connect each assessment objectives to enough to ensure someone else would reach the same conclusion reading your report.\n</p>\n<p>\n If you are an CCP helping an Organization prepare you provide actionable feedback that can get added to a Plan of Action that would lead to the practice getting met with enough depth and breadth.\n</p>\n<p>\nWhen determining the adequacy of evidence you need to consider all three assessment methodologies. For some practices you will rely on the governance documents more while other practices will require a focus on the mechanisms. The nature of the control determines how much focus you put on each of the assessment methodologies.\n</p>\n<p>First you ask which of the three methodologies will provide you the greatest depth in ensuring breadth to help ensure the accuracy of of the evidence used in the assessment procedure. You consider if you need a basic, focused, or comprehensive use of the methodology against the assessment objects.\n</p>\n<p>\nOnce you decide on which assessment methods give you the greatest depth you would then increase the chances of making a correct assessment by including evidence from other methodologies but you may not apply the same level of focus to the depth of the assessment. By utilizing a mixture of assessment methodologies, and including both quantitative and qualitative evidence in your report or system security plan you ensure the adequacy of the evidence to prove the accuracy of your claims.\n</p>\n<p>\nReferences:\n</p>\n<small>NIST-SP-800-171a Appendix D</small><br>\n<small>NIST SP-800-37</small><br>\n<small>NIST SP-800-18</small><br>\n<small>Bonner, R. (2002). The Importance of Scoping and Applicability in CMMC. Retrieved from: [defcert.com/the-impor...](https://defcert.com/the-importance-of-scoping-and-applicability-in-cmmc/.) DefCert.</small><br>\n<small>Image Credit Remixed From Bryan Mathers's Anatomy of an Open Badge originally shared with a Public Domain license CC0</small>\n",
        "date_published": "2022-03-04T16:19:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2022/03/04/what-data-is.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2022/02/21/categorizing-inscope-fci.html",
        "title": "Categorizing In-Scope FCI Assets using a CMMC Level One Self-Questionnaire",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2022/69da81a12b.jpg\" width=\"600\" height=\"435\" alt=\"two red buckets for fire prevention\" />\n<p>CMMC 2.0 did not change much for level one beyond moving to a self-assessment model rather than relying on a third party assessor. In fact many companies will end up hiring a Certified CMMC Professional to conduct their self-assessment.</p>\n<p>Level one, under the Cybersecurity Maturity Model Certification Framework, requires companies to self assess against 15 Safeguards in FAR Clause 52.204-21 which get assessed against 17 requirements from NIST-SP-800-171 and 59 assessment objectives from NIST-SP-800-171a.</p>\n<p>Before one can begin a Level One self-assessment you need to conduct a CMMC Level One Scoping assessment.</p>\n<p>Before one can conduct a Level One scoping assessment you need to categorize your FCI, or Federal Contract Information assets.</p>\n<p>Do not think of FCI as something you put in one bucket and your company&rsquo;s data in another bucket. Work towards a baseline of keeping the water clean of malicious intent, deliberate or accidental. regardless of how you categorize the data.</p>\n<p>Only you can prevent dumpster fires.</p>\n<h2>FCI Assets</h2>\n<p>Federal Contract Information (FCI) is any information recieved, created, transmitted, or stored that is the result of a federal contract and not meant for public release.</p>\n<p>FCI,does not get labeled and represents such a broad category of data most companies will simply apply Level One as the baseline for their entire system.</p>\n<p>CMMC level one represents the floor in cybersecurity. Few will have an FCI enclave that separates FCI from data in other systems and processes. Remember a process can involve multiple systems and a system gets made up of different components.We will see exceptions.</p>\n<p>Companies that do level two work or higher may separate an FCI environment by default of carving out a Controlled Unclassified Environment. Many service companies that do Level Three or even Classified work may have a front office that handles all the contracting and  associated with an award.</p>\n<p>Multi-national corporations may have some subsidaries or divsions that are level one and others that are level three.</p>\n<p>Even in these scenarios your risk based security plan should exceed the basic safeguards of FAR-21 if you want to protect your company&rsquo;s intellectual property.</p>\n<p>So when identifying FCI assets in scope it maybe best to not think of individual files or even software but to think about how your company processes, stores, and transmits federal contract information.</p>\n<p>When assets get defined as anything with value that processes, stores, and transmits federal contract information it is easy to see how having your entire system in scope becomes a requirement.</p>\n<ul>\n<li>Process-Assets  that access, enter, edit, generate, change, print and delete FCI in the workflow of your contract</li>\n<li>Store-Simply data at rest like a saved file. You need to protect your data as much as the governments data.</li>\n<li>Transmit-Assets sharing FCI. Remember this can be person to person or software to software (components)</li>\n</ul>\n<h2>How do I identify FCI Assets?</h2>\n<p>Given the advice that one should consider the entire system in scope for FCI how should a contractor go about categorizing FCI Assets?</p>\n<p>Even though the Level One assessment and scoping guides say there are no documentation requirements assessed at level one you should have documentation about your FCI assets.</p>\n<p>You do not need to see your documentation to pass yourself on a self-assessment but you should never be able to pass yourself without good asset management. This requires policies, procedures, and inventory.</p>\n<p>Documentation.</p>\n<p>So to best assess the FCI in your environment you may choose the following set of checklist questions derived from the assessment guide. These questions attempt to elicit all the FCI assets you would need to document across processes, storage, and transmission.</p>\n<h3>Process</h3>\n<p>As you begin to identify the processes that involve FCI you seeo to answer, &ldquo;How does data flow through your company from contract award to conlcusion?&rdquo;</p>\n<p>Some of the FCI assets, such as key boundaries, places that stop unauthorized access, could fit in all categories. These assets got listed under transmission rather than listing them in multiple places. I chose transmission over process thinking risk management.</p>\n<p>Most spillage occurs at the boundaries when data is in transit (and by leaked crednetials through phish but there is no phishing awareness and training requirements at level one. Please do phishing training and turn on MFA). Therefore thinking about your key boundaries (even though they protect data at rest too) as assets  protecting FCI in transmission made sense to me. Feel free to move the questions into any shape or form you want.</p>\n<p>Also remember most level one companies will rely on commercial cloud enterprise software. Much of the FCI asset categorization revolves around knowing your software, the default configurations and how to properly configure it based on your security plan.</p>\n<p>When considering categorizing processes that handle FCI assets you need to answer:</p>\n<ul>\n<li>What people can access FCI?</li>\n<li>What are all the third party apps and software people use...All of them, even people's favorite browser plug-ins?</li>\n<li>Does your list of people identify what systems and processes they can access by identifier or role?</li>\n<li>Do you list the devices that can access your system? Do you know how your enterprise software list devices accessing the system?</li>\n<ul>\n<li>By type of device?</li>\n<li>By specific devices?</li>\n<li>A mix of both?</li>\n</ul>\n<li>Do you have a list of unique identifiers you assign to devices?</li>\n<li>Do you have a list of your external systems' (Microsoft, Google, Salesforce) identification and access management and password policy defaults?</li>\n<li>\n<li>Do you treat FCI different than rest of your data?</li>\n<li>Do you list all external systems you use like your Enterprise Software and Alarm Company?</li>\n<li>Do you list any policies and procedures you have for destroying FCI?</li>\n<li>Do you have a list of you policies and procedures for escorting and logging visitors?</li>\n<li>Do you have a list of all your physical access devices such as keys, and NFC badges?</li>\n<li>Do you have a list of policies and procedures for handing out and collecting devices during hiring and termination?</li>\n<li>Do you have a network diagram?</li>\n<li>Do you have a systems diagram showing how FCI moves (data flow diagram)?</li>\n<li>Do you have a floor plan?</li>\n<li>Do you have an org chart?</li>\n<h2>Store</h2>\nMost companies at level one will use an enterprise cloud storage solution. While most effort will be needed to train employees not to use personal accounts, level one has no training requirements.\n<p>When considering categorizing FCI assets you need to ask:</p>\n<ul>\n<li>Do you have a list of devices and systems that store FCI?</li>\n<li>Do you have a list of people who can access processes that protect stored data?</li>\n<li>Do you have a list of all your enterprise baseline controls for securing and possibly encrypting FCI?</li>\n</ul>\n<h2>Transmit</h2>\nAgain when transmitting FCI your employees, often through accidental internal threats, will cause most issues by using personal accounts. Not knowing the default settings of your Enterprise software is a close second.\n<p>When considering categorizing FCI assets you need to ask:</p>\n<ul>\n<li>Do you have a list of people who can transmit FCI?</li>\n<li>Do you have a list of approved methods for transmitting FCI?</li>\n<li>Do you list individuals allowed to post information to public systems?</li>\n<li>Do you list the components of key internal boundaries</li>\n<li>Do you list all the components that protect communication at key external boundaries?</li>\n<li>Do you list system components vulnerable to malicious code?</li>\n<li>Do you have a list of your current external systems (email, file sharing, etc) software life cycles for all the processes you use?</li>\n<li>Do you list the policies your Enterprise Software uses to scan for malicious code?</li>\n</ul>\n<p>A small business doing a level one self-assessment will inherit responsibility for protecting FCI assets from third party enterprise cloud vendors such as Microsoft Office 365 or Google Workspace. Much of your level one asset management will get determined by how well you can find the terms of service, baseline configurations. You then list any requirements you add to the defaults (turn on MFA please).</p>\n<p>You self-assess the FCI assets against the applicable controls in the CMMC Level One assessment guide. Meaning you would not assess key boundaries like a firewall for documenting physical access devices.</p>\n<p>These questions will only help you categorize Federal Contract Information as it moves through your processes built in your system and when you transmit or store this data. The list of questions should help to identify the type of inventory needed for a level one self-assessment.</p>\n<p>Pleasse do not think each question requires an its own inventory or document. The Netowrk Diagram for example may check off more than five of the prompts listed above.</p>\n<p>As a company self-assessing you need to focus on using Level One to get a baseline measure of your cybersecurity hygiene and use your compliance with FAR Clause 52.204-21  to create a bare minimum for protecting data, both your IP and the Gov&rsquo;s FCI, in your risk based security plan.</p>\n<p>For companies working toward level two CMMC certification if you were honest when calculating a score to upload in SPRS, and it was was below -50 getting to level one first may provide you with direction (just make sure any devices and components at key boundaries meet Level two requirements) before purchasing.</p>\n<p>Do not think of FCI in terms of an enclave or the assets moving through subsystems. Your entire system needs to handle federal contract information</p>\n<p>It is okay if you can not answer these questions yet, but one can not self-assess at level one without scoping. You can not scope until you know how in-scope assets move through your system.</p>\n<p>Count your stuff, Then protect it.</p>\n<p>Otherwise when you go to put out the next fire at work you may grab the bucket full of lubricant oil and not water.</p>\n<p>(P.S. Please turn on MFA)\n(P.S.S. The first P.S is really important)</p>\n<p><small>Img Credit <a title=\"Fire Buckets at Oakworth Station\" href=\"https://flickr.com/photos/atoach/21890042259\">&ldquo;Fire Buckets at Oakworth Station&rdquo;</a> by <a href=\"https://flickr.com/people/atoach\">Tim Green aka atoach</a> is licensed under <a href=\"https://creativecommons.org/licenses/by/2.0/\">CC BY</a> </small></p>\n",
        "date_published": "2022-02-21T16:15:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2022/02/21/categorizing-inscope-fci.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/12/20/many-certified-cmmc.html",
        "title": "Asset Categorization and CMMC",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2021/e2410a984f.jpg\" width=\"600\" height=\"400\" alt=\"\" />\n<p>Many Certified CMMC Professional  (CCP)will find the Configuration Management domain one of the trickiest for organization seeking certification to implement. Yet you have to ensure all employess have secure equipment from the starting line. By spelling out clear rules of the road through policieis and procedures you can ensure all clients</p>\n<p>The 11 practices, six from level 2, three from level 3 and one level five requirement focus on how an organization deploys, sets up and manages systems, devices, software, networks and hardware. Specifically on an organizations ability have a configuration baseline and practices to audit this configuration and introduce changes.</p>\n<h1 id=\"why-configuration-management\">Why Configuration Management</h1>\n<p>A CCP will want to work with clients  to develop configuration management policies and procedures to mitigate security risks. You cannot eliminate vulnerabilities and reduce the costs of systems maintenance without a good configuration management. Every device you give an employee, every network router, and every switch needs to follow specific set up in a consistent manner. A Certified CMMC Professional will needs to work with a client to  manage all changes. This will require organizations seeking certification to develop defined change control process.</p>\n<p>Imagine if you allowed employees to simply go online and order a laptop. How would you know what Operating Systems get used? Will you know if they update the computer? Which anti-virus software comes installed?</p>\n<p>Configuration management limits these issues. A company must have standard baseline image, not just for devices but for all the endpoints. Your configuration management and change logs need to track the software version, any hardware or software installed, ports that get open or blocked, and protocols for vulnerability scanner that the user does not control.</p>\n<p>Configuration Management takes deep technical knowledge. A CCP will need to work with software documentation, vulnerability scanning software, STIGS, Reference architecture from an external service provider, or often a checklists of steps to follow</p>\n<p>In fact, talented CCPs will see configuration more as a life cycle approach rather than a simple security management checklists. This lifecycle moves a system from the concept of operations through the vulnerability scanning, change management, operations, and decommissioning. As a system matures the people in a company will come and go. New technologies will emerge. A CCP can help clients address these programs by ensuring they have a consistent change management policy through the lifecycle of the system that boils down to system hardening, change management, and change management processes.</p>\n<p>You cannot accept the defaults. Rarely will products come out of the box with secured to a a NIST-SP-800-171 baseline. A CCP will work with clients to ensure service packs get updated, unnecessary features get deactivated, account provisioning stays in compliance, and all firewalls and automatic updates get set up. If an organization seeking certification inherits many of these practices from an external service provider such as an MSP or IT form the CCP will need to review the shared responsibility matrix.</p>\n<p>The configuration management lifecycle requires a focus on change management. You must ensure systems remain stable and employees cannot make changes without privileged access. As a CCP make sure clients include change management in their configuration policies. An Organization Seeking Certification must have a formal review proposed for all changes. This should include regularly scheduled reviews and an emergency process for installing critical patches. Only these proposed changed should get made. Finally, a CCO should ensure a client as procedures in place to re-assess their baseline setting and ti evaluate if it should change.</p>\n<p>In order for these first two elements of configuration management lifecycle to occur a CCP will need to assist companies in tracking the process through change logs. This includes having a change request process, evaluating the risk of change, an approval process, testing the change, evaluating if employees need new training, implementing a baseline, validating the baseline, and then finally documenting the change.</p>\n<p>Many of the changes to a system happen through software updates and patches released by a vendor. Therefore, change management processes must address how a company handles patch management. A CCP should work with organizations seeking certification to ensure the configuration management policy addresses patching.</p>\n<p>Configuration Management provides recognized, standardized, and established benchmarks that spell out the procedures a company must follow to secure their systems and metrics.</p>\n<h1 id=\"practices-of-the-configuration-management-domain\">Practices of the Configuration Management Domain</h1>\n<p>The following security requirements fall under the Configuration Management family:</p>\n<h2 id=\"341-establish-and-maintain-baseline-configurations-and-inventories-of-organization-information-systems-including-hardware-software-firmware-and-documentation-throughout-the-respective-system-development-life-cycles\">3.4.1 Establish and maintain baseline configurations and inventories of organization information systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.</h2>\n<p>A company must have a baseline approved by management to meet the assessment objectives under this practice. A CCP will have to work with their clients to ensure the\nbaseline configurations get developed, documented, and maintained for each syetsm. This means identifying all the systems that handle FCI or CUI, monitoring these endpoints, and developing these endpoints so the baseline configuration before meets 171 compliance before user access.</p>\n<p>This requires a system development life cycle spelled out in your configuration management plan. You must provide the foundation for the successful development, implementation, and operation of company information systems.</p>\n<p>A Certified CMMC Professional has an ethical obligation to include staff on the team, or let who possess security expertise and skills to ensure that needed security capabilities are effectively integrated into configuration management utilizing best practices in reference architecture.\nSecurity awareness and training programs can help ensure that individuals having key security roles and responsibilities have the appropriate experience, skills, and expertise to conduct assigned system development life cycle activities. The effective integration of security requirements into enterprise architecture also helps to ensure that important security considerations are addressed early in the system development life cycle and that those considerations are directly related to the company’s business processes. This process also enables the integration of the information security architecture into the enterprise architecture, consistent with company risk management and information security strategies.</p>\n<p>The configuration management domain lives and dies based on good document-based artifacts. As a Certified CMMC Professional working with clients to integrate a lifecycle approach you may have to assist clients in developing or curating specifications such as:</p>\n<ul>\n<li>configuration management policy</li>\n<li>procedures addressing the baseline configuration of the information system</li>\n<li>procedures addressing configuration settings for the information system</li>\n<li>configuration management plan</li>\n<li>security plan</li>\n<li>enterprise architecture documentation</li>\n<li>security configuration checklists</li>\n<li>evidence supporting approved deviations from established configuration settings</li>\n<li>change control records</li>\n<li>information system audit records</li>\n<li>information system design documentation</li>\n<li>information system architecture and configuration documentation</li>\n<li>information system configuration settings and associated documentation</li>\n<li>change control records</li>\n<li>other relevant documents or records</li>\n</ul>\n<p>The technical members of a Certified CMMC Professional’s team will need to work closely with employees who have configuration management responsibilities, security configuration management responsibilities, and network adminsitrators. Again for many Organizations seeking certification this maybe an IT company or Managed Service Provider with these roles. In this case you must also ensure the shared responsibility matrix or teaming agreements handle baseline configuration, change processes, audit logs, and patching procedures.</p>\n<p>A CMMC assessor will want to see these employees or service providers conduct the following tests:</p>\n<ul>\n<li>processes for managing baseline configurations</li>\n<li>automated mechanisms supporting configuration control of the baseline configuration</li>\n<li>processes for managing configuration settings</li>\n<li>automated mechanisms that implement, monitor, and/or control information system configuration settings</li>\n<li>automated mechanisms that identify and/ or document deviations from established configuration settings</li>\n</ul>\n<h2 id=\"342-establish-and-enforce-security-configuration-settings-for-information-technology-products-employed-in-organization-information-systems\">3.4.2 Establish and enforce security configuration settings for information technology products employed in organization information systems.</h2>\n<p>This practice requires companies to bake security into their configuration management plan. A CCP must work with their clients to ensure assets only have features and capabilities that allow them to do their job. A good configuration management policy reflects the most restrictive settings that still allow a business to operate. Like any element of configuration management changes to security tools must get approved, tested, and documented.</p>\n<p>Once again a CCP will need to ensure a company has strong document based artifacts to meet the assessment objectives of this practice. These specifications can include:</p>\n<ul>\n<li>configuration management policy</li>\n<li>procedures addressing the baseline configuration of the information system</li>\n<li>procedures addressing configuration settings for the information system</li>\n<li>configuration management plan</li>\n<li>enterprise architecture documentation</li>\n<li>information system design documentation</li>\n<li>information system architecture and configuration documentation</li>\n<li>security configuration checklists</li>\n<li>evidence supporting approved deviations from established configuration settings</li>\n<li>system audit records</li>\n<li>change control records</li>\n<li>other relevant documents or records</li>\n</ul>\n<p>A CMMC Assessor will want to see interview the same people and observe many similar tests for this practices as well as other practices in this domain.</p>\n<h2 id=\"343-track-review-approvedisapprove-and-audit-changes-to-information-systems\">3.4.3 Track, review, approve/disapprove, and audit changes to information systems.</h2>\n<p>To ensure a company meets this practice a Certified CMMC Professional should first identify the IT leadership employees who act as a review board. All changes must get approved an d logged to have enough evidence for the assessment objectives. By building in a set time for the review board to meet you can help clients meet the requirements. You also need to make sure these changes get documents in IT asset management policies.</p>\n<p>Numerous changes must get documented. These include modifications to hardware, software, or firmware components and configuration settings. The change process cannot interfere with information system operations. Thus testing needs to reflect company security policies and procedures. They get by information system security policies and procedures default features. Overall a company want to protect  the specific health, safety, and environmental risks.\nOperational systems may need to be taken off-line, or replicated to the extent feasible, before testing can be conducted. If information systems must be taken off-line for testing, the tests are scheduled to occur during planned system outages whenever possible. If testing cannot be conducted on operational systems, organizations employ compensating controls (e.g., testing on replicated systems).\nChanges to information systems should be reviewed and approved by company management prior to implementation.\nBeyond the evidence collected for the other practices in this domain a CCP may also want to consider:</p>\n<ul>\n<li>change control records</li>\n<li>information system audit records change control audit and review reports</li>\n<li>agenda /minutes from configuration change control oversight meetings</li>\n<li>other relevant documents or records</li>\n</ul>\n<p>Beyond the other individuals interviewed to gather evidence a CCP will want to speak with or help to establish a change review board. A CMMC assessor will want to observe tests on processes for configuration change control and automated mechanisms that implement configuration change control.</p>\n<h2 id=\"344-analyze-the-security-impact-of-changes-prior-to-implementation\">3.4.4 Analyze the security impact of changes prior to implementation.</h2>\n<p>You cannot simply introduce new software and changes to a company’s IT system and information security responsibilities such Information System Administrators, Information System Security Officers, Information System Security Managers, and Information System Security Engineers. Once again for many organizations seeking certification this will involve including external service providers that do IT and security. No one department or person could track the endpoints and software across an entire organization.</p>\n<p>When a change gets proposed a process or  control board must evaluate the security impact. The review process must have clear testing procedures. Many manufacturers will have a change control board or process as part of their Quality Management System for other certifications such as ISO 9001. A CCP should work with a client, who may not have dedicated IT staff, to meet these requirements using already existing processes. Tracking IT changes using the same process will save companies money and increase security.</p>\n<p>A CMMC assessor will want to ensure the effectiveness of theses tests. They must consider if the changes impact compliance with other 171 requirements. All configuration changes should then get tested, validated, and documented on a subset of devices or a staging environment before installing them on the operational system.</p>\n<p>This again falls to the importance of the change review board and the importance of clear policy and repeatable procedures with a plan to monitor, meet, and document testing and changes.</p>\n<h2 id=\"345-define-document-approve-and-enforce-physical-and-logical-access-restrictions-associated-with-changes-to-the-information-system\">3.4.5 Define, document, approve, and enforce physical and logical access restrictions associated with changes to the information system.</h2>\n<p>Zero trust means little once a malicious or unintentional internal threat has access to your servers and networks. You will need to track and log physical access to key physical areas where changes to the system can get introduced. This will often involve a key card and audit logs. As a CCP work with organizations seeking certification to ensure these areas get clearly marked and penalties for unauthorized access get spelled out in an employee handbook.</p>\n<p>For logical access you must consider the implications and how to track who can make security changes to a client’s boundaries. Modern identity management software  can require approval, set time bound windows, send notifications to the control board, have role based access and many more features to monitor changes to logical boundaries.</p>\n<p>For both physical and logical restrictions always ensure to keep the practices of least privilege in mind.</p>\n<p>Beyond the other document-based artifacts already collected for this Domain a CCP must also consider:</p>\n<ul>\n<li>logical access approvals</li>\n<li>physical access approvals</li>\n<li>access credentials</li>\n<li>change control records</li>\n<li>information system audit records</li>\n<li>other relevant documents or records</li>\n</ul>\n<p>A CMMC assessor will want to interview employees with logical and physical access. They will need access to employees with information security responsibilities and network administrators.</p>\n<p>The assessor will want to see these employees perform automated mechanisms supporting/ implementing/enforcing access restrictions associated with changes to the information system</p>\n<h2 id=\"346-employ-the-principle-of-least-functionality-by-configuring-the-information-system-to-provide-only-essential-capabilities\">3.4.6 Employ the principle of least functionality by configuring the information system to provide only essential capabilities.</h2>\n<p>An employee of a client will not need minesweeper and every Instagram photo filter on their computer in order to do their job. Simply put an Organization Seeking Certification must configure technology so employees only have functions need to keep the system and business operational. A CCP will need to work with a client to identify and remove/disable applications, ports, protocols, services and settings on your systems. This often means imaging machines to remove or add on to default settings.</p>\n<p>If a client a CCP works with does not use VOIP than disable the ports VOIP uses.</p>\n<p>A CCP will utilize a variety of evidence for document-based artifacts. They should note an inventory of ports gets included in the System Security Plan. ACCMC assessor will want to observe a test on the processes prohibiting or restricting functions, ports, protocols, and/or services</p>\n<h2 id=\"347-restrict-disable-and-prevent-the-use-of-nonessential-programs-functions-ports-protocols-and-services\">3.4.7 Restrict, disable, and prevent the use of nonessential programs, functions, ports, protocols, and services.</h2>\n<p>This practice relates closely to 3.4.6, and like many relies on strong IT Asset Management. A company, however, must explicitly define how they limit ports and protocols necessary to provide the service needed for continuation and security. You may disable FTP, for example,  or remove applications from a device before access Once again this inventory of ports and programs must get included in the SSP.</p>\n<p>In fact companies should consider disabling unused or unnecessary physical and logical ports/ protocols such as Universal Serial Bus (USB), File Transfer Protocol (FTP), and Hyper Text Transfer Protocol (HTTP on information systems to prevent unauthorized connectios\nAs a CCP you may have to help an organization seeking certification evaluate companies that  can utilize network scanning tools, intrusion detection and prevention systems, and end-point protections. Firewalls and host-based intrusion detection systems to identify and prevent the use of prohibited functions, ports, protocols, and services can also help mitigate much risk.\nAs a CCP help clients gather evidence from typical document-based artifacts that include.</p>\n<ul>\n<li>configuration management policy</li>\n<li>procedures addressing least functionality in the information system</li>\n<li>configuration management plan</li>\n<li>security plan</li>\n<li>nformation system design documentation</li>\n<li>information system configuration settings and associated documentation</li>\n<li>specifications for preventing software program execution</li>\n<li>security configuration checklists</li>\n<li>documented reviews of functions, ports, protocols, and/or services</li>\n<li>change control records</li>\n<li>information system audit records</li>\n<li>other relevant documents or records</li>\n</ul>\n<p>A Certified CMMC Professional will need to work with employees with responsibilities for reviewing functions, ports, protocols, and services on the information system and network administrators. Together make sure observable test can get performed on:</p>\n<ul>\n<li>processes for reviewing/disabling non-secure functions, ports, protocols, and/or services</li>\n<li>automated mechanisms implementing review and disabling of non-secure functions, ports, protocols, and/or services</li>\n<li>processes preventing program execution on the information system</li>\n<li>processes for software program usage and restrictions</li>\n<li>automated mechanisms preventing program execution on the information system</li>\n<li>automated mechanisms supporting and/or implementing software program usage and restrictions</li>\n</ul>\n<h2 id=\"348-apply-deny-by-exception-blacklist-policy-to-prevent-the-use-of-unauthorized-software-or-deny-all-permit-by-exception-whitelisting-policy-to-allow-the-execution-of-authorized-software\">3.4.8 Apply deny-by-exception (blacklist) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting policy to allow the execution of authorized software.</h2>\n<p>This practice builds on top 3.4.7 but requires companies to maintain a list of approved software and a list of software denied to all or requiring an exception.\nIn fact many organizations go beyond the minum of this control and organizations verifying the integrity of approve-listed software programs usingcryptographic checksums, digital signatures, or hash functions. These certificates help to verify versions and secure updates.</p>\n<p>Between maintaining an approved list and a not-authorized list, the denial list provides stronger protection. Policies alos get deployed to  prevent certain types of software from being run on the company’s systems such as games. A CCP will need to ensure a client checks these policies s by periodic audit.</p>\n<p>Beyond the usual document based artifacts of this domain a CCP will want to help an organization seeking certification organize evidence from:</p>\n<ul>\n<li>information system configuration settings and associated documentation</li>\n<li>list of software programs not authorized to execute on the information system</li>\n<li>list of software programs authorized to execute on the information system</li>\n<li>security configuration checklists</li>\n<li>review and update records associated with list of unauthorized software programs</li>\n<li>review and update records associated with list of authorized software programs</li>\n<li>change control records</li>\n</ul>\n<p>Employees with information security responsibilities and network administrators will need to know how to demonstrate tests on</p>\n<ul>\n<li>process for identifying, reviewing, and updating programs not authorized to execute on the information system</li>\n<li>process for identifying, reviewing, and updating programs authorized to execute on the information system</li>\n<li>process for implementing blacklisting automated mechanisms supporting and/or implementing blacklisting</li>\n<li>process for implementing whitelisting automated mechanisms supporting and/or implementing whitelisting</li>\n</ul>\n<h2 id=\"349-control-and-monitor-user-installed-software\">3.4.9 Control and monitor user-installed software.</h2>\n<p>As a Certified CMMC professional just make sure companies disable user installed software on in scope systems. Remember users should not have privileged or admin access on machines that connect to your network and all privileged users always require MFA authentication. This will allow a company to control unapproved software.</p>\n<p>Policies must fully describe allowed installations and procedures to check that for policy violations. These polices may want to have very stringent exceptions for installing software, especially on the devices of privileged users.</p>\n<p>A CMMC Assessor will not only want to review these policies and procedures but they will want to see employees perform tests on processes governing user-installed software on the information system an automated mechanisms for alerting personnel/roles when unauthorized installation of software gets detected.</p>\n<p>If a company takes the time to put down a clear pathway for configuration management we can help to protect the confidentiality of information. Just remember while we need to get to the finish line one should approach it more as conditioning. Once you have your baseline configured get back to tthe starting line and review the deployment as you maintiain the overall cyber health of a company.</p>\n<p>&ldquo;Starting Line&rdquo; by Phil Roeder <a href=\"https://flickr.com/photos/tabor-roeder/26007099597\">flickr.com/photos/ta&hellip;</a> is licensed under CC BY</p>\n",
        "date_published": "2021-12-20T14:39:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/12/20/many-certified-cmmc.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/12/01/overview-of-cmmc.html",
        "title": "Overview of CMMC 2.0",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2021/a7e98d8093.jpg\" width=\"600\" height=\"400\" alt=\"\" />\n<p>Ben Franklin once quipped, &ldquo;“When you are finished changing, you are finished.”</p>\n<p>Nothing could ring more true in cybersecurity. Frameworks need to live and breath to respond to evolving threats.</p>\n<p>On November 4, 2021 the Department of Defense unveiled an update to the the Cybersecurity Maturity Model Certification framework to streamline compliance, increase flexibility, and lower cost for manufacturers and IT providers.</p>\n<h2 id=\"tldr\">TLDR</h2>\n<ul>\n<li>Reduce number of levels from Five to Three</li>\n<li>Return to NIST as maintainer of all documents</li>\n<li>Allow level one self-assessments</li>\n<li>Self-assessments require senior level affirmation</li>\n<li>Level Two is Old Level Three and NIST SP800-171 baseline for Controlled Unclassified Information</li>\n<li>Level Two is bifurcated into priortized and non-prioritized contracts</li>\n<li>Prioritized contracts require third party assessments.</li>\n<li>Return of limited time bound POAMS</li>\n<li>Return of limited approved waivers</li>\n</ul>\n<h2 id=\"reduced-levels\">Reduced Levels</h2>\n<p>CMMC 1.0 had five levels. Level One aligned to seventeen controls from NIST SP-800-171 to meet the fifteen safeguards required by FAR 52.204.21 for Federal Contract Information. Level Three, required for CUI, aligned to 110 controls from NIST SP-800-171 and 20 additional controls. Level Five would align to practices selected from NIST SP-800-172.</p>\n<p>This model did not work for maturity given the different baselines required for sensitive data. One would not seek a level two certification. In fact, DoD said no bids would even ask for a level two. We also had no classes or assessments for level two or four.</p>\n<p>Yet CMMC 1.0 had cummulative levels. Meaning you had to meet all of level one and two to meet level three. This pushed some CUI requirements down to level two which made no sense given lvel three served as the NIST SP-800-171 baseline.</p>\n<p>CMMC 2.0 removes the ill-fitted maturity requirements.</p>\n<img src=\"https://cdn.uploads.micro.blog/29546/2021/abda828e77.png\" width=\"600\" height=\"711\" alt=\"\" />\n<img src=\"https://cdn.uploads.micro.blog/29546/2021/2ee5c3b7d8.png\" width=\"600\" height=\"435\" alt=\"\" />\n<h2 id=\"return-of-national-institute-of-standards-and-technology\">Return of National Institute of Standards and Technology</h2>\n<p>CMMC 1.0 tried to address some of the shortcomings of NIST-SP-800-171. In fact, early on the AB, rumor has it, tried to remove requirements until NARA/ISOO reminded them that the CUI program exists in law and NIST-SP-800-171 provides the baseline. They could only add and not remove.</p>\n<p>CMMC 1.0 added twenty additional practices, often referred to the Delta 20s, and made the assumed controls of NIST-SP-800-171 around policy and procedures (an assumption of practices Non Federal Organizations (NFO) just do..they don&rsquo;t) explict in the process maturity measures.</p>\n<p>CMMC 2.0 removes anything unique to CMMC and returns us to just NIST-SP-800-171. Moving forward only NIST will change the requirements. We will see many of the delta 20s making a return, and while policies and procedures do not get explicitly assessed you can not pass an assessment without policy and procedures.</p>\n<img src=\"https://cdn.uploads.micro.blog/29546/2021/bae6427b0a.png\" width=\"600\" height=\"264\" alt=\"\" />\n<h2 id=\"timeline-and-rulemaking\">Timeline and Rulemaking</h2>\n<p>In order to allow for third party assessments under the Defense Federal Acquisition Supplemental regulations the Department of Defense (more likely their lawyers) decided we need to codify this in federal law.</p>\n<p>This requires a &ldquo;harmonization&rdquo; of rulemaking. First CFR 32, which governs the CUI program needs revision. Then CFR 48, which enables DFARS will get revised.</p>\n<p>Federal rule making takes a long time and the DoD estimates suggest 9-24 months. Before contractors breath a sigh of relief they should realize that a 24 month timeframe speeds up the original intent of the five year pilot program.</p>\n<p>Once the rule making process gets complete no pilot program will get unrolled because compliance with 171 required since 2017. The rule changing just empowers third party assessments under the DFARS clauses.</p>\n<h2 id=\"more-flexibility\">More Flexibility</h2>\n<p>CMMC 1.0 did not allow for any open assessment objectives. You had to meet all 305 to get a level three certification.</p>\n<p>CMMC 2.0 allows for a set of limited and timebound POAMs.</p>\n<p>Before you jump for joy and think you can couch really expensive stuff as an ever ending POA with a never reached milestones you should understand the caveats.</p>\n<p>First you need a minimum SPRS score self-assessing or having a third party assess you against the 171a methodology. A cut score still exists. They have lowered the threshold. How far? We do not know, but it won&rsquo;t be low.</p>\n<p>You also can not POAM all the requirements and objectives. 171a breaks scores down into 5, 3, or 1. While official guidance did not get released officials have hinted no five pointers in the POAM. The most expensive stuff gets five points.</p>\n<p>You also get 180 days to rectify the POAM. This flexibility saves you nothing. In fact trying to address  a five point control in three months may cost you a ton more than good planning.</p>\n<h2 id=\"what-does-it-mean\">What does it Mean?</h2>\n<p>For organizations seeking certification, little. Keep growing the SSP and shrinking the POAM. We always had 171 as a baseline and that did not change. The Interim DFARS clauses 7019 and 7020 did not go away. DFARS clause 7012 did not go away. If you have CUI or FCI on your systems the people, processes, and technology within scope still fall in scope.</p>\n<p>For CEO or CIO of organization seeking certification the affirmation requirements increase your personal liability under Fair Clause Claim. In fact both the DoJ and the DoD have highlighted increased focused on the whistleblower elements of the Fair Claims Act. You may find your lawyers, or more likely your Prime&rsquo;s lawyers demanding a third-party assessment even if you do not hold CUI on a prioritized contract.</p>\n<p>Nobody knows what prioritized contracts mean. You cannot plan on what level of level two you will fall under. Plan your self-assessment as if a third-party assessor will come in and verify your results.</p>\n<p>If you wanted to join the ecosystem as a Certified CMMC Professional CCP or a CMMC Certified Assessor you may find the market grew instead of the logical conclusion the market contracted with self-assessments.</p>\n<p>It makes sense for the DoD to press pause on third party assessments. They have no idea how big the DIB is but they knew the majority would fail a level one, forget a level three assessment. Why make companies pay for a test you know they will fail?</p>\n<p>Yet the market for CCPs and CCAs may have grown. While the DoD may not require a third-party assessor you can bet many a Prime contractor will if you want to remain in their supply chain. Further the number of companies who need to self-assess will require more support.</p>\n<p>The number of companies needing a third party assessor remains high. The DoD has pinned this number on 30,000-40,000 and the CMMC-AB places it higher. Further, current thinking, likely to change, has any level three company who wants an assessment by the Government against the upcoming tailored controls from 172 must first have a level two assessment from a C3PAO against 171.</p>\n<p>In the end, the baseline of NIST-SP-800-171 did not change. Use the next nine to 24 months to grow the SSP and shrink the POAM.</p>\n<p><a title=\"Change\" href=\"https://flickr.com/photos/mattwieve/14752609983\">Change</a> flickr photo by <a href=\"https://flickr.com/people/mattwieve\">Matt Henry photos</a> shared under a <a href=\"https://creativecommons.org/licenses/by/2.0/\">Creative Commons (BY) license</a></p>\n",
        "date_published": "2021-12-01T13:00:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/12/01/overview-of-cmmc.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/11/11/no-cmmc-hot.html",
        "title": "No CMMC Hot Takes. Just Take the Time for Some Slow Reads",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2021/a2b9a776b9.jpg\" width=\"600\" height=\"400\" alt=\"\" />\n<p>Inbox overflowing with email  invitations to CMMC.20 webinars? Every consultant and software service promising to give you the most up to date info your company can not do without?</p>\n<p>You can do without. I offer no hot takes.</p>\n<p>Just some slow reads.</p>\n<p>If you really want to get prepared start reading. Congress got it wrong. Cybersecurity does take reading. A ton of reading.</p>\n<p>We know CMMC 2.0 will not kick in for 9-24 months on government clocks. I have no idea how long that will last in real time or dog years.</p>\n<p>Until then read.</p>\n<p>Evaluate the System Security Plan (SSP).</p>\n<p>Read more.</p>\n<p>Throw out your poorly templated  SSP and start over.</p>\n<p>Read more.</p>\n<p>Finalize the SSP and write your POAM.</p>\n<p>Read more.</p>\n<p>Have set meetings to address POAM. Revist SSP in six months.</p>\n<p>Read more.</p>\n<p>Grow the SSP and Shrink the POAM.</p>\n<p>If you do not want to do the reading hire an expert. You can try to do cybersecurity without reading. You can also try accounting without math.</p>\n<p>So instead of beating you over the head with one more CMMC 2.0 webinar I offer you my top ten hit reading list for 7012 compliance.</p>\n<p>Reading and Time. My turnkey easy button solution to CMMC 2.0</p>\n<ol>\n<li>FIPS-199/200 - The basic controls. Only thing gov truly mandates</li>\n<li>SP 800-30 and 39 -learn the risk management process</li>\n<li>SP 800-37 - Do risk management</li>\n<li>SP 800-18 - How to write an SSP</li>\n<li>SP 800-60 &amp; 70 - Mapping data flows and info system</li>\n<li>SP 800-53 - 1200 controls in the catalog. Spend a hot minute here.</li>\n<li>SP -800-171 -Learn the derived controls selected from 53 that combined with the basic controls from FIPS that you must have on nonfederal system (don&rsquo;t skip Appendices)</li>\n<li>SP 800-115 - How do we test controls\n9 SP 800-162 How to speak engineer to humans</li>\n<li>SP 800-137 - continuous monitoring guideline</li>\n</ol>\n<p>Bonus reading: SP 800-161 Supply chain risk management</p>\n<p>img credit: &ldquo;A Shot of Ice and Fire&rdquo; by ElleFlorio <a href=\"https://flickr.com/photos/elle_florio/27926246623\">flickr.com/photos/el&hellip;</a> is licensed under CC BY-SA</p>\n",
        "date_published": "2021-11-11T13:30:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/11/11/no-cmmc-hot.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/10/19/cybersecurity-did-bootcamps.html",
        "title": "Cybersecurity: Did Bootcamps Break Us or Save Us",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2021/a58ee35169.jpg\" width=\"100%\" alt=\"\" />\n<p>The cybersecurity awareness and training industry tops a billion dollars in revenue and will only grow as regulatory frameworks that require companywide learning programs spread.</p>\n<p>At the same time and given Higher Education&rsquo;s inability to adapt or keep up in digital fields, a training program that tops hundreds of billions of dollars grew overnight. In fact, a study by CompTIA (bias disclosure: a test vendor) found 91% of all employees use certifications in hiring.</p>\n<p>Classes to pass the certification exploded overnight. I worry the bootcamp model broke us.</p>\n<p>I do not want people equating a four-day class in how to pass a test to equal deep learning based in cognitive science. Not when it comes to cybersecurity. The mission too important to hunt for a quick fix in awareness and training.</p>\n<p>I know, like CMMC these certification classes are not meant to teach cybersecurity skills. Still, I personally believe the domains of knowledge assessed on the certified classes too hard to master in a four-day seminar.</p>\n<p>I don&rsquo;t blame anyone, but human nature. You can never lay shame on someone for taking the path of least resistance when it comes to securing food or shelter for them and theirs. Once you introduce a high stakes test humans will immediately start mixing a broth to corrupt the reliability and validity of that test.</p>\n<p>At the same time these increased cost and regulations caused expected resentment in the cybersecurity professional community. Many feel their experience has established these skills and they feel preyed upon by a certificate mill industry. They have a point.</p>\n<p>The entire tech industry, however (I included) could benefit from a good dose of humility. Nobody knows it all, and if you know more, others in the class benefit. Those most successful in bootcamp classes are probably humble folks in other online spaces.</p>\n<h3>Bootcamp Model</h3>\n<p>In a &ldquo;bootcamp&rdquo; style class, whether to train employees or to prepare for a certification test ,the learning gets crammed into a very short time frame over long extended days.</p>\n<p>Almost all cognitive science research supports longer durations for learning. In fact, retention ability decays very quickly. Further long-term transfer to other domains increases when high quality feedback gets connected with bursts of content, activity, and reflection.</p>\n<p>Bootcamp models do work, and we have emerging research to support this, in well-defined domains with discrete skill sets. Configuring your endpoint detection, learning to write JavaScript, even playing Clarinet.</p>\n<p>The Domain of cybersecurity, especially when preparing to move from one industry framework or another, however, cannot happen overnight. Yes, as I stated these classes do not train you in cybersecurity, but it will take specialized knowledge to move from a HIPPA audit to a 171 assessment for example.</p>\n<p>These domains of knowledge too complex for quick learning just to check off a compliance box.</p>\n<h3>Myth of Auto-Didactic Learner</h3>\n<p>No bootcamp lives in a vacuum (until Space Force starts orbital unit training) so when people claim to only want self-paced learning, they should make sure they have community support somewhere.</p>\n<p>Nobody learns alone. No one gets self-taught. Full stop.</p>\n<h3>Community is the Curriculum.</h3>\n<p>The original MOOCS, which helped kick off the coding and cybersecurity bootcamp craze, never focused on size. they focused on people. When David Cormier coined the term the massive modified open, not the size of the class.</p>\n<p>It meant using network theory to encourage the spread of open resources and pedagogy through ever growing learning communities.</p>\n<p>So even a four day or four-week self-paced online class needs some element of community. You need peers to have discussions. You need groups to work on scenarios and case studies that will reflect what cybersecurity and assessors will do in the field. Most importantly you need high quality feedback from your instructors.</p>\n<p>Not opinion. Stable and replicable finding from cognitive science research and based on principles of Universal Design for Learning to ensure all learners can succeed.</p>\n<h3>Bootcamp Models Dont Meet Diverse Workforce Needs</h3>\n<p>You need a lot of resources to check out for four days and go to an intensive bootcamp. Childcare, carpools, community volunteering, the bootcamp model do not reflect the needs of the modern workforce.</p>\n<p>Bootcamp models do not help diversity, equity, and inclusion when the only option involves four days of unpaid work. We need to provide learning communities that allow for flexible and supportive learning modalities. As a nation we must root cybersecurity trainings in groups that face historical exclusion in the tech and cyber industry.</p>\n<p>These four-day learning bonanzas also hurt organizations. As a CEO do you want your entire cyber/IT team out of pocket for four days? What if like many small businesses as CEO you are your entire cyber/IT team? Can you be out for four days?</p>\n<h3>A Better Way forward with CyberDI and Southern Connecticut State University</h3>\n<p>At SCSU, we have developed and iterated on the CyberDI curriculum that they will deliver on our online and offline campuses as an LTP through four rounds of iterative design with the goals of using principles of cognitive science in curriculum development and delivery.</p>\n<p>Real science. Not bootcamp marketing or certificate mill hype.</p>\n<p>In our five-week class model you meet twice a week for live classes each week. Instructors schedules these classes either at noon, the evening, or the weekends depending on local audience needs. They offer hybrid and fully online versions. The lectures and discussions get recorded so if life gets in the way anyone can catch up.</p>\n<p>Every practice and process in the CMMC model gets covered through systematic and explicit instruction following the &ldquo;Instructor does, class does, you do&rdquo; model. This predictability, science tells, us, improves learning.</p>\n<p>Social learning, not just explicit instruction, gets baked into the model. We have two weekly office hours where instructors and community members just drop in to get specific technical help or to ask general questions about course content.</p>\n<p>We know from research, building scaffolds that gives learners support drives success.</p>\n<p>Our course navigation is simple and works in Blackboard, Canva, Microsoft Teams, or my favorite a simple HTML website. In every module you are asked to read, write, and participate. We give you access to easy to navigate resources.</p>\n<img src=\"https://cdn.uploads.micro.blog/29546/2021/c15fff8a6a.png\" width=\"731\" height=\"469\" alt=\"screenshot of Google Classroom\" />\n<p>You can see above how each model gets laid out in a Google Classroom example. We know from decades of research ease of navigation drives learner efficacy and success.</p>\n<p>Most importantly you take part in production-based learning driven by feedback designed to elicit growth against the course objectives. Feedback, both formal and informal, drive learning. The teacher guide we provide has tips on writing feedback. The instructors who teach the CyberDI classes on SCSU campuses will get on going coaching in their questioning and discussion techniques. They get additional training on how to write and deliver feedback for growth.</p>\n<p>We do hope you choose a training program based in cognitive science and not just certificate mill marketing hype. The classes CyberDI will teach on our campuses meet this criteria.</p>\n<p>Just wanted to end with a quick shoutout to the subject experts who helped write and shape the curriculum</p>\n<h4>Curriculum Authors:</h4>\n<ul>\n<li>Leighton Johnson- Wrote our Domain Scenarios</li>\n<li>Paul Netopski- Wrote our CMMC Assessment Process Chapter</li>\n<li>Vincent Scott- Co-wrote history of CMMC and Domain Scenarios</li>\n<li>Tom Cornelius- Open Source contributor. We utilize Comp;iance Forge's CC BY-SA Scoping Guidance. </li>\n<li> Gregory McVerry co-wrote CUI scenarios, co-edited textbook with Dr. Tucker</li>\n<li>Lauren Tucker-lead author on instructinal guide, co-edited text book</li>\n<li>Richard Dawson-Wrote 162 aligned introductions for 17 Comains</li>\n<li>Dana Mantilla-Video Instructor who  interviewed top talent</li>\n<li>Brian Rogalski-co-wrote CUI scenarios</li>\n</ul>\n<p>Academic Advisor:\nLeslie Weinstein</p>\n<p>Video Guests:</p>\n<ul>\n<li>Allison Giddens</li>\n<li>Vincent Scott</li>\n<li>Margaret Glover</li>\n<li>Paul Netopski</li>\n<li>Matthew Carson</li>\n<li>Jake Williams</li>\n<li>Amira Armond</li>\n<li>Ryan Heildron</li>\n<li>Vic Malloy</li>\n<li>Kyle Lai</li>\n</ul>\n<p>img credit: Bootcamp dreams. by jgmac1106 shared under an CC-BY-SA license a  A remix of:\nWork boot&quot; by Bigbadvoo <a href=\"https://flickr.com/photos/bigbadvoo/243564879\">flickr.com/photos/bi&hellip;</a> is licensed under CC BY &ldquo;Storm Clouds Gathering&rdquo; by izoo3y <a href=\"https://flickr.com/photos/izoo3y/8735884805\">flickr.com/photos/iz&hellip;</a> is licensed under CC BY-SA &ldquo;Cha-Ching&rdquo; by spcbrass <a href=\"https://flickr.com/photos/spcbrass/368281633\">flickr.com/photos/sp&hellip;</a> is licensed under CC BY-SA</p>\n",
        "date_published": "2021-10-19T11:08:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/10/19/cybersecurity-did-bootcamps.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/10/03/any-questions-is.html",
        
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2021/0ebf0f2c11.jpg\" width=\"600\" height=\"600\" alt=\"\" />\n<p>We want to transform CyberSecurity Awareness and Training into an active learning process. For far too long we have assumed video-based quizzes work at the minimum and real training cannot happen because you need decades of experience to do Cyber.</p>\n<p>Neither assumption rings true. Active learning leads to greater transfer and retention. This production-based method, where learners must do stuff with what they learn begins with questioning.</p>\n<p>In my time working on Cybersecurity Maturity Model Certification courses, I have reviewed so much curriculum. Coched Provisional Instructors as they develop lesson plans and provided feedback to our instructors as we iterate on curriculum at Southern Connecticut State University.</p>\n<h2>Stop Asking Any Questions</h2>\n<p>Almost all the instruction I observe relies on direct intruction with little learner interaction. I see it in video based training and lectures where a highly talented Subject Matter Expers asks, &ldquo;Any Questions&rdquo; at the end of each segment or lecture.</p>\n<p>Everyone has questions. No one will ask.</p>\n<p>Instead a good teacher uses questions to elicit evidence of and scaffold knowledge growth. You can think of three types</p>\n<ul>\n  <li>Literal</li>\n  <li>Inferential</li>\n  <li>Evaluative</li>\n  </ul>\n<p>Literal questions get answered with explicit, which means identifiable in the text, details. Inferential questions require students to combine information in a text, either explicitly or implied, and combine this with prior knowledge or another source. Evaluative questions ask you to combine implicit information with an opinion and may focus on why and how to fill is missing details.</p>\n<p>As an instructor you need to plan your questioning well. You can use verbs from Bloom&rsquo;s Taxonomy or Webb’s Depth of Knowledge, but you need to ask questions for learning to occur.</p>\n<h2>Helping Out CMMC Instructors</h2>\n<p>So, to help out the Instructors who utilize the CMMC curriculum we write we started to create a question guide for each of the 17 Domains. It includes a definition from NIST SP-800-162 and questions a Certified CMMC Professional can use to help an Organization Seeking Certification. We derive these from 162 as well.</p>\n<p>We then include every assessment objective. CMMC courses mean nothing without Assessment Objectives. Next, we close with sample discussion questions. We hope these focus on pain points and common misconceptions. When an LTP or Provisional Instructor uses our material, you can know we provide you the tools to have active discussions,</p>\n<p>Check out our Access Control Example</p>\n<iframe src=\"https://docs.google.com/presentation/d/e/2PACX-1vQu3z0iiB9SOe3XEAE2iTYTxFTuNtDxJJgdzPodhpBZmm4IIhl0xrkbqLRKE3GnvA/embed?start=false&loop=false&delayms=30000\" frameborder=\"0\" width=\"100%\"  allowfullscreen=\"true\" mozallowfullscreen=\"true\" webkitallowfullscreen=\"true\"></iframe>\n<p><small>Featured Image <a title=\"Question\" href=\"https://flickr.com/photos/pagedooley/3983181467\">&ldquo;Question&rdquo;</a> by <a href=\"https://flickr.com/people/pagedooley\">kevin dooley</a> is licensed under <a href=\"https://creativecommons.org/licenses/by/2.0/\">CC BY</a> </small></p>\n",
        "date_published": "2021-10-03T14:02:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/10/03/any-questions-is.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/09/05/you-are-doing.html",
        "title": "You are Doing Cyberscecurity Awareness and Training Wrong",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2021/26047056ab.png\" width=\"600\" height=\"470\" alt=\"two people on the left and right of someone screaming in their ear\" />\n<p>Let me tell you how most of my pitch calls go when someone needs instructional design work for their company&rsquo;s cybersecurity awareness and training.</p>\n<p>The customer typically says something along the lines of, &ldquo;We just need a quick and dirty training, to check off the compliance box&rdquo;.</p>\n<p>I ask, &ldquo;Can you send me your policies and procedures so I can weave them into the training?&rdquo;</p>\n<h3 id=\"response-a\">Response A:</h3>\n<p>&ldquo;My boss doesn&rsquo;t want this eating up a bunch of time and resources. We just need the compliance. This isn&rsquo;t about learning.&rdquo;</p>\n<p>In the case of Response A, I always say, &ldquo;Doesn&rsquo;t it make sense to train your employees on your security stack based on their roles? Don&rsquo;t you know policy and procedures mean nothing without people? We can write your awareness and training so it reflects your people, processes, and technology, and most importantly the threats the data you hold faces.&rdquo;</p>\n<h3 id=\"response-b\">Response B:</h3>\n<p>&ldquo;We really don&rsquo;t have the policies and procedures in place.&rdquo;</p>\n<p>For Response B, I always say, &ldquo;Then your awareness and training needs to start with how to write and deploy policies and procedures.&rdquo;</p>\n<h3 id=\"the-call-back\">The Call Back</h3>\n<p>Almost always I get a call back an hour or day later with, &ldquo;I talked to the boss. They want to keep it dead simple and focus on compliance. How much for a quick one hour training?&rdquo;</p>\n<p>I wish them luck and shut down the call.</p>\n",
        "date_published": "2021-09-05T11:45:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/09/05/you-are-doing.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/08/23/when-you-cut.html",
        "title": "The Basics of Controlled Unclassified Information",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2021/509e4bcf66.png\" width=\"144\" height=\"68\" alt=\"\" />\n<p>When you cut through the marketing hype—and ignore all of the LinkedIn trolls predicting the doom of the Cybersecurity Maturity Model Certification (CMMC) program— you realize CMMC did not arise out of the blue. When you reasearch its history, you will find nothing especially new or unfamiliar. CMMC simply requires third party attestation of what defense contractors already had to do in order to fulfill the legal requirements of their agreements. The major change associated with CMMC is that it no longer allows for the self-assessment of cyber hygiene associated with Controlled Unclassified Information (CUI), as measured against NIST-SP-800-171 &ldquo;Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations.&rdquo;</p>\n<p>Individual contractors no longer have the authority to say how well they secure CUI. Instead, a third pary must come in and assess this information. In essence, it all comes down to CUI. But what do we mean we say Controlled Unclassified Information (CUI)?</p>\n<h2>What is CUI?</h2>\n<p>The US Government defines CUI as information which requires safeguarding or dissemination controls necessitated by law, regulation, or Government-Wide Policy; however, it does not include classified or nuclear stuff. The latter two fall under classified policies, and therefore require even more protections than CUI.</p>\n<p>The CUI program is thoroughly explained in the Code of Federal Regulation 32, Part 2002. This program  standardizes how the Executive Branch handles CUI. The Department of Defense (DoD), for example, established a CUI policy on March 6th 2002. This policy, DoD Instruction 5200.48, &ldquo;Controlled Unclassified Information,&rdquo; fulfills their requirements to develop a CUI policy. Every department, and thus their respective agencies, must have a similar CUI policy.</p>\n<p>The CUI designation was created in response to 9/11 via President Obama&rsquo;s Executive Order 13556. This executive order required all unclassified information throughout the Executive Branch which necessitated additional protection above and beyond information not for public release to be labeled CUI. Before this CUI policy, no uniform marking system existed for this kind of information across the Federal Government. Different agencies used an alphabet soup of labels such as FOUO, LES, and SBU.</p>\n<p>Under the Executive Order, the National Archives and Record Administration (NARA) was appointed to lead on developing a universal CUI Policy. The Secretary of Commerce, through the Office of Management and Budget, decided that CUI required moderate protection. FISMA, the Federal Information Modernization Security Act, then authorized the National Institute of Standards and Technologies (NIST) to develop standards for the protection of CUI.</p>\n<p>In fact, section two of the Executive Order designated NARA as the Executive Agency to oversee the order and the CUI program. NARA delegated this authority to the Information Security Oversight Office (ISOO). ISOO established a CUI registry that is:</p>\n<ul>\n  <li>Publicly Accessible</li>\n  <li>Includes authorized categories</li>\n  <li>Includes subcategories and guidance</li>\n  <li>Includes citations to laws and regulation and government wide policies</li>\n  </ul>\n<p>The Department of Defense then defined their <a href=\"https://www.dodcui.mil/Portals/109/Documents/CUI%20Registry/CUI%20Registry%20PDF%2019%20AUG%2021.pdf?ver=rfA1nKy-UyVx0clW9lZTCQ%3d%3d\">relevant categories</a> using DoD Instruction 5200.48, &ldquo;Controlled Unclassified Information&rdquo;.</p>\n<p>The ISOO CUI policy defines two types of CUI: Basic and Specified. Specified CUI contains specific handling controls, which it requires or permits agencies to use, and which differ from those used for Basic CUI. So, if a federal law or regulation requires handling instructions beyond the basic protections of CUI, we call this CUI Specified. An agency can decide internally, or with agreement from ISOO, to require additional protections.</p>\n<h2>CUI Lifecycle</h2>\n<p>The CUI lifecycle requires a contractor to identify the CUI they handle, to explicitly mark this data as CUI, to protect this CUI while in transit and at rest, to only share CUI for a lawful purpose, to destroy CUI when necessary, and to decontrol CUI when it no longer needs additional security.</p>\n<h3>Identifying CUI</h3>\n<p>It is best to begin this process by determining if you have any CUI in your system, or if you wish to bid on future contracts that would require CUI in your systems. Unfortunately, most of the data contractors receive from the DoD and prime contractors will not have proper markings. This does no alleviate a contractor of the legal responsibilities for protecting CUI, especially if they have existing contracts with the Defense Federal Acquisition Regulation Supplemental (DFARS) clause 7012, which requires self-attestation for protecting CUI against a 171 baseline.</p>\n<p>Once you identify the CUI in your system, identify which contract vehicles with a 7012 clause the CUI is often associated with. Then identify the people or roles with legal access to that CUI under each contract. In fact, you should create a matrix to capture this information.</p>\n<p>You cannot expect the DoD or a prime contractor to label all CUI created under a CUI contract. How could a Contracting Officer (CO) or a Program Management Office decide if the personal notes taken or meeting minutes contain CUI?</p>\n<iframe width=\"560\" height=\"315\" src=\"https://www.youtube.com/embed/E-XOAebDJHY\" title=\"YouTube video player\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture\" allowfullscreen></iframe>\n<h3>Marking CUI</h3>\n<p>The CUI program set out to protect unclassified information and ensure the timely sharing of information. The marking requirements of CUI vary based on the kinds of CUI and the chosen designation indicator. These influence the requirements for banner markings, which have to include category markings, control markings, and any limited dissemination markings (only certain people should see this).</p>\n<p>CUI marking requirements are influenced by more than just their category and control markings. The type of media it is associated with, such as emails or military documents, can influence the marking as well. Email banners may differ from the requirements for removable media. CUI can also be co-mingled into documents that require different limited dissemination, or are considered classified. Finally, you also have rules about marking CUI for mailing.</p>\n<p>The marking must include a designation indicator. This indicates who created the CUI. This can include a variety of formats such as a letterhead, a logo on a sticker, a signature, or a controlled byline. You have no requirement to include contact information, but many markings add this optional information.</p>\n<p>Department of Defense guidance suggests using a Designation Indicator block when space allows. This includes who controls the data, as well as anyone to which control was flowed through an authorized and legal use, any limited dissemination controls, and a point of contact. For example:</p>\n<p>Controlled by:  OUSD(I&amp;S)</p>\n<p>Controlled by:  CL&amp;S INFOSECCUI Category(ies):  PRVCY, OPSEC</p>\n<p>Limited Dissemination Control: FEDCON</p>\n<p>POC:  John Brown, 703-555-0123</p>\n<p>The banner marking can include three elements. The first, the control marking, is mandatory. This can say &ldquo;controlled&rdquo; or &ldquo;CUI.&rdquo;  Category markings are required for CUI Specified, and are separated by two // slashes. If dissemination controls are included, those follow the category markings, again after two forward slashes. Banners must appear in Bold Capitalized text, and ought to be centered when possible.</p>\n<p><strong>CUI</strong>  works as a basic CUI label.</p>\n<p>Category markings are optional, except in the case of CUI Specified. In fact, when you have Specified CUI, you are required to include the letters SP before the category marking. If more then one type of specified marking is included, you alphabetize them, but only separate each by one / forward slash after the first category, which follows the two // forward slashes and the basic marking.</p>\n<p><strong>CUI//SP-HLTH/PHYS</strong> In this example we see two CUI specified categories which follow the basic CUI marking.</p>\n<p>The banner markings can also designate the dissemination controls. Limited Dissemination Controls identify an intended audience, so a document does not need continuous authorization.</p>\n<p>No Foreign Dissemination (NOFORN) —Information may not be disseminated in any form to foreign governments, foreign nationals, foreign or international organizations, or non-U.S. citizens.</p>\n<p>Federal Employees Only (FED ONLY) —Dissemination authorized only to employees of the U.S.\nGovernment executive branch agencies, or armed forces personnel of the U.S. or Active Guard and Reserve.</p>\n<p>Federal Employees and Contractors Only (FEDCON) —Includes individuals or employees who enter a contract with the U.S. to perform a specific job or supply labor, and dissemination is in furtherance of the contractual purpose.</p>\n<p>No Dissemination to Contractors (NOCON) —Intended for use when dissemination is not permitted to federal contractors, but permits dissemination to state, local, or tribal employees.</p>\n<p>Dissemination List Controlled DL ONLY —Dissemination authorized only to those individuals, organizations, or entities included on an accompanying dissemination list.</p>\n<p>Authorized for Release to Certain Foreign Nationals Only (REL TO USA, LIST) —Information has been predetermined by the designating agency to be releasable only to the foreign country(ies) or international organization(s) indicated, through established foreign disclosure procedures and channels.</p>\n<p>The Department of Defense CUI guidance also allows dissemination marking to be included in the designation box. These include:</p>\n<p>Distribution Statement A:  Approved for public release.  Distribution is unlimited.</p>\n<p>Distribution Statement B:  Distribution authorized to U.S. Government agencies only (fill in reason and date of determination).</p>\n<p>Distribution Statement C:  Distribution authorized to U.S. Government agencies and their contractors (fill in reason and date of determination). Other requests for this document shall be referred to (insert controlling DoD office).</p>\n<p>Distribution Statement D:  Distribution authorized to Department of Defense and U.S. DoD contractors only (insert reason and date of determination). Other requests for this document shall be referred to (insert controlling DoD office).</p>\n<p>Distribution Statement E:  Distribution authorized to DoD Components only (fill in reason and date of determination). Other requests shall be referred to (insert controlling DoD office).</p>\n<p>Distribution Statement F:  Further dissemination only as directed by (insert controlling DoD Office and date of determination) or higher DoD authority.</p>\n<p>On digital media, you include these markings. On PowerPoint slides, you can include the CUI label at the top and bottom of the title slide with the indication block and the CUI label on the bottom of each slide. In a word document, you can include a cover sheet with the marking and designation block.</p>\n<h4>Removable Media</h4>\n<p>On a removable storage device, you are required to include the basic marking and a controlling indicators. Each file contained on the storage device needs its own marking. When feasible, you should include all required elements in the designation block, but the CUI basic marking and the originator or controller must always be included.</p>\n<h4>Email</h4>\n<p>Email is a bit trickier. When you send an email (try not to) containing CUI, you must let the recipient know. You must include a banner marking in the body of the email. Furthemore, best practice suggests including it in the CUI itself. Many companies use email server rules to sequester email with CUI. The subject line helps protect the data. When you forward email you must keep all banner markings. Make sure you cut and paste the banner to the top of the forward. You can also portion mark emails like regular documents where you call out sections that contain CUI.</p>\n<iframe width=\"560\" height=\"315\" src=\"https://www.youtube.com/embed/UxpF21AsxZE\" title=\"YouTube video player\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture\" allowfullscreen></iframe>\n<h3>Physical Protection of CUI</h3>\n<p>You will need to create a controlled environment to protect CUI. The regulations require you to have at least one physical barrier, such as sealed envelopes, locked doors, bins, drawers, or electronic locks. You have flexibility in deciding what counts as a physical barrier.</p>\n<p>You also need to consider meeting areas. You will need to control meeting access when CUI is shared and discussed. You will need to mark the door with the lock, noting only authorized indivduals allowed, and you will need a clean desk policy for after the meeting.</p>\n<p>Think about who has access to your controlled environments. You will need to lock away CUI from after hour cleaning crews, and to keep visitor and employee logs of areas that contain or discuss CUI. Your computer systems and networks also need to control access. You need to include banner markings on devices and systems that can connect to controlled environments.</p>\n<p>Basically, on electronic systems, you need to create some kind of barrier to prevent unauthorized access to CUI. This can include network folders, files, intranet, cloud enclaves, file sharing sites, and individual machines or devices.</p>\n<iframe width=\"560\" height=\"315\" src=\"https://www.youtube.com/embed/j0AzEnoopIw\" title=\"YouTube video player\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture\" allowfullscreen></iframe>\n<h3>Encryption and CUI</h3>\n<p>Based on Office of Management and Budget (OMB) policy, CUI requires moderate protection. This, in turn, requires encryption which meets a specific level called FIPS Validated 140-2A. At the simplest definition, encryption means that something we read in plain text is scrambled into a cyphertext. The authorized holder then has a &ldquo;key&rdquo; to unscramble the ciphertext into plain text.</p>\n<p>The approved encryption techniques are authorized by NIST in a document called &ldquo;Federal Information Processing Standards (FIPS) 140-2.&rdquo; The approved techniques, which can change based on use case and authorizer, include: AES, Triple-DES, and the Digital Signature Standard (“DSS”).  NIST-SP-800-171 (3.1.13 and 3.13.11) and CMMC spell out specific requirements for encryption (AC.3.014, SC.3.177).</p>\n<p>With FIPs level encryption, we make an important distinction between modules and devices. A module can be an embedded part of a product, such as an &ldquo;encrypt this email&rdquo; button or an entire product such as a CUI cloud enclave. A device, such as a laptop or cellphone, does not itself need the encryption. The tool accessed on that device to share, view, store, or transmit CUI must use encryption modules that meet FIPS standards.</p>\n<h3>Destroying CUI</h3>\n<p>When you destroy CUI, the NARA policy CFR 32 Part 2002 requires the CUI to end up unreadable, indecipherable, and irreconcilable. The NARA policy follows guidance of National Institute of Standards and Technology (NIST) Special Publication (SP) 800-88, Revision l: &ldquo;Guidelines for Media Sanitization&rdquo; or any technique approved by Classified National Security Information (32 CFR 2001.47).</p>\n<p>In 2019, NARA released <a href=\"https://www.archives.gov/files/cui/documents/20190715-cui-notice-2019-03-destroying-cui-in-paper-form.pdf\">guidance</a> on destroying paper-based CUI. You must follow the specifics of NIST-SP-800-88 when shredding paper. You must crosscut, meaning up and down, and left and right, down to 1mm x 5mm (0.04in x 0.2in) in size. You can also pulverize paper using disintegrator devices equipped with a 3/32in pulverizer. The approved shredders can get expensive. Many companies use a third party shredder or recycler that will provide a certification that they meet the requirements of NIST-SP-800-88.</p>\n<p>You can always go the cheapest route and follow the burn recommendations.</p>\n<p>In terms of media, there are also destruction requirements. NIST SP 800-171 3.8.3 states, “Sanitize or destroy system media containing CUI before disposal or release for reuse.&quot; The type of media will determine how you sanitize the device. Hard drives, for example, need different disposal methods than static hard drives.</p>\n<iframe width=\"560\" height=\"315\" src=\"https://www.youtube.com/embed/RZJdTOwxPuw\" title=\"YouTube video player\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture\" allowfullscreen></iframe>\n<h3>Decontrolling CUI</h3>\n<p>CFR 32 Part 2002 defines decontrolling as the event in which the authorizing agency decides the CUI &ldquo;no longer requires such controls.&rdquo; You must have policies and procedure in place to decontrol CUI. CUI can be decontrolled automatically or through positive decontrol. In automotive decontrol, a prior event, such as a date, is chosen when the controls are no longer required by law or policy. In positive decontrol, the authorizing agency takes an action to remove the controls.</p>\n<p>While a contractor can be appointed by the authorizing agency to disagree with the ability to decontrol CUI on a contract with the 7012 clause, it will not happen often.</p>\n<iframe width=\"560\" height=\"315\" src=\"https://www.youtube.com/embed/DL42CoWsnDk\" title=\"YouTube video player\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture\" allowfullscreen></iframe>\n<p>In the end, when you think CMMC, just think about CUI and how you can protect it from unauthorized disclosure.</p>\n",
        "date_published": "2021-08-23T17:46:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/08/23/when-you-cut.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/08/03/cmmc-and-ethics.html",
        "title": "CMMC and Ethics",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2021/812fb181d9.jpg\" width=\"600\" height=\"450\" alt=\"\" />\n<p>At a recent <a href=\"https://player.vimeo.com/video/580373403\">Town Hall</a>, the Cybersecurity Maturity Model Certification Accreditation Board (CMMC-AB) CEO Matt Travis noted that \"trust and confidence in the CMMC Ecosystem\" is the shared responsibility of both the AB and the members of the community.</p>\n<p>In fact, Travis's call to action harkened back to the the testimony of Deputy Assistant Secretary of Defense for Industrial Policy Jesse Salazar, who noted in his testimony to the Armed Service Committee cybersecurity subcommittee:</p>\n<blockquote>\n<p>DoD must ensure there are clearly defined roles and responsibilities, standards of conduct, and audit mechanisms governing relationships with private sector entities within the external assessment system.</p></blockquote>\n<p>In order for CMMC to succeed, ethics must matter.</p>\n<p>In the realm of Cybersecurity Maturity Model Certification, the Professional Code of Conduct drives ethical considerations. This document provides the standards to which all members hold themselves accountable.</p>\n<p>The document unites around five principles:</p>\n<ul>\n<li>Professionalism</li>\n<li>Objectivity</li>\n<li>Confidentiality</li>\n<li>Proper Use of Methods</li>\n<li>Information Integrity</li>\n</ul>\n<p>The document then lays out the practices inherent to each principle, in addition to how reporting features are implemented.</p>\n<p>Conflict of Interests occur when a person has a duty or motivation to serve the interests of more than one party in the engagement of an activity. According to Matt Travis, this can lead to a variety of consequences, including:</p>\n<ul>\n<li>Compromised Judgement</li>\n<li>Threatened Objective Decisions</li>\n<li>Undermined Impartiality</li>\n<li>Destroyed Confidence in Fairness and Integrity</li>\n<li>Required Disclosure</li>\n</ul>\n<h3>CMMC Conflict of Interest</h3>\n<p>We must remember that a mere perception of conflict can cause serious damage, even when no such conflict exists. Conflicts of interest can also exist without malicious intent or outcomes.</p>\n<p>The CMMC-AB, in fact, must establish a firewall between the registration of consultants, the accreditation of training schools, and the Assessment of Organizations Seeking Certification (OSC).</p>\n<p>Section 3.1.8 of the CMMC Professional Code of Conduct (CPCOC) requires everyone to avoid conflicts of interest to the greatest extent possible. We have a duty to avoid conflicts and report them when they occur.</p>\n<p>The professional code of conduct in Section 3.1.10 also prohibits Certified Third Party Assesment Organizations (C3PAOs) from soliciting business from the organizations they assess. In other words, you can not fail an OSC and then offer services to help them pass the next assessment.</p>\n<h3>CMMC and Objectivity</h3>\n<p>The CPCOC prohibits a credentialed assessor from joining an assessment team if that individual helped the organization prepare for the assessment. </p>\n<p>The ecosystems of many companies have Registered Professional Organization (RPO) credentials and C3PAO credentials. A business can not provide RPO services and then join a C3PAO Assessment Team, or host an Assessment Team themselves. Furthermore, if you have signed the CPCOC, you have an obligation to report this activity if you see it.</p>\n<h3>CMMC-AB and Ethics</h3>\n<p>In order to understand how the Accreditation Board (AB) must adhere to the ethics of the CPCOC, we must first understand their role in the ecosystem. The AB is required to: </p>\n<ul>\n<li>Authorize CMMC C3PAOs to conduct assessments</li>\n<li>Accredit C3PAOs in accordance with ISO 17020</li>\n<li>Authorize the CAICO (CMMC Assessors and Instructors Certification Organization) to certify CMMC Instructors and Assessors</li>\n<li>Establish, maintain, and Manage the CMMC Marketplace</li>\n<li>Oversee the CMMC Professional Code of Conduct</li>\n</ul>\n<p>Due to these roles the CMMC-AB has a variety of tools to limit Conflict of Interest</p>\n<ul>\n<li>CMMC-AB Code of Ethics</li>\n<li>CMMC-AB Conflict of Interest Policy</li>\n<li>CMMC-AB Directors Agreement</li>\n<li>CMMC Code of Professional Conduct</li>\n<li>Contract with Department of Defense</li>\n<li>CMMC-AB Audit, Ethics, and Compliance Committee</li>\n<li>Security and Compliance Officer</li>\n<li>ISO 170ii General Requirements for Accreditation Bodies Assessing and Accrediting Conformity Assessment Bodies</li>\n</ul>\n<p>These elements work together to ensure the CMMC ecosystem maintains a high ethical standard. \n<h3>Duty to Disclose</h3>\n<p>The CMMC-AB will release a disclosure matrix that lists all of the players in the ecosystem, and then a list of possible affiliations. These include elements of potential conflict such as ownership, financial interest, teaming agreements, family members, personal relationships, employment affiliations, and more. The AB will decide if, based on its role in the ecosystem, if that is a type of relationship that is okay, to be avoided, or risky enought to require mitigation.</p>\n<p>This document will explain your responsibilities to report conflict of interest.</p>\n<h3>Red Lines for the CMMC-AB</h3>\n<p>Based on the policies governing the AB, its members must not fail to disclose conflicts, have a vested interest in an C3PAO, use their status on the AB to generate business or leads, endorse any commercial product implicitly or explicitly, accept any gifts, or operate in a credentialed company within the ecosystem for the duration of one year after leaving the board.</p>\n<h3>Shady Vendors</h3>\n<p>As a member of the ecosystem, you face a barrage of emails. Many of these provide snake oil services or over-promise. As a small business, owners rely on word of mouth, not drip campaigns from marketing teams. Avoid anyone who promises quick assessments or turn key services.</p>\n<p>Take your time. You do not need a Level Three Certification overnight. 2026 is still a bit far off. Until then, just grow the SSP and shrink the POA&M.</p>\n",
        "date_published": "2021-08-03T17:07:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/08/03/cmmc-and-ethics.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/08/03/cybersecurity-begins-with.html",
        "title": "CyberSecurity Begins with Awareness and Training",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2021/d33f358d50.jpg\" width=\"600\" height=\"400\" alt=\"Bad Ragaz - Original Sin\" statues of apes />\n<p>It always comes down to the humans. Even with the best security, the tiniest friction can cause all systems fail. That 2% of DNA separating us from chimpanzees really messes with your cyber hygiene.</p> \n<p>If you want security you need to focus on the biggest attack vector: people.</p>\n<p>The Cybersecurity Maturity Model Certification (CMMC) program revolves around a national awareness and training program to increase the validity and reliability of the cybersecurity hygiene for the Defense Industrial Base (DIB).</p>\n<p>Relying on self-assessments hurts the overall validity of an organization's cyber hygiene, due to the scoring system for determining compliance. In NIST-SP-800-171 nor 171a, the methodology describes a scoring scheme. That model of having 110 points, and subtracting either 1, 3, or five points, came from the Defense Contracting Management Agency (DCMA). It did not work.</p>\n<p>Relying on self-assessments hurt the overall reliability of knowing if someone had achieved adequate compliance against NIST-SP-800-171. A lot of revenue depends on contracts from the Department of Defense that carry the 7012 clause. Many companies lacked experience or have had past success with a business development strategy of ignoring Department Defense mandates .</p>\n<p>We use the amount of data exfiltration from small manufacturers as proof of the failure. The daily ransomware attacks DIB companies face is further observable evidence that self-assessment does not work.</p>\n<p>CMMC requires us to realize cybersecurity isn't just everyone's job. Cybersecurity IS everyone. You must control your story, data, and identity. The people matter.</p>\n<p>In fact, the CMMC model requires an Awareness and Training Policy for Level Two (and thus Level Three, given the cumulative nature of the model):</p>\n<blockquote>\n<p>AT.2.999 </p>\n<p>Establish a policy that includes Awareness and Training. </p>\n</blockquote>\n<p>So how do you build an Awareness and Training policy? You need to understand what people need to know, when they need to know it, and how you will prove they know it. This begins, like all learning, by definining key terms.</p>\n<h2>What is Awareness?</h2>\n<p>I can understand the dangers of swimming in riptides in the absence of the training to escape one. All employees must have an awareness of the threats your company faces.</p>\n<p>In fact NIST SP 500-172, defines awareness as</p>\n<blockquote>sensitivity to the threats and vulnerabilities of computer systems and the recognition of the need to protect data, information, and the means of processing them </blockquote>\n<p> However, awareness—like swimming—does not equal training. In terms of cybersecurity, a company needs to have a general understanding of threats and cyber hygiene in order for it to grow. So, for example, while I may hang Controlled Unclassified Information (CUI) posters in the enclave to keep people aware of company policies, that does not equal a training program on selecting the correct shredder for the destruction of paper-based CUI. </p>\n<p>You may publish many of your policies in an employee handbook to make them aware of security issues. But you still need to train employees on how to execute these policies. </p>\n<h2>What is Training?</h2>\n<p>Awareness focuses on what, while training focuses on why and how. Training will take longer, and you as the learner will need to generate observable evidence of knowledge growth.</p>\n<h2>What Type of Awareness Programs do my Employees Need?</h2>\n<p>Based on the NIST 800-171a assessment objectives included in CMMC, you have to have an overall awareness of the threats CUI faces. All employees need an awareness of policies, standards, and procedures. This is often best covered in the Employee Handbook and Acceptable Use Policies.</p>\n<p>Your technical staff will need to understand the security risks associated with their activities to keep data safe. This, again, will require the development of Operating System awareness, and you may need to run multiple awareness programs for each major and minor technical system.</p>\n<p>Managers and system administrators need awareness of the applicable policies, standards, and procedures related to the security of the systems they oversee. This will include reference documents, a required tour of a wiki or database, and Security Technical Implementation Guides (STIGs).</p>\n<p>Some Awareness and Training requirements kick in at Level Two when we talk Cybersecurity Maturity Model Certification (CMMC):  </p>\n<blockquote>\n<p><strong>AT.2.056</strong> </p>\n<p>Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities, and of the applicable policies, standards, and procedures related to the security of those systems. </p>\n</blockquote>\n<blockquote>\n<p>ASSESSMENT OBJECTIVES [NIST SP 800-171A] </p>\n<p>Determine if: </p>\n<ul>\n   <li> [a]  security risks associated with organizational activities involving CUI are identified; </li>\n   <li> [b]  policies, standards, and procedures related  to the security of the system are identified; </li>\n   <li> [c]  managers, systems administrators, and users  of the system are made aware of the security risks associated with their  activities; and </li>\n    <li>[d]  managers, systems administrators, and users     of the system are made aware of the applicable policies, standards, and procedures  related to the security of the system. </li>\n    </ul>\n    </blockquote>\n<p>To meet the assessment objectives of this practice you will need to provide multiple types of security awareness and training programs</p>\n<h2>What type of Training Program Do My Employees Need</h2>\n<p>Based on the NIST 800-171a assessment objectives included in CMMC, you have to have three domains of training. One domain is focused on your CUI policy, another on threat analysis, and another on your system, security, and roles.</p>\n<p>CMMC has an entire set of objectives on developing and deploying a CUI policy. In your training, you need to ensure your managers and technical systems engineers, or Managed Service Providers (MSPs), know how CUI is protected on your system.</p>\n<p>Your training around applicable policies, standards, and procedures related to the security of the system will need extensive documentation, and will include recognizing educational certificates and providing your own training related to your reference architecture. </p>\n<p>For example, take AT.2.057, which requires contractors to \"ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities. \" This will require operating system training specific to a company's reference architecture. You will rely on different certificate programs to ensure your technical staff can stay current as technology changes. You will need multiple trainings for each of the operating systems deployed on your major and minor systems that store, transmit, destroy, or create CUI as the result of a government contract.</p>\n<h2>What is the Purpose of my Awareness and Training Policy?</h2>\n<p>The first objective of AT.2.999 establishes a policy that includes Awareness and Training, which requires you to have a purpose to your awareness and training policy. For Level Three certification, you need a mission and strategic goals. AT.3.997 requires contractors to \"establish, maintain, and resource a plan that includes Awareness and Training\" objectives b and c. </p>\n<p>We recommend you do this on company-wide scale, via a threat awareness and training program. Explore the threats, external and internal, you face. Analyze risks to your business and supply chain.</p>\n<p>Break employees into groups and have them draft threat analysis documents (this is a Level Four requirement, but wise to implement ahead of time). Then when you have a complete list of threats, have the groups craft mission and goal statements.</p>\n<p>You then work with the groups in a whole company setting to ensure your employees draft the kind of comprehensive policy statement you envision. Ownership builds awareness.</p>\n<p>Many mature and large organizations will have awareness and training policies developed. If this is the case for your organization, you should still conduct ongoing threat analysis discussions at the department level.</p>\n<p>At the end of the day, make sure folks are aware.</p>\n<h2>Who needs Awareness and Training?</h2>\n<p>Everyone. Awareness and training ensure policies and procedures become company culture. However, it is important to note that your managers, sales staff, and security engineers need different awareness and training.</p>\n<p>NIST Special Publication 800-16, \"Information Technology Security Training Requirements,\" recommends creating a role-based training matrix. You can combine this approach with CMMC requirements to create a full curriculum scope and sequence for your awareness and training program.</p>\n<p>In the first column of the Matrix, list all the user roles on your information systems. Include a row for \"all.\" You can group trainees by their roles as well.</p>\n<p>Then create four domains in your awareness and training program:</p>\n<ul>\n<li>Employee Responsibilities,</li>\n<li>Information System Policies, </li>\n<li> CUI</li>\n<li>Reference Architecture</li>\n</ul>\n<p>What kind of training an employee receives, and in which domain, depends on their role. For example, all employees may have to watch a training and certify they read the Employee Handbook and Acceptable Use Policies. You probably want a training on the email rules of your company for all employees.</p>\n<p>For Level Three CMMC Certification, you need to document what will be learned. In fact, Assessment Objective [e] of AT.3.997 requires you to document \"the plan documents, activities, and due dates.\" In your matrices, be sure to list the trainings, in addition to when due dates occur.</p>\n<p>Fill out the chart indicating when role-based awareness and training occurs, what it includes, and how it is assessed.</p>\n<p>Large companies may have an internal learning management system that may track many of these metrics. Smaller companies may have to contract with a vendor. If you purchase IT or security products from MSPs or vendors, try to negotiate a training package, or choose those you see as compliance partners.</p>\n<h2>What should Awareness and Training Cover?</h2>\n<h3>Employee Responsibilities</h3>\n<p>You need to cover the four domains of knowledge, but now you must also develop the scope of learning objectives and the sequence of training for the matrices.</p>\n<p>First begin with employee responsibilities by examining the everyday system-wide awareness and trainings all employees must receive. This includes the employee handbook, sexual harassment, legal compliance, company wide posters, CUI handling posters, and stickers. These are everyday business practices that require awareness and training.</p>\n<p>Then decide which of these policies need more than awareness and actual training. This could include a short video summarizing the employee handbook with a quiz. Employees often have to attend mandatory trainings with a supervisor. </p>\n<p>Once you have the list, decide if the subject requires awareness or training. Add it to the matrix.</p>\n<h3>Controlled Unclassified Information</h3>\n<p>As noted above, you must include awareness and training on the \"security risks associated with organizational activities involving CUI are identified.\"  In other words, you need to develop a CUI Training Program.</p>\n<p>At Level Two of the CMMC, your company will need awareness and training on the internal threats faced by companies who have a legal right to handle Control Unclassified Information on behalf of a government contract.</p>\n<p>At Levels Two and Three, your awareness and training program must include your company policies on receiving, creating, labeling, disseminating, transmitting, storing, and destroying CUI. This policy should cover the specific workflows for handling this information. You will also need to include your Incident Response Training on handing CUI data spillage.</p>\n<p>At Level Four, your CUI awareness and training program should include recognizing and responding to threats from social engineering that can lead to advanced persistent threat actors, breaches, and suspicious behaviors; you will be required to update the training at least annually, as well as when there are significant changes to relevant threats. </p>\n<h3>Information System Policies</h3>\n<p>Then you will have company-wide information system policies, such as your password policy, email policy, device policy, how Multifactor Authentification works (please turn on MFA), et cetera. </p>\n<p>These Information System Policies apply to all employees, however, at this point you may have to start specializing. The account generation for your Mobile Device Management tools may vary from your payroll system. In fact, at this level you will start to specialize at the Operating System level.</p>\n<p>Different types of operating systems will require you to verify employee training through different certificates. If you deploy in Kubernetes in Azure or use S3 in  WS Govcloud, each of those stacks has individual Security Technical Implementation Guides (STIGs) and certification programs.</p>\n<p>You must consider all the major and minor systems, the data that flows through them, and the laws and regulations that govern how that data is used and shared.</p>\n<p>As a contractor, you also will need to consider trainings on your acquisition team on what kind of service level agreements you need in your vendor agreements with regards to information and technology systems. Trainings need to include examining vendor agreements and SLAs to determine if proposed security solutions meet CMMC Level Three standards.</p>\n<h3>Reference Architecture</h3>  \n<p>As Tom Cornelius from Compliance Forge notes, \"You must see policy as a blueprint and not documentation. You are more an archtiect than a writer.\"</p>\n<p>As an organization, you will need solid reference architecture on how you build secure systems that can handle a moderate baseline for the protection of Controlled Unclassified Information. You will have a set of documents that describe how to build the ideal environment for your use case. You will need awareness and training on how to use and update your reference architecture.</p>\n<p>Take configuration management for example. If you do not have a clear configuration management documentation and provide baseline training on using the necessary references, you will not have the basics of Access Control, the root of cybersecurity.</p>\n<p>Next, you can turn to the other domains in CMMC to determine the specifics of company-wide training policies.</p>\n<h4>What other Domains Should Awareness and Training Cover?</h4>\n<p>The Awareness and Training you provide must go well beyond the practices and process of the AT domain. In fact, according to <a href=\"https://nativeintelligence.com\">Native Intelligence</a> in a blog post on Amira Armond's CMMC Audit, Awareness and Training needs to cover fourteen additional practices across five domains</p>\n<ul>\n<li>Access Control (AC)</li>\n<li>Media Protection (MP)</li>\n<li>Maintenance (MA)</li>\n<li>Physical Protection (PE)</li>\n<li>Systems and Communications Protection (SC)</li>\n</ul>\n<h2>How to Get Started on an Awareness and Training Plan</h2>\n<h3>Create an Instructional Leadership Team</h3>\n<p>You first begin by designating who owns your awareness and training program. The Instructional Leadership Team should contain stakeholders across the organization and not just from IT or your security team (if you even have either position. The team could include your Information System Security Officer, CIO, CTO, information System Security Manager, human resources, facility security officer, or employees designated to serve on the instructional leadership team.)</p>\n<h3>Craft Goals, Missions, and Objectives</h3>\n<p>Your instructional Leadership Team then crafts your goals mission and objectives. This begins by a walkthrough through of your threat environment. Understand the common threats to the sensitive data you hold. </p>\n<p>You can have very generic goals, missions, and objectives for your trainings. You may want to consider utilizing the awareness and training domain to strengthen your talent across the board. However, you only need to track system security related training with CMMC.</p>\n<h3>Determine Roles for Awareness and Training</h3>\n<p>Next, the Instructional Leadership Team determines roles and responsibilities. Christina Reynolds of BDO-USA recommends using the RAC model: who is Responsible, who is Accountable, and who need to be Consulted. The goal is to create observable evidence that partially meets assessment objectives c, d, and g of AT.2.999</p>\n<blockquote><p>\" the roles and responsibilities of the activities covered by this policy are defined; (i.e., the responsibility, authority, and ownership of Awareness and Training activities);\"</p>\n<p> \"The policy establishes or directs the establishment of procedures to carry out and meet the intent of the policy;\"</p>\n<p>\"the policy is endorsed by management and disseminated to appropriate stakeholders; and  \"</p>\n</blockquote>      \n<p>So  you develop a matrix of roles and responsibilities. Include general users, data owners, system owners, and members of the Instructional Leadership Team. Make a column for each.</p>\n<p>Then, in the rows include who must complete training, who develops the training program, who agrees to acceptable use policies, who decides which roles get what training, who completes role based training, and who is responsible for record keeping.</p>\n<h3>Establish Company-wide Baselines</h3>\n<p>Now, decide what basic training every employee must have. This will include your awareness activities, employee handbooks, email policies, acceptable use policies, etc. You may include optional training on overall threat awareness and common attack vectors, such as phishing.</p>\n<p>The goal is to establish the bare minimum of security awareness you want with your employees. This wil usually include a variety of trainings like company wide meetings, video on-demands, or online learning.</p>\n<h3>Develop A Training Matrix</h3>\n<p>Now that you have a baseline of security awareness and training you want for employees, you next decide on specialized roles, and create a role-based training matrix. People in specialized roles and management positions will need additional training over and beyond what every employee recieves.</p>\n<p>You need to group people into roles based on functions in the workplace.</p>\n<p>Then create a list of topics, which includes items such as:</p>\n<ul>\n    <li>CUI</li>\n    <li>Email</li>\n    <li>Threat Awareness</li>\n    <li>Media Protection</li>\n    <li>Passwords</li>\n    <li>Mobile Devices</li>\n    <li>Access Control Policy</li>\n    <li>Reference Architecture</li>\n    <li>Crafting Service Level Agreements</li>\n    <li>etc</li>\n</ul>  \n<p>You then decide based on the number of roles created by your Instructional Leadership Team which group gets what training. </p>   \n<h3>Develop Company Wide Awareness and Training Rubric</h3>\n<p>Next the Instructional Leadership Team needs to define success metrics for your awareness and training program. In terms of CMMC, it is important to know if a plan really does not kick in until Level Four process requirements, but you cannot have a compliant training program at this Level without evidence of learning gains.</p>\n<p>The evidence of awareness and training success, like all compliance data, can fall into one of three categories: interview, observe and test.</p>\n<p>First, you want to understand if your awareness and trainign impacts your operational security. Indicators could include reduction in down time, increased phishing test success rates, and incident reporting. If you can not automate these metrics, you can have the Instructional Leadership Team rate them on a four point likert scale.</p>\n<p>You also have training program metrics, such as the frequency of training programs, learner performance, attendance, and learner feedback. You should check with your state on the requirements to protect and retain employee training data.</p>\n<h3>Evaluate Content</h3>\n<p>Now you have to choose content that will align your role based matrices with your required learning matrices. It will probably be cheaper to purchase curriculum than to develop it in-house. However, when you pay for an instructional designer to develop your program, you can align the program to your company culture and workflow.</p>\n<p>The majority of cybersecurity training is video-based garbage designed to allow you to check off a compliance box about providing training. Develop or utilize a rubric for evaluating curriculum. You may consider hiring a consultant to help you evalaute curriculum. At the very least, choose your networks from word of mouth.</p>\n<h3>Create Deployment and Evaluation Schedule</h3>\n<p>Next, you must create a scope and sequence guide for your curriuclum. This document includes the objectives of your chosen curriculum, how those objectives will be measured, when the curriculum will be delivered, and who will evaluate the result. You can include information about awareness and training.</p>\n<p>For awareness, you could include the posters you hang and monthly security reminders that are delivered by email. The awareness program occurs all the time, and for all users.</p>\n<p>For training, this again will be a role-based document. Many people may end up including the role-based matrix in the scope and sequence of the curriculum. </p>\n<h3>Craft Awareness and Training Plan Compliance Documentation</h3>\n<p>Finally, you will need to create a way to document your awareness and training program, so you organize observable evidence in a way that would not require a CMMC assors to make any inferences about your program. Spell out how you meet each requirement in your Policy, Procedures and Plans. If you followed the path above, you will have the majority of the required documentation already.</p>\n<p>Now, as your goal you must include the procedures you have decided upon for your Awareness and Training Policy, in addition to how you plan to include the metrics from your Awareness and Training in both your System Security Plan (SSP) and your Awareness and Training Plan.</p>\n<p>Create a policy for retaining security training records. Create the procedures to make sure this happens.</p>\n<p>Include a table in your policy that explicitly addresses all of the required Awareness and Rraining in a practice or assessment objective. Then, in your SSP, reference this policy and include two pieces of observable evidence that the assessment objectives have been met.</p>\n<p>For example, you need to include training of internal threats at Level Two of CMMC. This means that for Level Three compliance, you must demonstrate you provide this training. Explicitly spell this out, in addition to any required training in your Awareness and training Policy and Procedures.</p>\n<p>For many companies, beginning with the Awaress and Training domain may provide a great launching point for your CMMC journey.</p>\n<h2> Meet CMMC Compliance through Awareness and Training </h2>\n<p>Can you complete your SSP as you utilize and also reach compliance on the Awareness and Training domain? Would this approach lead to increased hygiene?</p>\n<p>Everyone frets over CMMC devolving into a checklist of policy and confusing technical controls. Awareness and Training makes this difference.</p>\n<p><strong>Christina Reynolds co-authored this post in the guidance she provided in how to craft Awareness and Training Policy</strong></p>\n<p><small>Featured Image: <a title=\"Bad Ragaz - Original Sin\" href=\"https://flickr.com/photos/kecko/51235670162\">&ldquo;Bad Ragaz - Original Sin&rdquo;</a> by <a href=\"https://flickr.com/people/kecko\">Kecko</a> is licensed under <a href=\"https://creativecommons.org/licenses/by/2.0/\">CC BY</a> </small></p>\n",
        "date_published": "2021-08-03T15:02:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/08/03/cybersecurity-begins-with.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/07/28/how-do-you.html",
        "title": "How do you use the Discussion Section of the CMMC Assessment Guides?",
        "content_html": "<p>Great post from <a href=\"https://www.linkedin.com/in/alexyjohnson/\">Alex Johnson</a> on the difference between the discussion and requirements of CMMC practices.</p>\n<p>&ldquo;I want to offer some information to those who may be struggling with understanding what options are available to you regarding the implementation of NIST SP 800-171 and CMMC requirements or practices.</p>\n<p>NIST SP 800-171 Section 2.2 contains the following:</p>\n<p>&ldquo;A discussion section follows each CUI security requirement providing additional information to facilitate the implementation and assessment of the requirements. This information is derived primarily from the security controls discussion sections in [SP 800-53] and is provided to give organizations a better understanding of the mechanisms and procedures used to implement the controls used to protect CUI. The discussion section is informative, not normative. It is not intended to extend the scope of a requirement or to influence the solutions organizations may use to satisfy a requirement. The use of examples is notional, not exhaustive, and not reflective of potential options available to organizations. &quot;</p>\n<p>The bottom line is that you have options. The discussions are not telling you exactly what you have to do. Rather, they are helping you to understand the essence of what the requirement is. There are a few discussions that are normative, but only a few.</p>\n<p>A great example of this can be found in MP.2.119 (3.8.1). These assessment objectives require you to physically control and securely store media containing CUI. The discussion indicates that &ldquo;physically controlling system media includes conducting inventories.&rdquo; However, that is not a requirement based on NIST SP 800-171 Section 2.2.</p>\n<p>I hope this helps some who may &ldquo;extend the scope of a requirement&rdquo; based on the discussion section.&rdquo;</p>\n<p>&lt;a href=&quot;<blockquote class=\"quoteback\" data-title=\"\" data-author=\"linkedin.com\" data-avatar=\"https://micro.blog/linkedin.com/avatar.jpg\" cite=\"https://www.linkedin.com/posts/activity-6826146082469281793-PZdG\">Alexy J. on LinkedIn: I want to offer some information to those who may be struggling with <a href=\"https://www.linkedin.com/posts/activity-6826146082469281793-PZdG\">linkedin.com</a><p class=\"post_archived_links\">Archiving&hellip;</p><footer>linkedin.com <cite><a href=\"https://www.linkedin.com/posts/activity-6826146082469281793-PZdG\"><a href=\"https://www.linkedin.com/posts/activity-6826146082469281793-PZdG\">https://www.linkedin.com/posts/activity-6826146082469281793-PZdG</a></a></cite></footer></blockquote><script src=\"https://micro.blog/quoteback.js\"></script></p>\n",
        "date_published": "2021-07-28T10:50:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/07/28/how-do-you.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/07/14/inventory-matters.html",
        "title": "Inventory Matters",
        "content_html": "<p>Inventory matters. As <a href=\"https://www.linkedin.com/in/solontek-ceo-sspencer/\">Sarah Spencer </a>CEO of SolonTek notes, &ldquo;You cannot protect what you cannot see.&rdquo;</p>\n<p><small><a title=\"dandoodlescan065-inventory is waste\" href=\"https://flickr.com/photos/sixmilliondollardan/3966823194\"><img src=\"https://live.staticflickr.com/2640/3966823194_fb9f9b5a2e_z.jpg\" /></a><br /><small><a title=\"dandoodlescan065-inventory is waste\" href=\"https://flickr.com/photos/sixmilliondollardan/3966823194\">&ldquo;dandoodlescan065-inventory is waste&rdquo;</a>  by <a href=\"https://flickr.com/people/sixmilliondollardan\">Inha Leex Hale</a> is licensed under <a href=\"https://creativecommons.org/licenses/by/2.0/\">CC BY</a> </small></p>\n<p>Now, some people read the CMMC assessment guide for Level One and think, &ldquo;Huh no inventory needed?&rdquo;</p>\n<p>This is not true. You may not need to show your inventory results or policies for Level One compliance, but you will not be Level One compliant without good inventory policy.</p>\n<p>Think about assessment objective f of Access Control 1.001, &ldquo;[f] system access is limited to authorized devices (including other systems).&rdquo; You will need to inventory your systems to comply with this objective.</p>\n<p>What about CUI? If you read NIST-SP800-18 on writing a System Security Plan, you quickly realize you need to inventory all of your 7012 contracts and the data owner for each one.</p>\n<p>Vincent Scott and I developed a quick table of &ldquo;some&rdquo; of the areas hit by good inventory. The word &ldquo;identified&rdquo; happens a ton in the CMMC assessment guides. You have to decide if this also means counting. This list will continue to grow, so if you think we missed something, please let us know.</p>\n<p>Comment on LinkedIn or better yet get a blog and send me a webmention.</p>\n<table border=\"solid 1px\" width=\"90%\">\n<tbody>\n  <tr>\n<td style=\"font-weight: 400;\" width=\"39\">CMMC Level</td>\n<td style=\"font-weight: 400;\" width=\"187\">Domain</td>\n<td style=\"font-weight: 400;\" width=\"68\">Number</td>\n<td style=\"font-weight: 400;\" width=\"72\"></td>\n<td style=\"font-weight: 400;\" width=\"677\">Definition</td>\n<td style=\"font-weight: 400;\" width=\"505\">Assessment Objective</td>\n<td style=\"font-weight: 400;\" width=\"100\">NIST 171</td>\n</tr>\n<tr>\n<td style=\"font-weight: 400;\" width=\"39\">1</td>\n<td style=\"font-weight: 400;\" width=\"187\">Access Control</td>\n<td style=\"font-weight: 400;\" width=\"68\">AC.1.001</td>\n<td style=\"font-weight: 400;\" width=\"72\"> </td>\n<td style=\"font-weight: 400;\" width=\"677\">Limit information system access to authorized users, processes acting on behalf of authorized users, or devices</td>\n<td style=\"font-weight: 400;\" width=\"505\">[c] devices (and other systems) authorized to connect to the system are identified;</td>\n<td style=\"font-weight: 400;\" width=\"100\">3.1.1</td>\n</tr>\n<tr>\n<td style=\"font-weight: 400;\" width=\"39\">1</td>\n<td style=\"font-weight: 400;\" width=\"187\">Access Control</td>\n<td style=\"font-weight: 400;\" width=\"68\">AC.1.001</td>\n<td style=\"font-weight: 400;\" width=\"72\"> </td>\n<td style=\"font-weight: 400;\" width=\"677\">Limit information system access to authorized users, processes acting on behalf of authorized users, or devices</td>\n<td style=\"font-weight: 400;\" width=\"505\">[f] system access is limited to authorized devices (including other systems).</td>\n<td style=\"font-weight: 400;\" width=\"100\">3.1.1</td>\n</tr>\n<tr>\n<td style=\"font-weight: 400;\" width=\"39\">2</td>\n<td style=\"font-weight: 400;\" width=\"187\">Access Control</td>\n<td style=\"font-weight: 400;\" width=\"68\">AC.2.006</td>\n<td style=\"font-weight: 400;\" width=\"72\"> </td>\n<td style=\"font-weight: 400;\" width=\"677\">Limit use of portable storage devices on external systems</td>\n<td style=\"font-weight: 400;\" width=\"505\">[a] the use of portable storage devices containing CUI on external systems is identified and documented;</td>\n<td style=\"font-weight: 400;\" width=\"100\">3.1.21</td>\n</tr>\n<tr>\n<td style=\"font-weight: 400;\" width=\"39\">2</td>\n<td style=\"font-weight: 400;\" width=\"187\">Access Control</td>\n<td style=\"font-weight: 400;\" width=\"68\">AC.2.011</td>\n<td style=\"font-weight: 400;\" width=\"72\"> </td>\n<td style=\"font-weight: 400;\" width=\"677\">Authorize wireless access prior to allowing such connections</td>\n<td style=\"font-weight: 400;\" width=\"505\">[a] wireless access points are identified;</td>\n<td style=\"font-weight: 400;\" width=\"100\">3.1.16</td>\n</tr>\n<tr>\n<td style=\"font-weight: 400;\" width=\"39\">2</td>\n<td style=\"font-weight: 400;\" width=\"187\">Access Control</td>\n<td style=\"font-weight: 400;\" width=\"68\">AC.2.015</td>\n<td style=\"font-weight: 400;\" width=\"72\"> </td>\n<td style=\"font-weight: 400;\" width=\"677\">Route remote access via managed access control points</td>\n<td style=\"font-weight: 400;\" width=\"505\">[a] managed access control points are identified and implemented; </td>\n<td style=\"font-weight: 400;\" width=\"100\">3.1.14</td>\n</tr>\n<tr>\n<td style=\"font-weight: 400;\" width=\"39\">2</td>\n<td style=\"font-weight: 400;\" width=\"187\">Access Control</td>\n<td style=\"font-weight: 400;\" width=\"68\">AC.2.016 </td>\n<td style=\"font-weight: 400;\" width=\"72\"> </td>\n<td style=\"font-weight: 400;\" width=\"677\">Control the flow of CUI in accordance with approved authorizations</td>\n<td style=\"font-weight: 400;\" width=\"505\">[c] designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified;</td>\n<td style=\"font-weight: 400;\" width=\"100\">3.1.3</td>\n</tr>\n<tr>\n<td style=\"font-weight: 400;\" width=\"39\">3</td>\n<td style=\"font-weight: 400;\" width=\"187\">Access Control</td>\n<td style=\"font-weight: 400;\" width=\"68\">AC.3.020 </td>\n<td style=\"font-weight: 400;\" width=\"72\"> </td>\n<td style=\"font-weight: 400;\" width=\"677\">Control connection of mobile devices</td>\n<td style=\"font-weight: 400;\" width=\"505\">[a] mobile devices that process, store, or transmit CUI are identified;</td>\n<td style=\"font-weight: 400;\" width=\"100\">3.1.18</td>\n</tr>\n<tr>\n<td style=\"font-weight: 400;\" width=\"39\">3</td>\n<td style=\"font-weight: 400;\" width=\"187\">Access Control</td>\n<td style=\"font-weight: 400;\" width=\"68\">AC.3.022 </td>\n<td style=\"font-weight: 400;\" width=\"72\"> </td>\n<td style=\"font-weight: 400;\" width=\"677\">Encrypt CUI on mobile devices and mobile computing platforms</td>\n<td style=\"font-weight: 400;\" width=\"505\">[a] mobile devices and mobile computing platforms that process, store, or transmit CUI are identified;</td>\n<td style=\"font-weight: 400;\" width=\"100\">3.1.19</td>\n</tr>\n<tr>\n<td style=\"font-weight: 400;\" width=\"39\">2</td>\n<td style=\"font-weight: 400;\" width=\"187\">Configuration Management</td>\n<td style=\"font-weight: 400;\" width=\"68\">CM.2.061 </td>\n<td style=\"font-weight: 400;\" width=\"72\"> </td>\n<td style=\"font-weight: 400;\" width=\"677\">Establish and maintain baseline configurations and inventories of organizational systems throughout the respective system development life cycles</td>\n<td style=\"font-weight: 400;\" width=\"505\">[e] the system inventory includes hardware, software, firmware, and documentation; and</td>\n<td style=\"font-weight: 400;\" width=\"100\">3.4.1</td>\n</tr>\n<tr>\n<td style=\"font-weight: 400;\" width=\"39\">1</td>\n<td style=\"font-weight: 400;\" width=\"187\">Identification and Authentication</td>\n<td style=\"font-weight: 400;\" width=\"68\">IA.1.076 </td>\n<td style=\"font-weight: 400;\" width=\"72\"> </td>\n<td style=\"font-weight: 400;\" width=\"677\">Identify information system users, processes acting on behalf of users, or devices</td>\n<td style=\"font-weight: 400;\" width=\"505\">[c] devices accessing the system are identified.</td>\n<td style=\"font-weight: 400;\" width=\"100\">3.5.1</td>\n</tr>\n<tr>\n<td style=\"font-weight: 400;\" width=\"39\">1</td>\n<td style=\"font-weight: 400;\" width=\"187\">Identification and Authentication</td>\n<td style=\"font-weight: 400;\" width=\"68\">IA.1.077</td>\n<td style=\"font-weight: 400;\" width=\"72\"> </td>\n<td style=\"font-weight: 400;\" width=\"677\">Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems</td>\n<td style=\"font-weight: 400;\" width=\"505\">[c] the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access.</td>\n<td style=\"font-weight: 400;\" width=\"100\">3.5.2</td>\n</tr>\n<tr>\n<td style=\"font-weight: 400;\" width=\"39\">3</td>\n<td style=\"font-weight: 400;\" width=\"187\">Media Protection</td>\n<td style=\"font-weight: 400;\" width=\"68\">MP.3.123 </td>\n<td style=\"font-weight: 400;\" width=\"72\"> </td>\n<td style=\"font-weight: 400;\" width=\"677\">Prohibit the use of portable storage devices when such devices have no identifiable owner</td>\n<td style=\"font-weight: 400;\" width=\"505\">[a] the use of portable storage devices is prohibited when such devices have no identifiable owner.</td>\n<td style=\"font-weight: 400;\" width=\"100\">3.8.8</td>\n</tr>\n<tr>\n<td style=\"font-weight: 400;\" width=\"39\">1</td>\n<td style=\"font-weight: 400;\" width=\"187\">Physical Protection</td>\n<td style=\"font-weight: 400;\" width=\"68\">PE.1.134</td>\n<td style=\"font-weight: 400;\" width=\"72\"> </td>\n<td style=\"font-weight: 400;\" width=\"677\">Control and manage physical access devices</td>\n<td style=\"font-weight: 400;\" width=\"505\">[a] physical access devices are identified;</td>\n<td style=\"font-weight: 400;\" width=\"100\">3.10.5</td>\n</tr>\n<tr>\n<td style=\"font-weight: 400;\" width=\"39\">2</td>\n<td style=\"font-weight: 400;\" width=\"187\">System and Communications Protections</td>\n<td style=\"font-weight: 400;\" width=\"68\">SC.2.178</td>\n<td style=\"font-weight: 400;\" width=\"72\"> </td>\n<td style=\"font-weight: 400;\" width=\"677\">Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device </td>\n<td style=\"font-weight: 400;\" width=\"505\">[a] collaborative computing devices are identified;</td>\n<td style=\"font-weight: 400;\" width=\"100\">3.13.12</td>\n</tr>\n<tr>\n<td style=\"font-weight: 400;\" width=\"39\">2</td>\n<td style=\"font-weight: 400;\" width=\"187\">System and Communications Protections</td>\n<td style=\"font-weight: 400;\" width=\"68\">SC.2.179 </td>\n<td style=\"font-weight: 400;\" width=\"72\"> </td>\n<td style=\"font-weight: 400;\" width=\"677\">Use encrypted sessions for the management of network devices</td>\n<td style=\"font-weight: 400;\" width=\"505\">[a] the organization has one or more policies and/or procedures for establishing connections to manage network devices;</td>\n<td style=\"font-weight: 400;\" width=\"100\">N/A</td>\n</tr>\n<tr>\n<td style=\"font-weight: 400;\" width=\"39\">1</td>\n<td style=\"font-weight: 400;\" width=\"187\">System and Informational Integrity</td>\n<td style=\"font-weight: 400;\" width=\"68\">SI.1.211 </td>\n<td style=\"font-weight: 400;\" width=\"72\"> </td>\n<td style=\"font-weight: 400;\" width=\"677\">Provide protection from malicious code at appropriate locations within organizational information systems</td>\n<td style=\"font-weight: 400;\" width=\"505\">[a] designated locations for malicious code protection are identified;</td>\n<td style=\"font-weight: 400;\" width=\"100\">3.14.2</td>\n</tr>\n</tbody>\n</table>\n",
        "date_published": "2021-07-14T11:02:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/07/14/inventory-matters.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/07/07/prrequisites-for-a.html",
        "title": "Prequisites for a DIBCAC CMMC Assessment",
        "content_html": "<p>While we await the release of the CMMC assessment process from the AB, we can look to how the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) conducted Level Three assessments of Certified Third Party Assessment Organizations (C3PAO) to understand their methodology.</p>\n<p>As we know, Cybersecurity Maturity Model Certification (CMMC) assessments happen in four phases. With each step, you decide to continue with the next phase of assessment. At a brown bag luncheon DIBCAC released their go/no-go decision trees.</p>\n<p>This provides a road map for companies that may want to prepare for their CMMC journey now.</p>\n<h2>Documented SSP</h2>\nIf you do not have a documented System Security Plan (SSP) you cannot be scored against the 171 framework or CMMC. \n<p>If you utilize the NIST templates for 171a self-assessments, your SSP will not include all of the domains, practices, and assessment objectives necessary for Level 3 CMMC certification.</p>\n<h2>Policy, Procedures, and Plans</h2>\nDo you know how much documentation CMMC takes? A lot—a lot—like hand falls off from writing amounts.\n<p>At Level 2, you need a policy for every single one of the 17 domains in CMMC. This does not necessarily mean you must have 17 different documents, but you can. At Level 3, you need to document the procedures for implementing these policies, in addition to having a plan to budget and resource for these procedures.</p>\n<p>If you miss any of the necessary policies, procedures, or plans, you will not be allowed to proceed. If any of these three exist in draft form, you will not be allowed to not proceed. If you have confused procedures and plans, you will not be allowed to proceed.</p>\n<h2>Completed Self-Assessment</h2>\nYou need to certify that you have assessed yourself, and have no open action items on the 705 assessment objectives of CMMC.\n<p>The information owner of the organziation seeking certification must validate the completion of the self assessment.</p>\n<h2>No Open Plans of Action</h2>\nLevel 3 CMMC certification is a binary assessment. Do or do not—there is no try. If you score a 704/705, and therefore are compliant on 99.85% of assessment objectives, you will fail. While there is no penalty for a low score on Medium, High, or Basic Self-Assessments, Level 3 CMMC Assessments follow Yoda rules. \n<h2>Customer Responsibilities Matrix</h2>\nIf you use a Managed Service Provider or a Managed Security Service Provider, you need to know what assessment objectives they help you meet, which ones they do not, and which ones you share with them. \n<p>You then have to work these matrices into your procedures to make sure you complete your shared obligations.</p>\n<p>If either step goes missing, you will not be allowed to proceed with certification.</p>\n<h2>Procedures are Repeatable</h2>\nYou must have your procedures written in such a way that an assessor can repeat them and get the same result you get, every time.\n<p>If you cannot follow your procedures, or if they are not reliably replicable, you will not be allowed to proceed.</p>\n<img src=\"https://cdn.uploads.micro.blog/29546/2021/9acb031b63.png\" width=\"366\" height=\"600\" alt=\"\" />\n",
        "date_published": "2021-07-07T12:28:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/07/07/prrequisites-for-a.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/07/06/how-long-does.html",
        "title": "How Long Does a CMMC Assessment Take?",
        "content_html": "<p>I don&rsquo;t know. You don&rsquo;t know. Nobody knows.</p>\n<p>The scoping and final methodology guides have yet to hit the press as we await approval from the Department of Defense.</p>\n<p>Until then we guess, but with observable evidence in mind.</p>\n<p>The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) portion of the Defense Contract Management Agency verified the self-assessment of a few organizations that attested to NIST-SP-800-171 compliance. To date they have conducted around 200 assessments of various kinds. Only a small portion of the 200 assessments conducted to date are CMMC Level 3 Assessments, which consist of both a High Assessment by DIBCAC and additional CMMC controls.</p>\n<p>Under the new interim rules of the Defense Federal Acquisition Regulation, supplemental assessments come in four flavors. First, there is the home made variety of Basic-Self assessments, called the 7018. These are followed by Medium Assessments, which are conducted by DIBCAC off-site, and fall under 7019; the majority of the 200 assessments conducted to date have been at this level. The High Assessment flavor of 7020 requires an on-site, in-depth review of the implementation of 701 from DIBCAC. Finally, the banana split of them all—171—comes with CMMC sprinkles. Don&rsquo;t worry; only the Undersecretary of A&amp;S has hands on this jummy jar.</p>\n<p>So, currently you get a call and DIBCAC asks for documents, or they may roll in to kick the tires on the System Security Plan (SSP) and the Plan of Action and Milestone.</p>\n<p>For the C3PAO, things are a bit different. They need 100% compliance on all 705 assessment objectives. In the case of a Level 3 CMMC Assessment, scoring a 704 out of 705 means failure. Under the interim rule, you can still have a POA&amp;M; Medium, High, and Basic Self-Assessments are scored on a scale of -203 to 110, and there is no penalty for a low score. However, you will be need to pass these assessments with flying colors before you will be able to consider passing a Level 3 CMMC Assessment. On a CMMC Assessment performed by DIBCAC for a C3PAO, you can have no open assessment objectives.</p>\n<h3>Six Week Assessment Cycle</h3>\n<img class=\"alignnone wp-image-622 size-large\" src=\"http://ctcmmccoalition.com/wp-content/uploads/2021/07/DCMA-DIBCAC-Lessons-Learned-Slide-2-1024x571.png\" alt=\"\" width=\"1024\" height=\"571\" />\n<p>Overall, the assessments take around six weeks. Most of these assessments occurred during the COVID-19 lockdown, and it has been speculated that the circumstances of the pandemic may have extended the timeline, although this is doubtful.</p>\n<p>Four weeks before an assessment begins, DIBCAC meets with the Organization Seeking Certification (OSC), in this case the Certified Third Party Assessment Organization (C3PAO) candidate. You then receive a systems set-up to exchange documents. Consider: will your company use email, or a third party file sharing service?</p>\n<p>Two weeks before an assessment, DIBCAC reviews the documents and decides if the prerequisites fall in place. They then meet with the C3PAO to discuss their go or no-go decision.</p>\n<p>One week before an assessment, DIBCAC finalizes the assessment plan with the OSC.</p>\n<p>Then, the assessment week hits. DIBCAC has built a team and grouped domains into four loose categories. These give you clues to the types of people a C3PAO may include on an assessment team. We loosely categorize these into:</p>\n<ul>\n \t<li>Group One- Identity and Access Management</li>\n \t<li>Group Two- People and Procedures</li>\n \t<li>Group Three- Technical Systems</li>\n \t<li>Group Four- Governance</li>\n</ul>\n<img class=\"alignnone wp-image-624 size-large\" src=\"http://ctcmmccoalition.com/wp-content/uploads/2021/07/Screen-Shot-2021-07-06-at-2.26.10-PM-1024x545.png\" alt=\"\" width=\"1024\" height=\"545\" />\n<p>Then for one week—in some cases two, if the assessment goes long— the assessment takes place. Following this, the final report is written by the DIBCAC team.</p>\n<p>As we have no official assessment process to share; we can only guess at what the Department of Defense will do by looking at what the Department of Defense does in the coming months.</p>\n<p>Just remember, CMMC is a bit off. 2026 does not even show up on desk calendars.</p>\n<p>Until then, grow the SSP and shrink the POA&amp;M.</p>\n<p>featured image:</p>\n<p><a title=\"TIme\" href=\"https://flickr.com/photos/dominichargreaves/29161572685\">TIme</a> flickr photo by <a href=\"https://flickr.com/people/dominichargreaves\">Dominic Hargreaves</a> shared under a <a href=\"https://creativecommons.org/licenses/by-sa/2.0/\">Creative Commons (BY-SA) license</a></p>\n<p>source: DIBCAC CMMC Assessment Team (April 2021).  Candidate C3PAO Brown Bag. Defense Industrial Base Cybersecurity Assessment Center (DIBCAC)</p>\n",
        "date_published": "2021-07-06T14:39:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/07/06/how-long-does.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/06/24/controlled-unclassified-glossary.html",
        "title": "Controlled Unclassified Information Glossary",
        "content_html": "<p>Need a Controlled Unclassified Information cheat cheet? Getting an acronym induced migraine?</p>\n<p>Look no further for relief than this handy-dandy CUI Glossary ripped, remixed, and reused verbatim from the Code of  Federal Regulations.</p>\n<p><a title=\"dictionary focus\" href=\"https://flickr.com/photos/chrisdlugosz/3405152555\"><img src=\"https://live.staticflickr.com/3626/3405152555_464ab7b6d4_z.jpg\" alt=\"dictionary focus\" /></a><br /><small><a title=\"dictionary focus\" href=\"https://flickr.com/photos/chrisdlugosz/3405152555\">dictionary focus</a> flickr photo by <a href=\"https://flickr.com/people/chrisdlugosz\">Cubosh</a> shared under a <a href=\"https://creativecommons.org/licenses/by/2.0/\">Creative Commons (BY) license</a></small></p>\n<p><strong>Agency</strong> (also Federal agency, executive agency, executive branch agency) is any “executive agency,” as defined in 5 U.S.C. 105; the United States Postal Service; and any other independent entity within the executive branch that designates or handles CUI.</p>\n<p><strong>Agency CUI policies</strong> are the policies the agency enacts to implement the CUI Program within the agency. They must be in accordance with the Order, this part, and the CUI Registry and approved by the CUI EA.</p>\n<p><strong>Agreements and arrangements</strong> are any vehicle that sets out specific CUI handling requirements for contractors and other information-sharing partners when the arrangement with the other party involves CUI. Agreements and arrangements include, but are not limited to, contracts, grants, licenses, certificates, memoranda of agreement/arrangement or understanding, and information-sharing agreements or arrangements. When disseminating or sharing CUI with non-executive branch entities, agencies should enter into written agreements or arrangements that include CUI provisions whenever feasible (see § 2002.16(a)(5) and (6) for details). When sharing information with foreign entities, agencies should enter agreements or arrangements when feasible (see § 2002.16(a)(5)(iii) and (a)(6) for details).</p>\n<p><strong>Authorized holder</strong> is an individual, agency, organization, or group of users that is permitted to designate or handle CUI, in accordance with this part.</p>\n<p><strong>Classified information</strong> is information that Executive Order 13526, “Classified National Security Information,” December 29, 2009 (3 CFR, 2010 Comp., p. 298), or any predecessor or successor order, or the Atomic Energy Act of 1954, as amended, requires agencies to mark with classified markings and protect against unauthorized disclosure.</p>\n<p><strong>Controlled environment</strong> is any area or space an authorized holder deems to have adequate physical or procedural controls (e.g., barriers or managed access controls) to protect CUI from unauthorized access or disclosure.</p>\n<p><strong>Control level</strong> is a general term that indicates the safeguarding and disseminating requirements associated with CUI Basic and CUI Specified.</p>\n<p><strong>Controlled Unclassified Information</strong> (CUI) is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. However, CUI does not include classified information (see paragraph (e) of this section) or information a non-executive branch entity possesses and maintains in its own systems that did not come from, or was not created or possessed by or for, an executive branch agency or an entity acting for an agency. Law, regulation, or Government-wide policy may require or permit safeguarding or dissemination controls in three ways: Requiring or permitting agencies to control or protect the information but providing no specific controls, which makes the information CUI Basic; requiring or permitting agencies to control or protect the information and providing specific controls for doing so, which makes the information CUI Specified; or requiring or permitting agencies to control the information and specifying only some of those controls, which makes the information CUI Specified, but with CUI Basic controls where the authority does not specify.</p>\n<p><strong>Controls</strong> are safeguarding or dissemination controls that a law, regulation, or Government-wide policy requires or permits agencies to use when handling CUI. The authority may specify the controls it requires or permits the agency to apply, or the authority may generally require or permit agencies to control the information (in which case, the agency applies controls from the Order, this part, and the CUI Registry).</p>\n<p><strong>CUI Basic</strong>  is the subset of CUI for which the authorizing law, regulation, or Government-wide policy does not set out specific handling or dissemination controls. Agencies handle CUI Basic according to the uniform set of controls set forth in this part and the CUI Registry. CUI Basic differs from CUI Specified (see definition for CUI Specified in this section), and CUI Basic controls apply whenever CUI Specified ones do not cover the involved CUI.</p>\n<p><strong>CUI categories and subcategories</strong> are those types of information for which laws, regulations, or Government-wide policies require or permit agencies to exercise safeguarding or dissemination controls, and which the CUI EA has approved and listed in the CUI Registry. The controls for any CUI Basic categories and any CUI Basic subcategories are the same, but the controls for CUI Specified categories and subcategories can differ from CUI Basic ones and from each other. A CUI category may be Specified, while some or all of its subcategories may not be, and vice versa. If dealing with CUI that falls into a CUI Specified category or subcategory, review the controls for that category or subcategory on the CUI Registry. Also consult the agency&rsquo;s CUI policy for specific direction from the Senior Agency Official.</p>\n<p><strong>CUI category or subcategory markings</strong> are the markings approved by the CUI EA for the categories and subcategories listed in the CUI Registry.</p>\n<p><strong>CUI Executive Agent</strong> (EA) is the National Archives and Records Administration (NARA), which implements the executive branch-wide CUI Program and oversees Federal agency actions to comply with the Order. NARA has delegated this authority to the Director of the Information Security Oversight Office (ISOO).</p>\n<p><strong>CUI Program</strong> is the executive branch-wide program to standardize CUI handling by all Federal agencies. The Program includes the rules, organization, and procedures for CUI, established by the Order, this part, and the CUI Registry.</p>\n<p><strong>CUI Program manager</strong> is an agency official, designated by the agency head or CUI SAO, to serve as the official representative to the CUI EA on the agency&rsquo;s day-to-day CUI Program operations, both within the agency and in interagency contexts.</p>\n<p><strong>CUI Registry</strong> is the online repository for all information, guidance, policy, and requirements on handling CUI, including everything issued by the CUI EA other than this part. Among other information, the CUI Registry identifies all approved CUI categories and subcategories, provides general descriptions for each, identifies the basis for controls, establishes markings, and includes guidance on handling procedures.</p>\n<p><strong>CUI senior agency official</strong> (SAO) is a senior official designated in writing by an agency head and responsible to that agency head for implementation of the CUI Program within that agency. The CUI SAO is the primary point of contact for official correspondence, accountability reporting, and other matters of record between the agency and the CUI EA.</p>\n<p><strong>CUI Specified</strong> is the subset of CUI in which the authorizing law, regulation, or Government-wide policy contains specific handling controls that it requires or permits agencies to use that differ from those for CUI Basic. The CUI Registry indicates which laws, regulations, and Government-wide policies include such specific requirements. CUI Specified controls may be more stringent than, or may simply differ from, those required by CUI Basic; the distinction is that the underlying authority spells out specific controls for CUI Specified information and does not for CUI Basic information. CUI Basic controls apply to those aspects of CUI Specified where the authorizing laws, regulations, and Government-wide policies do not provide specific guidance.</p>\n<p><strong>Decontrolling</strong> occurs when an authorized holder, consistent with this part and the CUI Registry, removes safeguarding or dissemination controls from CUI that no longer requires such controls. Decontrol may occur automatically or through agency action. See § 2002.18.</p>\n<p><strong>Designating CUI</strong> occurs when an authorized holder, consistent with this part and the CUI Registry, determines that a specific item of information falls into a CUI category or subcategory. The authorized holder who designates the CUI must make recipients aware of the information&rsquo;s CUI status in accordance with this part.</p>\n<p><strong>Designating agency</strong> is the executive branch agency that designates or approves the designation of a specific item of information as CUI.</p>\n<p><strong>Disseminating</strong> occurs when authorized holders provide access, transmit, or transfer CUI to other authorized holders through any means, whether internal or external to an agency.</p>\n<p><strong>Document</strong>  means any tangible thing which constitutes or contains information, and means the original and any copies (whether different from the originals because of notes made on such copies or otherwise) of all writings of every kind and description over which an agency has authority, whether inscribed by hand or by mechanical, facsimile, electronic, magnetic, microfilm, photographic, or other means, as well as phonic or visual reproductions or oral statements, conversations, or events, and including, but not limited to: Correspondence, email, notes, reports, papers, files, manuals, books, pamphlets, periodicals, letters, memoranda, notations, messages, telegrams, cables, facsimiles, records, studies, working papers, accounting papers, contracts, licenses, certificates, grants, agreements, computer disks, computer tapes, telephone logs, computer mail, computer printouts, worksheets, sent or received communications of any kind, teletype messages, agreements, diary entries, calendars and journals, printouts, drafts, tables, compilations, tabulations, recommendations, accounts, work papers, summaries, address books, other records and recordings or transcriptions of conferences, meetings, visits, interviews, discussions, or telephone conversations, charts, graphs, indexes, tapes, minutes, contracts, leases, invoices, records of purchase or sale correspondence, electronic or other transcription of taping of personal conversations or conferences, and any written, printed, typed, punched, taped, filmed, or graphic matter however produced or reproduced. Document also includes the file, folder, exhibits, and containers, the labels on them, and any metadata, associated with each original or copy. Document also includes voice records, film, tapes, video tapes, email, personal computer files, electronic matter, and other data compilations from which information can be obtained, including materials used in data processing.</p>\n<p><strong>Federal information system</strong>  is an information system used or operated by an agency or by a contractor of an agency or other organization on behalf of an agency. 44 U.S.C. 3554(a)(1)(A)(ii).</p>\n<p><strong>Foreign entity</strong>  is a foreign government, an international organization of governments or any element thereof, an international or foreign public or judicial body, or an international or foreign private or non-governmental organization.</p>\n<p><strong>Formerly Restricted Data</strong> (FRD) is a type of information classified under the Atomic Energy Act, and defined in 10 CFR 1045, Nuclear Classification and Declassification.</p>\n<p><strong>Handling</strong> is any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information.</p>\n<p><strong>Lawful Government purpose</strong> is any activity, mission, function, operation, or endeavor that the U.S. Government authorizes or recognizes as within the scope of its legal authorities or the legal authorities of non-executive branch entities (such as state and local law enforcement).</p>\n<p><strong>Legacy material</strong> is unclassified information that an agency marked as restricted from access or dissemination in some way, or otherwise controlled, prior to the CUI Program.</p>\n<p><strong>Limited dissemination control</strong> is any CUI EA-approved control that agencies may use to limit or specify CUI dissemination.</p>\n<p><strong>Misuse of CUI</strong>  occurs when someone uses CUI in a manner not in accordance with the policy contained in the Order, this part, the CUI Registry, agency CUI policy, or the applicable laws, regulations, and Government-wide policies that govern the affected information. This may include intentional violations or unintentional errors in safeguarding or disseminating CUI. This may also include designating or marking information as CUI when it does not qualify as CUI.</p>\n<p><strong>National Security System</strong> is a special type of information system (including telecommunications systems) whose function, operation, or use is defined in National Security Directive 42 and 44 U.S.C. 3542(b)(2).</p>\n<p><strong>Non-executive branch entity</strong> is a person or organization established, operated, and controlled by individual(s) acting outside the scope of any official capacity as officers, employees, or agents of the executive branch of the Federal Government. Such entities may include: Elements of the legislative or judicial branches of the Federal Government; state, interstate, tribal, or local government elements; and private organizations. Non-executive branch entity does not include foreign entities as defined in this part, nor does it include individuals or organizations when they receive CUI information pursuant to federal disclosure laws, including the Freedom of Information Act (FOIA) and the Privacy Act of 1974.</p>\n<p><strong>On behalf of an agency</strong> occurs when a non-executive branch entity uses or operates an information system or maintains or collects information for the purpose of processing, storing, or transmitting Federal information, and those activities are not incidental to providing a service or product to the Government.</p>\n<p><strong>Order</strong> is Executive Order 13556, Controlled Unclassified Information, November 4, 2010 (3 CFR, 2011 Comp., p. 267), or any successor order.</p>\n<p><strong>Portion</strong> is ordinarily a section within a document, and may include subjects, titles, graphics, tables, charts, bullet statements, sub-paragraphs, bullets points, or other sections.</p>\n<p><strong>Protection</strong>  includes all controls an agency applies or must apply when handling information that qualifies as CUI.</p>\n<p><strong>Public release</strong> occurs when the agency that originally designated particular information as CUI makes that information available to the public through the agency&rsquo;s official public release processes. Disseminating CUI to non-executive branch entities as authorized does not constitute public release. Releasing information to an individual pursuant to the Privacy Act of 1974 or disclosing it in response to a FOIA request also does not automatically constitute public release, although it may if that agency ties such actions to its official public release processes. Even though an agency may disclose some CUI to a member of the public, the Government must still control that CUI unless the agency publicly releases it through its official public release processes.</p>\n<p><strong>Records</strong> are agency records and Presidential papers or Presidential records (or Vice-Presidential), as those terms are defined in 44 U.S.C. 3301 and 44 U.S.C. 2201 and 2207. Records also include such items created or maintained by a Government contractor, licensee, certificate holder, or grantee that are subject to the sponsoring agency&rsquo;s control under the terms of the entity&rsquo;s agreement with the agency.</p>\n<p><strong>Required or permitted (by a law, regulation, or Government-wide policy)</strong> is the basis by which information may qualify as CUI. If a law, regulation, or Government-wide policy requires that agencies exercise safeguarding or dissemination controls over certain information, or specifically permits agencies the discretion to do so, then that information qualifies as CUI. The term &lsquo;specifically permits&rsquo; in this context can include language such as “is exempt from” applying certain information release or disclosure requirements, “may” release or disclose the information, “may not be required to” release or disclose the information, “is responsible for protecting” the information, and similar specific but indirect, forms of granting the agency discretion regarding safeguarding or dissemination controls. This does not include general agency or agency head authority and discretion to make decisions, risk assessments, or other broad agency authorities, discretions, and powers, regardless of the source. The CUI Registry reflects all appropriate authorizing authorities.</p>\n<p><strong>Restricted Data</strong> (RD) is a type of information classified under the Atomic Energy Act, defined in 10 CFR part 1045, Nuclear Classification and Declassification.</p>\n<p><strong>Re-use</strong> means incorporating, restating, or paraphrasing information from its originally designated form into a newly created document.</p>\n<p><strong>Self-inspection</strong> is an agency&rsquo;s internally managed review and evaluation of its activities to implement the CUI Program.</p>\n<p><strong>Unauthorized disclosure</strong> occurs when an authorized holder of CUI intentionally or unintentionally discloses CUI without a lawful Government purpose, in violation of restrictions imposed by safeguarding or dissemination controls, or contrary to limited dissemination controls.</p>\n<p><strong>Uncontrolled unclassified information</strong> is information that neither the Order nor the authorities governing classified information cover as protected. Although this information is not controlled or classified, agencies must still handle it in accordance with Federal Information Security Modernization Act (FISMA) requirements.</p>\n<p><strong>Working papers</strong> are documents or materials, regardless of form, that an agency or user expects to revise prior to creating a finished product.</p>\n<p>source: 32 Code of Federal Regulations. Section 2002.4-Definitions</p>\n",
        "date_published": "2021-06-24T09:42:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/06/24/controlled-unclassified-glossary.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/06/18/where-do-i.html",
        "title": "Where do I Begin My CMMC Journey?",
        "content_html": "<p>Stop looking for the easy button. Hang up on those who say, &ldquo;Turn Key&rdquo;</p>\n<p>Then get started, you may have more done than you think.</p>\n<p>Do not go to page one of the CMMC Assessment Guide Level Three and open up to page 10 and start with Access Control (AC.) 1.00.1</p>\n<blockquote>Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).</blockquote>\n<p>First by now you know only the assessment objectives matter. You must have enough observable evidence (multiple pieces of each) on the following AO&rsquo;s to reach compliance on AC 1.00.1</p>\n<p>Determine if:</p>\n<ul>\n<li>[a] authorized users are identified;</li>\n<li>[b] processes acting on behalf of authorized users are identified;</li>\n<li>[c] devices (and other systems) authorized to connect to the system are identified;</li>\n<li>[d] system access is limited to authorized users;</li>\n<li>[e] system access is limited to processes acting on behalf of authorized users; and</li>\n<li>[f] systemaccessislimitedtoauthorizeddevices(includingothersystems).</li>\n</ul>\n<p>Do not start here. Heads explode, you begin to think people comes from a different planet.</p>\n<div style=\"width:100%;height:0;padding-bottom:54%;position:relative;\"><iframe src=\"https://giphy.com/embed/1aKKuZOjn3qUg\" width=\"100%\" height=\"100%\" style=\"position:absolute\" frameBorder=\"0\" class=\"giphy-embed\" allowFullScreen></iframe></div><p><a href=\"https://giphy.com/gifs/movie-film-1990s-1aKKuZOjn3qUg\"></a></p>\n<h2 id=\"define-the-roles\">Define the Roles</h2>\n<p>In our training classes for the Organizations Seeking Cerification we say begin by determining <a href=\"https://www.drmacscybersecuritybrief.com/2021/06/17/who-took-the.html\">who has the authority</a> over different parts of your System Security Plan (SSP) (see NIST-SP-800-18 for more).</p>\n<iframe src=\"https://giphy.com/embed/B1TMcmoBAaSZi\" width=\"480\" height=\"360\" frameBorder=\"0\" class=\"giphy-embed\" allowFullScreen></iframe><p><a href=\"https://giphy.com/gifs/south-park-cartman-cops-B1TMcmoBAaSZi\"></a></p>\n<p>In small companies people often where all the hats. Still possible but you just need to initialize each one. After that we do not encourage folks to go right into counting and determining where Controlled Unclassified Information lives.</p>\n<h2 id=\"count-stuff\">Count Stuff</h2>\n<p>We also encourage folks to inventory their policy very early on. Employee handbooks, meeting minutes, onboarding docs, etc. Even if you have informal systems in long email chains find this stuff. It will help when you use a template or policy package from a vendor.</p>\n<p>Then try to count where CUI lives in your system and what % of revenue comes in from contracts that flow down the DFARS 7012 clause.</p>\n<p>From there nobody can tell you the correct right step. Every system and company in totally different state. A three year old SBIR funded machine learning company may use the latest and greatest in uncompliant technology and a sixty year old manufacturer pays more in end of life extension fees for uncompliant technology.</p>\n<div style=\"width:100%;height:0;padding-bottom:72%;position:relative;\"><iframe src=\"https://giphy.com/embed/4JVTF9zR9BicshFAb7\" width=\"100%\" height=\"100%\" style=\"position:absolute\" frameBorder=\"0\" class=\"giphy-embed\" allowFullScreen></iframe></div><p><a href=\"https://giphy.com/gifs/achievementhunter-rooster-teeth-achievement-hunter-off-topic-ah-4JVTF9zR9BicshFAb7\">via GIPHY</a></p>\n<h2 id=\"basics-of-cybersecurity\">Basics of Cybersecurity</h2>\n<p>We lean heavily on focusing on:</p>\n<ol>\n<li>Policy</li>\n<li>Access Control</li>\n<li>Inventory</li>\n<li>Awareness and Training</li>\n<li>Governance</li>\n</ol>\n<p>Before you even start thinking about your major techncal controls. Using these five roots of cybersecurity you should have enough skill to rough out a sketch of your data flow and network diagrams.</p>\n<p>A basic understanding of your scope. Now you can engage with cybersecurity and compliance experts on completing a true scoping assessment to prepare for a formative assessment before seeking a summative certification assessment.</p>\n<p>At the same time we wonder if you should think about CMMC compliance as starting with Awareness and Training Domain.</p>\n<div style=\"width:100%;height:0;padding-bottom:50%;position:relative;\"><iframe src=\"https://giphy.com/embed/26BROFLJSFhP0cMGk\" width=\"100%\" height=\"100%\" style=\"position:absolute\" frameBorder=\"0\" class=\"giphy-embed\" allowFullScreen></iframe></div><p><a href=\"https://giphy.com/gifs/art-illustration-liannedias-26BROFLJSFhP0cMGk\">via GIPHY</a></p>\n<h2 id=\"awareness-and-training-first\">Awareness and Training First?</h2>\n<p>Can you complete your SSP as you utilize and also reach compliance on the Awareness and Training domain? Would this approach lead to increased hygeine?</p>\n<p>Everyone frets over CMMC devolving into a checklist of policy and confusing technical controls. Awareness and Training makes this difference.</p>\n<div style=\"width:100%;height:0;padding-bottom:100%;position:relative;\"><iframe src=\"https://giphy.com/embed/lxN6uqrkziktujpAnH\" width=\"100%\" height=\"100%\" style=\"position:absolute\" frameBorder=\"0\" class=\"giphy-embed\" allowFullScreen></iframe></div><p><a href=\"https://giphy.com/gifs/kochstrasse-hannover-agencylife-agenturleben-lxN6uqrkziktujpAnH\">via GIPHY</a></p>\n",
        "date_published": "2021-06-18T14:01:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/06/18/where-do-i.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/06/17/who-took-the.html",
        "title": "Who took the Cake Marked CUI from the Fridge? CMMC and Data Ownership",
        "content_html": "<p>We have all seen or felt the rage. You go into fridge to grab the gooey cooey chocolate volcano cake you labeled in the fridge and the shelf laughs back at you with an eerily empty cackle. Someone did not know who owned the cake.</p>\n<p><a title=\"\" href=\"https://flickr.com/photos/carolineracine/4215368082\"><img src=\"https://live.staticflickr.com/2749/4215368082_4b41706c35_z.jpg\" alt=\"\" /></a><br /><small><a title=\"\" href=\"https://flickr.com/photos/carolineracine/4215368082\"></a> flickr photo by <a href=\"https://flickr.com/people/carolineracine\">carolinerac</a> shared under a <a href=\"https://creativecommons.org/licenses/by-nc-nd/2.0/\">Creative Commons (BY-NC-ND) license</a></small></p>\n<p>Almost all the guidance on CMMC tells you to start with determining where and how CUI flows through your system. You might want to first figure out who gets to decide the lunch policy and what goes in the fridge.</p>\n<p>Not to mention many a prime might tell you, &ldquo;We don&rsquo;t know if we send you CUI but you must have a system that supports receiving CUI if you want future contracts.&rdquo;</p>\n<p>So start with deciding whose in charge.</p>\n<h2>CMMC and Data Ownership.</h2>\nTo understand the team your company brings to the dance we turn to <span class=\"author-a-5oz66zz86zsg2z69za0z86zj8nz66zk\">NIST SP 800-18</span>. The document basically begins with deciding where the buck stops.\n<h3>What is Management Operation?</h3>\n<blockquote>In order for the plans to adequately reflect the protection of the resources, a senior management official must authorize a system to operate. The authorization of a system to process information, granted by a management official, provides an important quality control. By authorizing processing in a system, the manager accepts its associated risk.</blockquote>\nSo before you even decide how you want CUI to flow you gotta know who signs the dotted line.\n<h2>Roles and Responsibility</h2>\nManagement authorization should be based on an assessment of management, operational, and technical controls.\n<ol>\n \t<li>Security Officer</li>\n \t<li> Information Systems Owner</li>\n \t<li> Information Owner</li>\n</ol>\n<span id=\"page117R_mcid29\" class=\"markedContent\"><span dir=\"ltr\">According to NIST you appoint a The Chi</span><span dir=\"ltr\">ef Infor</span><span dir=\"ltr\">mation Offi</span><span dir=\"ltr\">cer.</span></span>\n<p><span id=\"page117R_mcid29\" class=\"markedContent\"><span dir=\"ltr\"><blockquote>(CIO)</span><span dir=\"ltr\"> is the agency official responsible for developing </span><span dir=\"ltr\">and m</span><span dir=\"ltr\">aintaining an agen</span><span dir=\"ltr\">cy-wide inf</span><span dir=\"ltr\">orm</span><span dir=\"ltr\">ati</span><span dir=\"ltr\">on security program and has the following </span><span dir=\"ltr\">responsibilities for syst</span><span dir=\"ltr\">em security planning</blockquote></span></span></p>\n<p>Most small manufacturers do not have a CIO. You either use a Managed Service Provider or you as CEO do it. Sometimes people choose Deborah in accounting because she keeps that WordPress site about her Gobots collection. But usually just you.</p>\n<ul>\n \t<li><span id=\"page117R_mcid31\" class=\"markedContent\"><span dir=\"ltr\">The CIO chooses the senior agency inform</span><span dir=\"ltr\">ation s</span><span dir=\"ltr\">ecurity officer (probably also you, an MSP, or Deborah).\n</span></span></li>\n \t<li>Develop all the security procedures  and policies(copy and paste SANS templates)</li>\n \t<li>Do all the cybersecurity stuff</li>\n \t<li>Do all the cybersecurity training stuff</li>\n</ul>\nThe Information Systems Owner, according to NIST, still probably just you, keeps all your wifi and printers going.\n<blockquote>Official responsible for the overall procurement, development, integration, modification, or operation and maintenance of the information system.</blockquote>\n<ul>\n \t<li>Write the system security plan</li>\n \t<li>Maintain and monitor the security plan</li>\n \t<li>Make sire people do the cybersecurity training</li>\n \t<li>Update the system security plan</li>\n \t<li>Help with implementing practices and processes</li>\n</ul>\nThe information owner, and unless we talking Intellectual Property, with CUI, we mean the Department of Defense, but in terms of your company you need to know who:\n<ul>\n \t<li>Establishes the roles and rules</li>\n \t<li>Help with security</li>\n \t<li>Decide who gets access to sensitive information</li>\n</ul>\nNIST SP 800-18 lists a few other jobs but we have already described three jobs past your headcount. Deborah quit when saw she had to do government level controls on private sector budgets.</span>\n<p>NIST wrote the guide to writing security plans for the government not for your small business. Just remember that you do need to decide who acts as the authorizing agent. Who says:</p>\n<ul>\n \t<li>Our System Security Plan good to go</li>\n \t<li>Authorize the information system</li>\n \t<li>Denies access to the information system</li>\n</ul>\n<p>When you begin your CMMC journey you need to decide who gets to play boss of the SSP, the information system, and all the people. And please stop taking food out of the fridge that does not have your name.</p>\n",
        "date_published": "2021-06-17T08:26:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/06/17/who-took-the.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/06/08/what-practices-and.html",
        "title": "What Practices and Assessment Objectives from CMMC apply to CUI?",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2021/0e82c89eab.jpg\" width=\"450\" height=\"600\" alt=\"\" />\n<p>Sometimes to get a job done you just need Data.</p>\n<p>In the Cybersecurity Maturity Model Certification program, with five levels of cyber hygeine,  almost all the Domains, practicies, and assessment objectives implicity require you to follow the regulations for the authorized handling of sensitive data: Controlled Unclassified Information (CUI) on non-federal systems (your computers, phones, internet, and other stuff).</p>\n<p>The major baseline for CMMC Level 3, which the Department of Defense will require for handling of CUI, builds off of NIST SP 800-171, &ldquo;Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations.&rdquo; Basically everything after the first Level in CMMC has a role in protecting CUI.</p>\n<p>Yet you should know the assessment objectives that explicitly call out CUI. Once you know you have CUI in your business use need to scope out your CMMC assessment. This means  you need think about your data flow from the DoD, or a prime, and all your subcontractors. You need to inventory all assets in and out of scope, you need a network diagram,  and need to know what third party or Software as a Service  companies you use and if they fall in scope or out of scope <a href=\"https://www.cmmc-coa.com/cmmc-kill-chain\">(CMMC Kill Chain, 2002)</a>.</p>\n<p>This sounds like a lot. It is. You <strikethrough> probably </strikethrough> need a professional.</p>\n<p>Still before engaging a vendor you should have a good understanding the assessment objectives that explicitly call out CUI. May provide you with a good place to start before enganging a cybersecurity Professional.</p>\n<h2 id=\"ac2005\">AC.2.005</h2>\n<p>Provide privacy and security notices consistent with applicable CUI rules.</p>\n<h3 id=\"assessment-objectives-nist-sp-800-171a\">ASSESSMENT OBJECTIVES [NIST SP 800-171A]</h3>\n<p>[a] privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category; and</p>\n<p>[b] privacy and security notices are displayed.</p>\n<h2 id=\"ac2006\">AC.2.006</h2>\n<p>Limit use of portable storage devices on external systems.</p>\n<h3 id=\"assessment-objectives-nist-sp-800-171a-1\">ASSESSMENT OBJECTIVES [NIST SP 800-171A]</h3>\n<p>[a]  the use of portable storage devices containing CUI on external systems is identified and documented;</p>\n<p>[b]  limits on the use of portable storage devices containing CUI on external systems are defined; and</p>\n<p>[c]  the use of portable storage devices containing CUI on external systems is limited as defined.</p>\n<h2 id=\"ac2016\">AC.2.016</h2>\n<p>Control the flow of CUI in accordance with approved authorizations.</p>\n<h3 id=\"assessment-objectives-nist-sp-800-171a-2\">ASSESSMENT OBJECTIVES [NIST SP 800-171A]</h3>\n<p>Determine if:\n[a]  information flow control policies are defined;</p>\n<p>[b]  methods and enforcement mechanisms for controlling the flow of CUI are defined;</p>\n<p>[c]  designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified;</p>\n<p>[d]  authorizations for controlling the flow of CUI are defined; and</p>\n<p>[e]  approved authorizations for controlling the flow of CUI are enforced.</p>\n<h2 id=\"ac3014\">AC.3.014</h2>\n<p>Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.</p>\n<h3 id=\"assessment-objectives-nist-sp-800-171a-3\">ASSESSMENT OBJECTIVES [NIST SP 800-171A]</h3>\n<p>[a] cryptographic mechanisms to protect the confidentiality of remote access sessions are identified; and</p>\n<p>[b] cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented.</p>\n<h2 id=\"ac3020\">AC.3.020</h2>\n<p>Control connection of mobile devices.</p>\n<h3 id=\"assessment-objectives-nist-sp-800-171a-4\">ASSESSMENT OBJECTIVES [NIST SP 800-171A]</h3>\n<p>[a] mobile devices that process, store, or transmit CUI are identified;</p>\n<p>[b] mobile device connections are authorized; and</p>\n<p>[c] mobile device connections are monitored and logged.</p>\n<h2 id=\"ac3022\">AC.3.022</h2>\n<p>Encrypt CUI on mobile devices and mobile computing platforms.</p>\n<h3 id=\"assessment-objectives-nist-sp-800-171a-5\">ASSESSMENT OBJECTIVES [NIST SP 800-171A]</h3>\n<p>[a] mobile devices and mobile computing platforms that process, store, or transmit CUI are identified; and</p>\n<p>[b] encryption is employed to protect CUI on identified mobile devices and mobile computing platforms.</p>\n<h2 id=\"am3036\">AM.3.036</h2>\n<p>Define procedures for the handling of CUI data.</p>\n<h3 id=\"assessment-objectives-cmmc\">ASSESSMENT OBJECTIVES [CMMC]</h3>\n<p>Determine if:\n[a] the organization establishes and maintains one or more processes or procedures for handling CUI data.</p>\n<h2 id=\"at2056\">AT.2.056</h2>\n<p>Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.</p>\n<h3 id=\"assessment-objectives-nist-sp-800-171a-6\">ASSESSMENT OBJECTIVES [NIST SP 800-171A]</h3>\n<p>Determine if:\n[a]  security risks associated with organizational activities involving CUI are identified;</p>\n<p>[b]  policies, standards, and procedures related to the security of the system are identified;</p>\n<p>[c]  managers, systems administrators, and users of the system are made aware of the security risks associated with their activities; and</p>\n<p>[d]  managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system.</p>\n<h2 id=\"ma3115\">MA.3.115</h2>\n<p>Ensure equipment removed for off-site maintenance is sanitized of any CUI.</p>\n<h3 id=\"assessment-objectives-nist-sp-800-171a-7\">ASSESSMENT OBJECTIVES [NIST SP 800-171A]</h3>\n<p>[a] equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI.</p>\n<h2 id=\"ma3116\">MA.3.116</h2>\n<p>Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.</p>\n<p>ASSESSMENT OBJECTIVES [NIST SP 800-171A]</p>\n<p>[a] media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI.</p>\n<h2 id=\"p2119\">P.2.119</h2>\n<p>Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.</p>\n<h3 id=\"assessment-objectives-nist-sp-800-171a-8\">ASSESSMENT OBJECTIVES [NIST SP 800-171A]</h3>\n<p>[a] paper media containing CUI is physically controlled;</p>\n<p>[b] digital media containing CUI is physically controlled;</p>\n<p>[c] paper media containing CUI is securely stored; and</p>\n<p>[d] digital media containing CUI is securely stored.</p>\n<h2 id=\"mp2120\">MP.2.120</h2>\n<p>Limit access to CUI on system media to authorized users.</p>\n<h3 id=\"assessment-objectives-nist-sp-800-171a-9\">ASSESSMENT OBJECTIVES [NIST SP 800-171A]</h3>\n<p>[a] access to CUI on system media is limited to authorized users.</p>\n<h2 id=\"mp3122\">MP.3.122</h2>\n<p>Mark media with necessary CUI markings and distribution limitations.</p>\n<h3 id=\"assessment-objectives-nist-sp-800-171a-10\">ASSESSMENT OBJECTIVES [NIST SP 800-171A]</h3>\n<p>[a] media containing CUI is marked with applicable CUI markings; and</p>\n<p>[b] media containing CUI is marked with distribution limitations.</p>\n<h2 id=\"mp3124\">MP.3.124</h2>\n<p>Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.</p>\n<p>ASSESSMENT OBJECTIVES [NIST SP 800-171A]</p>\n<p>[a] access to media containing CUI is controlled; and</p>\n<p>[b] accountability for media containing CUI is maintained during transport outside of controlled areas.</p>\n<h2 id=\"mp3125\">MP.3.125</h2>\n<p>Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.</p>\n<h3 id=\"assessment-objectives-nist-sp-800-171a-11\">ASSESSMENT OBJECTIVES [NIST SP 800-171A]</h3>\n<p>[a] the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards.</p>\n<h2 id=\"ps2127\">PS.2.127</h2>\n<p>Screen individuals prior to authorizing access to organizational systems containing CUI.</p>\n<h3 id=\"assessment-objectives-nist-sp-800-171a-12\">ASSESSMENT OBJECTIVES [NIST SP 800-171A]</h3>\n<p>[a] individuals are screened prior to authorizing access to organizational systems containing CUI.</p>\n<h2 id=\"ps2128\">PS.2.128</h2>\n<p>Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.</p>\n<h3 id=\"assessment-objectives-nist-sp-800-171a-13\">ASSESSMENT OBJECTIVES [NIST SP 800-171A]</h3>\n<p>Determine if:\n[a]  a policy and/or process for terminating system access and any credentials coincident with personnel actions is established;</p>\n<p>[b]  system access and credentials are terminated consistent with personnel actions such as termination or transfer; and</p>\n<p>[c]  the system is protected during and after personnel transfer actions.</p>\n<h2 id=\"pe3136\">PE.3.136</h2>\n<p>Enforce safeguarding measures for CUI at alternate work sites.</p>\n<p>ASSESSMENT OBJECTIVES [NIST SP 800-171A]</p>\n<p>[a] safeguarding measures for CUI are defined for alternate work sites; and</p>\n<p>[b] safeguarding measures for CUI are enforced for alternate work sites.</p>\n<h2 id=\"re2138\">RE.2.138</h2>\n<p>Protect the confidentiality of backup CUI at storage locations.</p>\n<h3 id=\"assessment-objectives-nist-sp-800-171a-14\">ASSESSMENT OBJECTIVES [NIST SP 800-171A]</h3>\n<p>[a] the confidentiality of backup CUI is protected at storage locations.</p>\n<h2 id=\"rm2141\">RM.2.141</h2>\n<p>Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.</p>\n<h3 id=\"assessment-objectives-nist-sp-800-171a-15\">ASSESSMENT OBJECTIVES [NIST SP 800-171A]</h3>\n<p>[a]  the frequency to assess risk to organizational operations, organizational assets, and individuals is defined; and</p>\n<p>[b]  risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency.</p>\n<h2 id=\"sc3177\">SC.3.177</h2>\n<p>Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.</p>\n<h3 id=\"assessment-objectives-nist-sp-800-171a-16\">ASSESSMENT OBJECTIVES [NIST SP 800-171A]</h3>\n<p>[a] FIPS-validated cryptography is employed to protect the confidentiality of CUI.</p>\n<h2 id=\"sc3185\">SC.3.185</h2>\n<p>Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.</p>\n<p>ASSESSMENT OBJECTIVES [NIST SP 800-171A]</p>\n<p>[a]  cryptographic mechanisms intended to prevent unauthorized disclosure of CUI are identified;</p>\n<p>[b]  alternative physical safeguards intended to prevent unauthorized disclosure of CUI are identified; and</p>\n<p>[c]  either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission.</p>\n<h2 id=\"sc3191\">SC.3.191</h2>\n<p>Protect the confidentiality of CUI at rest.</p>\n<h3 id=\"assessment-objectives-nist-sp-800-171a-17\">ASSESSMENT OBJECTIVES [NIST SP 800-171A]</h3>\n<p>[a] the confidentiality of CUI at rest is protected.</p>\n<h2 id=\"sc3193\">SC.3.193</h2>\n<p>Implement a policy restricting the publication of CUI on externally owned, publicly accessible websites (e.g., forums, LinkedIn, Facebook, Twitter).</p>\n<h3 id=\"assessment-objectives-cmmc-1\">ASSESSMENT OBJECTIVES [CMMC]</h3>\n<p>Determine if:\n[a]  the organization has a security policy which restricts publishing CUI to any externally owned, publicly accessible information system;</p>\n<p>[b]  the organization designates individuals authorized to post organization information onto any externally owned, publicly accessible information systems;</p>\n<p>[c]  the organization trains authorized individuals to ensure that publicly accessible organization information does not contain CUI;</p>\n<p>[d]  the organization conducts reviews to ensure CUI is not included in proposed content to be posted by the organization on a publicly accessible information system under its control; and</p>\n<p>[e]  the organization removes CUI, if discovered, from any publicly accessible information system under its control.</p>\n<p><a title=\"Data\" href=\"https://flickr.com/photos/awarmplace/7878915520\">Data</a> flickr photo by <a href=\"https://flickr.com/people/awarmplace\">thirteenthbat</a> shared under a <a href=\"https://creativecommons.org/licenses/by/2.0/\">Creative Commons (BY) license</a></p>\n",
        "date_published": "2021-06-08T19:08:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/06/08/what-practices-and.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/05/30/cmmc-process-assessments.html",
        "title": "CMMC Process Assessments: Get better at Doing Business",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2021/3e55c1ba6a.jpg\" width=\"600\" height=\"448\" alt=\"\" />\n<p>Getting lost in the different requirements of the Cybersecurity Maturity Model Certification? Pull back the sheets and realize much of what we mean withe practices and processes revolve around doing business better.</p>\n<p>You do practices in cybersecurity. Verbs. Controls. Compliance.</p>\n<p>These practices require processes to stick. Your company needs solid policies, documentation, and plans to implement practices. Processes. Governance. Nouns.</p>\n<p>With reflection through these processes comes security. Culture.</p>\n<p>When a company has plan to protect controlled unclassified information CUI, hires the right people, provides the training, and provides funding sensitive data gets protected.</p>\n<p>The practices in CMMC derive from controls of different security frameworks. 110 of the one hundred seventy one practices in CMMC originate from the safeguarding requirements and security requirements specified in FAR Clause 52.204-21and DFARS Clause 252.204- 7012. Level 1 is equivalent to all of the safeguarding requirements from FAR Clause 52.204-21. Level 3, building on Levels 1 and 2, includes all of the security requirements in NIST SP 800-171 plus twenty additional practices commonly called the Delta 20s (the Greek letter Delta, a triangle, means change)</p>\n<p>Basically, Cybersecurity Maturity Model Certification provides an avenue for third party attestation of NIST SP-800-171, twenty additional practices, and also measurement of process institutionalization. The process part of a CMMC assessment.</p>\n<p>Process institutionalization, or the set of repeated practices and processes that lead to stable hygeine within an organization, leads to better business practice. By focusing on institutionalizing the practices and processes of CMMC a company gains stability in times of stress and consistency of results over time.</p>\n<p>Any company who does business in the Defense Contracting space d should have a measure of their process maturity.</p>\n<h2>What is Maturity Measurement?</h2>\nMaturity models measure growth through a series of benchmark measures. Think of CMMC like the 60 inches sign on a roller coaster. You need to reach a certain level of maturity to go for a ride. CMMC, in processes, practices, and methods and set goals and priorities for improvement.\n<p>CMMC requires measurement of maturity. The assessments do not act as a growth measure, our maturation assessment. Instead you need to show compliance on every objective of every practice and process measurement.</p>\n<h3>What is Process Measurement?</h3>\nProcesses build culture. As a company you engage in specific procedural activities. CMMC has identified, using research from SEI and Carnegie Melon frrom the last 35 years, specfic maturation processes that allow cultures of cyber hygeine to thrive. These processes have five levels within CMMC.\n<p>You must meet the objectives of each of the processes at the level of certification.</p>\n<h3>An Overview of CMMC Process Maturity</h3>\nThe CMMC defines five levels of process maturity. Each level acts as a gateway benchmark assessment. You must demonstrate all level one and level two processes as well as level three in order for compliance. Five processes get measured Across CMMC. Two two processes at level two and one additional process as you move up each of level from three to five.\n<ul>\n \t<li>Level 1 requires that an organization performs the specified practices. You do not need to document any policy at level one for compliance. Meeting the security requirements of level one compliance will be easier with well written policy. rocess maturity is not assessed for Level 1.</li>\n \t<li>Level 2 requires that an organization create a plan and the policies to document the practices and processes required of CMMC. Policy, policy, policy.</li>\n \t<li>Level 3 requires that an organization establish, maintain, and resource a plan demonstrating the management of activities for practice implementation. You need to say who does what and how much you spend doing it. missions, goals, project plans, resourcing, required training, and stakeholders.</li>\n \t<li>Level 4 requires an organization to test how well things go in the implementation of the plan.</li>\n \t<li>Level 5 requires an organization to use continuous monitoring and improvement cycles.</li>\n</ul>\n<h2>History of Process Maturity Measurement</h2>\nThe process maturity assessment included in CMMC has a long history. The Software Engineering Institute began development in 1986 and released the Capability Maturity Model for Software, or CMM in 1991. The model gets used in both e Capability Maturity Model Integration (CMMI) and CERT Resilience Management Model, or CERT-RMM.\n<p>Cybersecurity takes culture and process measurement seeks to improve cybersecurity by shifting perspectives within an organization seeking certitication. Companies must measure, and understand the process, not the just use a checklist technical practices.</p>\n<p>CERT-RMM and the CMMC both measure practices and the institutionalization of these controls through process maturity assessment. In the CMMC an assessor will look for three types of processes: policy, practices, and plans. Commonly referred to as 99, 98 and 97 in the CMMC assessment guide.</p>\n<h2>Three Types of Processes</h2>\n<h3>99 Establish a policy</h3>\n(NOTE: Convert screenshots to tables for accessibility purposes)\n<img class=\"alignnone wp-image-475 size-large\" src=\"http://ctcmmccoalition.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-30-at-8.11.21-AM-1024x657.png\" alt=\"\" width=\"1024\" height=\"657\" />\n<p>Above you see the assessment objectives for the Awareness and Training Domain. These objectives requite establishing a policy process and below you thee same assessment objectives for the Access Control domain. What do you notice?</p>\n<img class=\"alignnone wp-image-476 size-large\" src=\"http://ctcmmccoalition.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-30-at-8.12.20-AM-1024x638.png\" alt=\"\" width=\"1024\" height=\"638\" />\n<h3>98 Document the CMMC practices to implement</h3>\nThe 99's require you to have policy.The 98's require a plan to make the policy come to life.\n<img class=\"alignnone wp-image-477 size-large\" src=\"http://ctcmmccoalition.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-30-at-8.13.16-AM-1024x451.png\" alt=\"\" width=\"1024\" height=\"451\" />\n<p>Above you see the assessment objectives for the Awareness and Training Domain. The 98s require you to document to implement your policies. Below you thee same assessment objectives for the Access Control domain. What do you notice?</p>\n<img class=\"alignnone wp-image-478 size-large\" src=\"http://ctcmmccoalition.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-30-at-8.14.06-AM-1024x424.png\" alt=\"\" width=\"1024\" height=\"424\" />\n<p>The 98s represent must of the practices in your SSP. However you do not want to include the line, &ldquo;See the SSP.&rdquo; This means an assessor needs tu hunt, pick, and infer. Tnree sure ways to fail an assessment.</p>\n<h3>97 Establish, maintain, and resource a plan</h3>\nIf the 98s describe your procedures for documenting CMMC practices. The 97s describe how you pay qualified people to get the job done.\n<img class=\"alignnone wp-image-479 size-large\" src=\"http://ctcmmccoalition.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-30-at-8.15.09-AM-1024x762.png\" alt=\"assessment objectiveds of AT.3.997\" width=\"1024\" height=\"762\" />\n<p>Above you see the assessment objectives for the Awareness and Training Domain. The 99s require you to budget and staff yoyr . Below you thee same assessment objectives for the Access Control domain. What do you notice?</p>\n<img class=\"alignnone wp-image-480 size-large\" src=\"http://ctcmmccoalition.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-30-at-10.05.53-AM-1024x820.png\" alt=\"Assessment objectives for AC.3.997\" width=\"1024\" height=\"820\" />\n<p>Across the 99s, 98s, and 99s we notice that the assessments objectives do not change. So you can come up with a template to make process asessment easier. You will not write 17 mission statements with goals and objectives. Many of the observable evidence will get used over and over. As an Organization Seeking Certification you need to draw an explicit link to your observable evidence and the assessments.</p>\n<h2>Where does Observable Evidence Live?</h2>\nBefore you think about process institutionalization take inventory of where your policy and procedures already live. You can find this in both policy and day to operation. Begin this effort by taking inventory of policies you already have at your company:\n<ul>\n \t<li>Employee Handbooks</li>\n \t<li>Employee Agreements</li>\n \t<li>HR Onboarding, Screening, and Termination</li>\n \t<li>Org Chart</li>\n \t<li>System Security Plan</li>\n \t<li>Threat Diagram</li>\n \t<li>Job Descriptions with Separation of Duty</li>\n \t<li>Nondisclosure agreements</li>\n \t<li>Vendor agreements</li>\n \t<li>Floor plan</li>\n \t<li>Visitor Guide</li>\n \t<li>Visitor logs</li>\n \t<li>Inventory Policy</li>\n \t<li>Awareness and Training Policy</li>\n \t<li>Project Scoping Policy</li>\n \t<li>Business Continuation Plan</li>\n \t<li>Disaster Recovery Plan</li>\n \t<li>Acceptable Use Policy</li>\n \t<li>Clean Desk Policy</li>\n \t<li>Password/MFA Policy</li>\n \t<li>Remote work station polic</li>\n \t<li>Acceptable Encryption Policy</li>\n \t<li>Account Management Policy.</li>\n \t<li>Audit Policy.</li>\n \t<li>Configuration Management Policy</li>\n \t<li>Email Policy (don't do dumb footers)</li>\n \t<li>Federal Contract Information Policy</li>\n \t<li>Controlled Unclassified Information Policy</li>\n \t<li>Penetration Testing Ploicy</li>\n \t<li>Software Installation Policy</li>\n \t<li>Workstation Security Policy</li>\n</ul>\nBefore you even begin to document your institutionalization you need to inventory your existing policy and if you  have glaring holes start to write the policy but also think about how daily operations can create observation evidence for process maturity assessment.\n<p>Think about the minutes of your weekly security stand ups, perhaps you have the results of a SWOT analysis, what about the daily task checklist for newtork mantainers, or logs from your SEIM? All of these provide evidence of institutionalization.</p>\n<h2>Hacking the Text Structure</h2>\nYou will not make 17 different documents and write a different report for every 99, 98, and 97. You could and an assessor will not mark you out of compliance but you can also develop more efficient methods. Some OSCs for example combine the 98 and 97 OE into one document. Others recommend creating a spreadsheet combining all off the process objectives.\n<p>At the minimum a spreadsheet should have the following columns</p>\n<ul>\n \t<li>Explicit text from a policy. Do not just list the policy or page number Copy the text</li>\n \t<li>The domain</li>\n \t<li>The Process</li>\n \t<li>Policy Document title</li>\n</ul>\nYou want to create an index that correlates the practices to the explicit text. For CMMC Level three you need procedures to implement 130 practices. To increase the chances of passing an assessment and lowering your cost\n<p>If you are using a wiki or a document rather than a spreadsheet make the Assessment Objectives explicit headings. Then under the heading add xxplicit text from a policy. and where it can be documented. Do not just list the policy or page number. Copy the text.</p>\n<p>When documenting the budget requirements for 97 some people may create a sanitized version without PII of experts and the annual spend. You should have an unsanitized copy that does not leave your premise and is made available for an assessor to view on site.</p>\n<p>Overall focusing on process maturity will help your business succeed. Compliance and security matter but policies and governance rule.</p>\n<p><small>Image credit: <a title=\"Processing\" href=\"https://flickr.com/photos/markcph/5137142884\">&ldquo;Processing&rdquo;</a> by <a href=\"https://flickr.com/people/markcph\">marksdk</a> is licensed under <a href=\"https://creativecommons.org/licenses/by-sa/2.0/\">CC BY-SA</a> </small></p>\n<p>Work Cited;:</p>\n<p>Armond, A. (2020).Policy templates and tools for CMMC and 800-171.<a href=\"https://www.cmmcaudit.org/policy-templates-and-tools-for-cmmc-and-800-171.\">www.cmmcaudit.org/policy-te&hellip;</a></p>\n<p>Carnegie Mellon University and The Johns Hopkins University Applied Physics Laboratory LLC. (2020).  CMMC Assessment Guide Level 3. Version 1.0.1</p>\n",
        "date_published": "2021-05-30T10:48:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/05/30/cmmc-process-assessments.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/05/29/is-my-outsourced.html",
        "title": "Is My Outsourced IT Provider in  CMMC Scope?",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2021/8dcf0f5c2a.jpg\" width=\"600\" height=\"164\" alt=\"\" />\n<p>Let&rsquo;s ask the Department of Defense</p>\n<blockquote>\"Q7: Our Company has outsourced its IT support and systems to a third-party contractor. Are we still responsible for complying with DFARS clause 252.204-7012 and implementing NIST SP 800-171?”</blockquote>\n<blockquote>A7: Outsourcing your IT to another company does not transfer your DFARS clause 252.204-7012 responsibilities or implementation of NIST SP 800-171 requirements. Your company is responsible and accountable for meeting the contractual obligations with the Government as per the contract. The key to successfully demonstrating compliance with DFARS clause 252.204-7012 and NIST SP 800-171 is having a well written contract with the third-party that describes your requirements, and includes deliverables that meet or exceed requirements to protect DoD CUI. If your IT service support is deemed to be less than or non-compliant with the contract, the company contracting with DoD is ultimately responsible.</blockquote>\n<p>NIST SP 800-171 requirements make up the basline of Cybersecurity Maturity Model Certification Level Three. Your IT Provider will fall in scope if they touch or have responsibilities on networks where Controlled Unclassified Information (CUI) transverses.</p>\n<h2>What Do I Do about my IT Provider?</h2>\n<p>A few strategies exist. First follow the advice of the Department of Defense and have one vendor agreement per contract that flows down the 7012 or 7019 clause. You need to think ahead of time how CUI will flow between you and your IT provider.</p>\n<p>You can also treat your IT provider as an &ldquo;employee.&rdquo; Issue the same badges and devices. Subject a specified IT contractor to the same policies and procedures you would of anyone else with a legal need to handle CUI.</p>\n<p>Some companies utilize a vCISO, a virtual security specialist split between some companies. You may want a third party to help with the inheritance between you and your IT provider. Inheritance means practices and processes that fall in scope and under the domain of a service providers. So your IT may inherit some controls from a cloud service like Azure, they provide some responsibility, and you the customer, with the 7012 clause contract, must make not only do you complete the requirements but the IT company does what they say they do.</p>\n<p>Finally you can try and descope your IT partner, but you can not do this, probably, without increasing your own headcount. Better to choose providers that will work with you as a cybersecurity partner.</p>\n<p><small>Source: Department of Defense (December, 2020). Frequently Asked Questions (FAQs) regarding the implementation of DFARS Subpart 204.73 and PGI Subpart 204.73; DFARS Subpart 239.76 and PGI Subpart 239.76</small></p>\n<p><small><a title=\"Technology\" href=\"https://flickr.com/photos/160246067@N08/41713888041\">Technology</a> flickr photo by <a href=\"https://flickr.com/people/160246067@N08\">TLC-kios</a> shared into the public domain using <a href=\"https://creativecommons.org/publicdomain/zero/1.0/\">Creative Commons Public Domain Dedication (CC0)</a></small></p>\n",
        "date_published": "2021-05-29T09:56:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/05/29/is-my-outsourced.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/05/24/what-is-scope.html",
        "title": "What is Scope? A Jargon Free Explanation",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2021/43c5b65293.png\" width=\"600\" height=\"399\" alt=\"\" />\n<p>Our current definition of Scope comes from 16th century mid Europe when the firearm spread across the continent. Scopo, aim in Italian, derived from the Greek word skopos for target. Skopos roots lie in the word Skeptesthai ‘look out.’</p>\n<p>In terms of Cybersecurity Maturity Model Certification,o= or CMMC, &lsquo;look out&rsquo; works. You need to know where federal contract information and control unclassified systems live within your business, network, and deal flows.</p>\n<p>The NIST Guide for Developing Security Plans for Federal Information Systems defines scoping guidance as:</p>\n<blockquote>Provides organizations with specific technology-related, infrastructure-related, public access-related, scalability-related, common security control-related, and risk-related considerations on the applicability and implementation of individual security controls in the control baseline.</blockquote>\nA lot of complex jargon to define the target you paint on the people, processes, and technology that touch either FCI or CUI a comonay handles as the result or on behalf of a Department of Defense contract with the DFARS 7012 clause.\n<p>When it comes time for a CMMC assessment we only aim the light at these places. The assessor will target areas sensitive data live. So we have to know how we protect data across our networks and those of our service providers.</p>\n<p>You must know what an assessor would consider relevant when determining what parts of your business fall in scope. This includes people, processes, and technology. All three work in tandem to secure FCI and CUI.</p>\n<p>You have to know what kind of supporting documents an assessor will ask for when determining if the scope you provided matches their evaluation ofhow you protect data across your network and those of your service providers. This often begins with a network diagram</p>\n<h2>What is a Network Diagram?</h2>\nA network diagram illustrates how data moves through your system and includes \"third-party services, cloud instances and remote access methods\" (Complinace Forge, 2021).\n<p>You limit scope by creating boundaries, like a lock on a door, that only allows authorized users to interact with data they have a legal need to use. As a small business owner, a managed service provide delivering IT support, or a consultant working with an Organization Seeking Certification you need the skills to quickly rough out a network diagram. To have a true network diagram you will need to enage a cybersecurity expert to perform a formative scoping assessment.</p>\n<p>As a contractor or manufacuturer in the Defense Industrial Base you should have the ability to draw a low-level diagram, a rough cartoonish space. Your Managed Service Provider or a cybersecurity expert wil help you with a high level diagram. This needs to be detailed and identify the ports, protocols and services. A high level diagram will also account for the physical and logical boundaries that restrict access to only authorized holders.</p>\n<h3>What is a Boundary?</h3>\n<p>Amira Armond, President of Kieri Solutions, defines boundries as anything that can break and allow data spillage. The lock works as a metaphor for boundaries because your physical boundaries fall in scope. Someone can break or pick a lock and steal data. Theft is data spillage.</p>\n<p>Physical security helps us think how boundaries fit in a network diagram of the data flow in our scope. You must lock your business to keep stuff from dissapearing. So scoping guidance, and network diagrams do include physical boundaries.</p>\n<p>Just as we must lock our physcial doors we also have to restrict the public from our data on our networks and the networks of service providers. We call these logical boundaries. These logical perimeters extend to all users of a system who can output sensitve data without the intervention of another person.</p>\n<p>The Committee on National Security System, a forum for the discussion of policy issues and is responsible for setting national-level cybersecurity policies, defines logical perimters as:</p>\n<blockquote>A conceptual perimeter that extends to all intended users of the system, both directly and indirectly connected, who receive output from the system without a reliable human review by an appropriate authority</blockquote>\n<p>So basically can they print stuff off the Internet and do you need to restrict this ability to &ldquo;output&rdquo; data to certain people? Many of these logical boundaries thus fall into th Domain of Access Control, limiting who gets to see what, and when.</p>\n<p>Logical boundaries also involve the processes of your company. Does marketing need access to FCI or CUI? Do you use access control policies to create a logical boundary? You can also use technology.</p>\n<p>Just as we have doors and locks on our physical business we also keep technological locks using routers and firewalls.</p>\n<h3>What data are in scope?</h3>\n<p>You must begin by first identifying where sensitive data exists in the day to day operations of your company. First you need to identify what contracts you have that flow from Department of Defense contracts with the 7012 clause. You then have to examine what data and artifacts you receive or create for this work. Now we can consider the people, processes and technology that touch and must protect CUI and FCI.</p>\n<p>Everyone one of these projects, that have FCI or CUI need to have someone responsible for that data. Data must have an owner. Typically this could be a project manager. Often in small firms this may also be the President or CEO</p>\n<p>Once you know who owns the data now you determine who should have access to the data. You need to restrict the sensitive data to only those with a legal reason to use that data. The less people in scope often the more money you save. Every person in scope may have a workstation or want remote access.</p>\n<p>Your systems, the technology, also fall in scope. Cell phones, email servers, cloud documents, and databases all contain CUI and require protection. In fact NIST wrote NIST-SP-800-171 to protect CUI on technology systems.</p>\n<p>Finally you need to think not just about the logical boundaries but also the physical boundariesthat protect your data. What buildings or offices does the data travel through? How are these spaces connected to the network? How are they secured physically.</p>\n<h3>Is scoping an Inventory Control?</h3>\n<p>Yes. Scoping inventories where CUI and FCI live and without an inventory of your sensitive data. Just as you inventory all of the endpoints, printers, and routers that transmit CUI you must first have a list of data, the associated contract/project, and the data owner. Only then do you know the data in scope. You can now track how it moves through your company.</p>\n<h3>What is a data flow diagram?</h3>\n<p>A data flow diagram identifies how sensitive data travels through your company and the people, processes, and technology that protects Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).</p>\n<p>You begin by creating a rough data flow diagram. First think of the physical transfers, like between departments. Do you use the mail, usb drives, does someone walk the data over? Then think about digital data. Do people share FCI and CUI via email or an encrypted file sharing service? Finally do you have any processes that move data around such as your ERP or CRM?</p>\n<p>Creating a data flow diagram will help you save money. It will also act as policy. If you do not document how data travels you will not enforce how it should travel. You will fail your assessment.</p>\n<p>In your network diagram you need to consider your data handling processes. CUI, while in transit, must have encryption. Controlled Unclassified Information also has rules for encryption when at rest. These rules will change based on where data gets stored. In a desk? a server on physical premise? The cloud? All of these locations impact you flow</p>\n<h3>What about my floor plan?</h3>\n<p>Your facilities will fall in scope and you need to include them in your network diagram. As Amira Armond (2021) <a href=\"https://www.cmmcaudit.org/cmmc-scope-are-you-ready-for-an-assessment/\">notes</a>, &ldquo;Physical security measures will be assessed only at the boundaries and within the in-scope area.&rdquo;</p>\n<p>So your facilities diagram should include information about where key card access lies, where vistors have access, and where CUI or FCI will exist and travel on your floor plan.</p>\n<blockquote>CMMC Practice MP.3.125: Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.</blockquote>\nFor many companies, especially smaller firms it may be cheaper to keep your entire floor plan in scope. As you get larger, or if you are a subsidiary of a foreign firm a CUI enclave will make more sense.\n<h3>What technology is in scope?</h3>\n<p>Out of people, processes, and technology the latter makes scoping hard. It comes down to Is this machine in scope? If this machine is in scope, how does that &ldquo;contaminate&rdquo; other areas and make them in scope too? This is the real challenge.</p>\n<p>For example If Server A is in scope, then what else must be in scope? You may use Acrtive Directory as a logical boundary. In scope. What if the Active directoy that controls access to server A, has access to otherdevices on the Local access network segment for server A? This also means the Anti-Virus console for this server is in scope. This cascade only gets tricker. You really need an expert at this point.</p>\n<h3>Is My Managed Service Provide in Scope?</h3>\n<p>Maybe.The DoD nor the CMMC-AB have released scoping guidance. So it is best to use your data flow diagram. If yoru MSP touches areas and endpoints where CUI gets transmitted or stored they will fall in scope. In fact the group doing the CMMC Level 3 assessments of the C3PAOs require the the C3PAO to rprovide a compliance inheritence matrix from any managed service provider in scope.</p>\n<p>You have many MSPs. Think about your keycard access logs where do they live? What about access control policies on your third party anti-virus. What about your Enterprise email provider? You must document how these companies meet the requirements for handling sensitive data.</p>\n<h3>Are My Remote Employees in Scope?</h3>\n<p>Go back to your data diagram. If your remote or hybrid employees can send, recieve, transmit, create, or destroy FCI and CUI from an alternative site they fall in scope. You must document that you provide equitable controls at remote sites that you do at the home site. You have important technology steps to take to include remote employees in scope.</p>\n<h3>Are Suppliers and Subcontractors in Scope?</h3>\n<p>Maybe. Follow the data flow. A supplier may flow CUI down to you as a result of a contract with the 7012 clause. This of course falls in scope. For both of you. You may also have to send CUI to a supplier. Many comopanies design parts that have not changed for decades. They often need to rebid on contracts. One way to shrink your scope is to use a file sharing service. If you can keep email out of scope (not easy) you can save tens of thousandsa of dollars.</p>\n<p>You need to decide where your scope ends. The C3PAO or CCA will know you can&rsquo;t control everything a sub or a prime does. You must describe how they handle security controls. We call this inheritence.</p>\n<h3>What are the official CMMC rules on scoping?</h3>\n<p>They do not exist. The draft assessment guide reads:</p>\n<blockquote>Prior to a CMMC assessment, the contractor must define the scope for the assessment that represents the boundary for which the CMMC certificate will be issued. Additional guidance on assessment scope will be available in the next version of this CMMC Assessment.</blockquote>\n<p>The best guidance we have comes from NIST SP-800-171</p>\n<blockquote>The requirements apply to components of nonfederal systems that process, store, or transmit CUI, or that provide security protection for such components.9 If nonfederal organizations designate specific system components for the processing, storage, or transmission of CUI, those organizations may limit the scope of the security requirements by isolating the designated system components in a separate CUI security domain. Isolation can be achieved by applying architectural and design concepts (e.g., implementing subnetworks with firewalls or other boundary protection devices and using information flow control mechanisms). Security domains may employ physical separation, logical separation, or a combination of both. This approach can provide adequate security for the CUI and avoid increasing the organization’s security posture to a level beyond that which it requires for protecting its missions, operations, and assets.</blockquote>\n<h3>How do I get Started?</h3>\n<p>Jacob Horne and Ryan Bonner of DefCert suggest all companies conduct a scoping assessment. If you get the scope wrong you will fail your CMMC assessment. It all begins by inventorying the data. What DoD contracts do you have with a 7012 clause? Regardless of CUI or FCI how does that data move through your organization. Start there.</p>\n<p>img src: scope&quot; by Tagosaku <a href=\"https://flickr.com/photos/tagosaku_japan/29184375277\">flickr.com/photos/ta&hellip;</a> is licensed under CC BY-ND</p>\n",
        "date_published": "2021-05-24T09:27:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/05/24/what-is-scope.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/05/21/does-cmmc-apply.html",
        "title": "Does CMMC apply to my company?",
        "content_html": "<img src=\"https://cdn.uploads.micro.blog/29546/2021/f12f320b47.png\" width=\"600\" height=\"447\" alt=\"right and left turn sign in front of network rack\" />\n<p>In the Defense contracting world we speak of primes, those who sign the contracts, and subs, subcontractors who get work on a prime contract. As you move up the supply chain everyone acts as both a prime and sub on various contracts. If you follow the Defense supply chain all the way to the source three multinational companies control the majority of the  spend.</p>\n<p>As a small business owner in Connecticut you may wonder if CMMC, Cybersecurity Maturity Model Certification applies to you. CMMC, the new initiative launched by the Department of Defense will require a third party to assess your cybersecurity.</p>\n<p>If you are a Defense contractor or work in advanced manufacturing in Conencticut you need to follow CMMC. Starting in 2026 all defence contracts will require third party CMMC assessments. Currently defense contractors who have a contract with a specific clause, 7012 must do a self assessment. CMMC will replace this. So if you have a Defense contract start preparing.</p>\n<p>Yet you may not even have a Defense contract and may want to think about CMMC compliance.  You may even have a business relationship with some contractors who demand you get compliant with . Some contractors may demand proof you uploaded a score from a self-assessment. These business to business relationships sit outside of the DFARS contracts that govern self-assessment (7012, 7019) and CMMC (7021).</p>\n<p>As a small business owner in Connecticut you should consult cybersecurity experts and legal before sharing a System Security Plan, Plan of Action &amp; Milestone, or your SRPS score from a self-assessment. If you have contracts that flow down the 7012 clause you can check with the Program Management Officer or the Contract Officer. The Department of Defense does not usually get involved in the relationships between a prime and subcontractor.</p>\n<p>At some point you have a decision to make. Do the revenues you generate from contracts that flow down a 7012 clause generate large enough margins to justify the investment in compliance with 171 using the 171a methodology and self-assessment and then further investment into CMMC by 2026?</p>\n<p>Yet much of cybersecurity, and the non-technical controls required by CMMC, equal better business practices. In fact legislation to provide data breach liability shields sits in the Connecticut State legislature right now. One of the frameworks allowed for compliance: NIST-SP-800-171. So you have a responsibility and many other compliance tasks such ISO 27001, ISO9001, CMMI Dev L that will lead to observable evidence an assessor would use.</p>\n<p>So you kinda gotta do this cybersecurity stuff no matter what.</p>\n<p>Entrepreneurs can also see the opportunity in providing CMMC compliance. The Connecticut CMMC Coalition believes our State can import, rather than export,compliance dollars and business in what we call the NAIC Nerd codes. Millions of dollars and thousands of jobs.</p>\n<p>The contracting world uses NAICS, a coding system of business types. They are six digit codes. The 54 are all the professional, scientific, and technical services. Connecticut has long stood on as the arsenal of democracy, and we must continue this history as we shift from kinetic warfare into immersive cyber battlefields.</p>\n<p>Lot of jobs in cyber, and with our role in finance, insurance, and Defense Connecticut can attract and develop top-talent. We can pwn the NAIC Nerd codes.</p>\n<p>So in answering, “Does CMMC apply to my company?”</p>\n<p>The answer is always, “It depends.”</p>\n<p>From a legal and regulatory perspective CMMC will involve any company that will receive or create either Federal Contract Information or Controlled Unclassified Information.</p>\n<p>Federal Contract Information, data generated by or on behalf of a government contract, not meant for public release will require a CMMC Certification Level 1. Federal Acquisition regulations, FAR 52.204-21 to be exact,  requires 17 basic safeguards of this data.</p>\n<p>Controlled Unclassified information (CUI), data received or created on behalf of the U.S. government that a law, regulation, or government-wide policy requires or permits an agency to handle will require CMMC Level 3 certification.</p>\n<p>img credit: CMMC choices. A remix of &ldquo;Network Rack&rdquo; flickr photo by one individual <a href=\"https://flickr.com/photos/44176115@N07/15401776380\">flickr.com/photos/44&hellip;</a> shared under a Creative Commons (BY-SA) license and &ldquo;Choices&rdquo; flickr photo by keepitsurreal <a href=\"https://flickr.com/photos/keepitsurreal/6107919083\">flickr.com/photos/ke&hellip;</a> shared under a Creative Commons (BY-SA) license shared under a Creative Commons (BY-SA)</p>\n",
        "date_published": "2021-05-21T10:50:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/05/21/does-cmmc-apply.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/05/19/three-goals-of.html",
        "title": "Three Goals of the Cybersecurity Maturity Model Certification Program",
        "content_html": "<p>Yesterday the Office of the Under Secretary of Defense for Acquisition &amp; Sustainment helped put their goals of Cybersecurity Maturity Model Ceritification (CMMC) in focus.</p>\n<p>In fact Jesse Salazar, Deputy Assistant Secretary of Defense for Industiral Policy, on the goals of the  when <a href=\"https://www.armed-services.senate.gov/imo/media/doc/DASD%20Salazar%2020210518_CMMC%20Hearing%20-%20FINAL1.pdf\">testifying</a> at the  Senate Armed Services Committee on Cybersecurity provided these three top level goals.</p>\n<blockquote>\n  <ol>\n    <li>To incorporate a unified set of cybersecurity requirements into acquisition processes and contracting language. Recognizing that cybersecurity should not be “one-size-fits-all  ,” the program includes several levels of cyber requirements, that allow flexibility to apply requirements appropriate to the defined sensitivity level of information at issue.</li>\n<li>To provide the Department assurance, via external assessment, that all contractorsa nd subcontractors participating in a given award meet mandatory cybersecurity requirements. The certification framework also facilitates the Department’s ability to  hold prime contractors accountable for ensuring that their suppliers are, in fact, implementing appropriate cybersecurity requirements. </li>\n<li>To develop supporting resources, information, and training to help contractors improve cyber readiness and comply with the Department’s requirements.</li>\n  </ol>\n  </blockquote>\n<img src=\"https://cdn.uploads.micro.blog/29546/2021/9d1489b3df.jpg\" width=\"600\" height=\"399\" alt=\"\" />\n",
        "date_published": "2021-05-19T09:14:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/05/19/three-goals-of.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/05/12/cmmc-and-the.html",
        "title": "CMMC and the Customer Responsbility Matrix",
        "content_html": "<p>Defense Contract Management Agency says all customer responsibility matrices must be complete prior to the start of their CMMC assessments. Yet only half the people know much about them. Why?</p>\n<h2 id=\"risk-management-framework\">Risk Management Framework</h2>\n<p>If you come from a Risk Management Framework as traceability matrices or work with federal systems you are familiar with CRM but for many people in the commercial industrial base the idea is new. Many folks in the CMMC heard of customer responsibility matrices when they saw how DCMA</p>\n<p>The Institute of Electrical and Electronics Engineers  Standard Glossary of Software Engineering Terminology (1990) defines it as</p>\n<blockquote>A matrix that records the relationship between two or more products of the development process (e.g., a matrix that records the relationship between the requirements and the design of a given software component). </blockquote>\n<p>The NIST glossary then adds two notes to this definition:</p>\n<blockquote>Note 1: A traceability matrix can record the relationship between a set of requirements and one or more products of the development process and can be used to demonstrate completeness and coverage of an activity or analysis based upon the requirements contained in the matrix.</blockquote>\n <blockquote>Note 2: A traceability matrix may be conveyed as a set of matrices representing requirements at different levels of decomposition. Such a traceability matrix enables the tracing of requirements stated in their most abstract form (e.g., statement of stakeholder requirements) through decomposition steps that result in the implementation that satisfies the requirements.</blockquote>\n<p>While NIST-SP-800-37 define how to apply RMF to federal systems NIST-SP-800-171 does not apply RMF to the protection of CUI. The CRM used by DCMA comes from FedRAMP.</p>\n<h2 id=\"fedramp\">FedRAMP</h2>\n<p>The Federal Risk and Authorization Management Program (FedRAMP) is a government-wide program that promotes the adoption of secure cloud services across the federal government by providing a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services.</p>\n<p>The Frequently Asked Questions used to define FedRamp as FISMA for the cloud. You can only choose to use authorized FedRAMP vendors. As part of this application process vendors must upload the &ldquo;FedRAMP Low or Moderate Control Implementation Summary (CIS) Workbook Template&rdquo;</p>\n<p>This document, artifact 9, is the best template for the customer responsibility matrix.</p>\n<h2 id=\"how-do-i-complete-the-customer-responsibility-matrix-for-cmmc\">How do I complete the customer responsibility matrix for CMMC?</h2>\n<p>Much of the cloud and CMMC remains dark. We do not have official scoping guidance but the DCMA CMMC assessments of C3PAO provide us clues, and as stated, DCMA will not begin a CMMC assessment with all CRMs used for securing or the authorized handling of CUI.</p>\n<p>You will get this from the cloud vendor that you have decided is in scope.</p>\n<ol>\n<li>\n<p>Implementation Status\n&ldquo;Implementation Status&rdquo; refers to the implementation status of the control (e.g., Implemented, Partially Implemented, Planned, Alternative Implementation, N/A).</p>\n</li>\n<li>\n<p>Control Origination\n“Control Origination” refers to which entity has responsibility for implementing the control. The following table defines the control origination options.</p>\n</li>\n</ol>\n<img src=\"https://cdn.uploads.micro.blog/29546/2021/6bc3a21d84.png\" width=\"600\" height=\"587\" alt=\"\" />\n<p>In your SSP you must make sure you link to the CRM and then describe how you fill your duties</p>\n<p>You begin by only using FedRAmp authorized cloud vendors. This will help your CMMC assessor trust the shared responsibility of the cloud vendor.</p>\n",
        "date_published": "2021-05-12T09:29:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/05/12/cmmc-and-the.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2021/04/28/what-is-cmmc.html",
        "title": "What is CMMC?",
        "content_html": "<p>In 2019 the Department of Defense announced the creation of the Cybersecurity Maturity Model Certification (CMMC) to replace the self reporting of cyber hygiene which used to govern the DIB. The CMMC puts an end to self-assessment, and requires a third party assessor to verify the cybersecurity maturity level of all contractors.</p>\n<p>All DoD contractors must comply with the Federal Acquisition Regulation (FAR) and the Defense Acquisition Regulation Supplemental (DFARS). These regulations require companies to meet specific security standards from the National Institutes Standard of Technology. If a company connects to the government network, they must meet the NIST 800-53 standards. Companies not connected to a network were previously required to self-certify that they met the 110 controls and completed actions to increase cyber hygiene as laid out in NIST 800-171.</p>\n<p>Third party assessors, who must complete coursework and obtain a certification, must now measure what maturity level a contractor has met. An organization must demonstrate the institutionalization of the process and the utilization of the practices outlined by NIST. Furthermore, the maturation model is cumulative, meaning a contractor must demonstrate they have met the practices and processes of lower levels as well.</p>\n<p>The goal is to protect two types of sensitive data: federal contract information, and controlled unclassified information.</p>\n<h2>What is FCI?</h2>\n<p>Authorized holders, who have a Department of Defense Contract with a 7012 clause must protect two types of sensitive data: Federal Contract Information and Controlled Unclassified Information.</p>\n<p>FCI, or Federal Contract Information, is any information included in or created for a government contract not meant for public release.</p>\n<p>You or the government can create FCI. Then, you must do the work on behalf of a contract that generates or uses information not intended for public release.</p>\n<p>You do not need to label FCI. No classification exists. Instead, you must apply basic safeguards to information not meant for public release.</p>\n<p>All of this was established by FAR Clause 52.204-21, which lays out basic protections for sensitive data. A company should not assume meeting the requirements of FAR will be easy or cheap. However, FAR requirements often reflect better business practices, and provide a good starting point on your CMMC journey.</p>\n<p>Contractors who only touch or create FCI will need to pass a Level 1 maturity assessment.</p>\n<p>By 2025, all contractors will be assessed using the CMMC Level 1 methodology.</p>\n<h2>What is CUI?</h2>\n<p>Controlled Unclassified Information requires greater protections than FCI. The government defines CUI as information that demands safeguarding or dissemination controls required by law, regulation, or Govt-Wide Policy, but which is not classified, and does not include nuclear data or material. These require greater protections than CUI.</p>\n<p>The CUI program was created by President Obama’s Executive Order 13556 after 9/11 to create a streamlined method for information sharing and safeguarding. The Information Security Oversight Office (ISOO) acts as the Executive Agent (EA) of the National Archives and Records Administration (NARA), and is responsible for oversight of the CUI program. The ISOO monitors the implementation of the CUI program by executive branch agencies.</p>\n<p>Contractors who touch, create, receive, transmit, or destroy CUI will need to pass a Level 3 maturation assessment</p>\n<p>By 2025(ish) all contractors will be assessed using the CMMC Level 3 methodology.</p>\n<h2>History of CMMC?</h2>\n<p>The Department of Defense launched the Cybersecurity Maturity Model Certification Program in 2019.</p>\n<p>The Software Engineering Institute built the initial versions of the CMMC in collaboration with the Johns Hopkins University Applied Physics Laboratory.</p>\n<p>However, the effort to secure the Defense Industrial Base goes back as far as 2017, when the Department of Defense required all contractors who receive a 7012 clause to self-assess their cyber hygiene using a set of controls called the Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. This was published by the National Institute of Standards and Technology, and is commonly reffered to as NIST SP-800-171, or simply 171.</p>\n<p>NIST was empowered to set the standards for cybersecurity by the Secretary of Commerce under the Federal Information Security Modernization Act, which was passed all the way back in 2002. In fact, NIST began taking charge of technology standards as far back as 1901n with the Organic Act. This was updated for the digital world with FISMA.</p>\n<p>So the CMMC, while officially beginning in 2019, has roots that are almost twenty years old.</p>\n<p>FISMA empowered the Secretary of Commerce to authorize the Office of Budget and Management to team with NIST. Through NIST, the OMB, and thus the Secretary of Commerce, set standards such as FIPS 199. FIPS 199 is a type of encryption authorized users must use when handling CUI. CMMC-AB, for example can’t just strip away FIPS.</p>\n<p>The Department of Defense instead created CMMC to help speed up compliance to 171 after the F-35 was stolen by the Chine military.</p>\n<p>The plans did not fall into Chinese hands by hacking a single computer or company. Rather, thousands of cyber attacks were launched against the networks of small government contractors who moved plans and files, such as key radar information, back and forth between emails and servers.</p>\n<p>These efforts did not stop with the F-35. In fact, according to a Government Accountability Office:</p>\n<p>“The Department of Defense (DOD) faces tens of millions of attempted malicious cyber intrusions per year as adversaries seek to take advantage of the department’s reliance upon computer networks.”</p>\n<p>Something had to be done.</p>\n<h3>The Interim Rules</h3>\n<p>The Department of Defense took the extraordinary approach of releasing an Interim Rule to speed up implementation of CMMC. The Interim rule introduced three new clauses, 7019, 7020, and 7021.</p>\n<p>The 7019 and 7020 clauses rely on the same approach to 171, but now only the Under Secretary of Defense for Acquisition and Sustainment can assign the 7021, which has the CMMC requirements.</p>\n<p>As of Nov 30, 2020 all contractors must continue to upload SRPS scores and self-attest under the 7019 clause.</p>\n<p>If the DoD wants to apply a medium review, the 7020 clause kicks in.</p>\n<p>Until 2025, only the Undersecretary of A+S can assign the 7021 clauses.</p>\n<p>The interim rule only applies to contracts after Nov 30. However, when a contract or Task Orger gets modified, which is often, than the interim 7019, 7020, and 7021 clauses kick in.</p>\n<p>The Interim rule is set to be finalized in May of 2021, which then lays out a path for all Defense contracts to have the 7021 clause by 2025-2026.</p>\n<p>It makes sense for Defense Contractors and Managed Support Providers, the IT companies that work with small manufacturers, to begin to understand and implement the CMMC model</p>\n<h2>What is the CMMC Model?</h2>\n<p>Since December 13, 2017 companies could lose DoD contracts due to lax cybersecurity. But the DoD took an extraordinary step of releasing an interim rule to DFARS.</p>\n<p>Until recently, DFARS required organizations to self assess. Companies had to provide documentation on meeting the 110 controls of NIST 800-171 by collecting artifacts into a Body of Evidence.</p>\n<p>A Body of Evidence contained three major items. The first was a Systems Security Plan, which describes a company’s infrastructure, such as the hardware and software utilized. The Plan of Action and Milestones (POA&amp;M) documented any shortcomings and described a remediation plan for those shortcomings. A company would also submit their procedures and policies as part of the Body of Evidence.</p>\n<p>DFARS required a contractors POA&amp;M to be shared with the DoD. A major change presented by the CMMC model is the removal of POA&amp;M and the introduction of third party auditors, rather than self assessments.</p>\n<p>The CMMC builds off of NIST 800-171 but also includes controls from other cybersecurity frameworks. Where CMMC differs is in both the maturation model and the role of third party assessors. The CMMC defines 17 domains of cyber hygiene that are comprised of 43 capabilities. These capabilities are institutionalized through 171 practices across five levels of maturation.</p>\n<p>The Office of the Under Secretary of Defense for Acquisition and Sustainment defines maturation as a, “set of characteristics, attributes, indicators, or patterns that represent capability and progression in a particular discipline.” The CMMC contains five levels of maturation.</p>\n<h3>The Five Levels of CMMC</h3>\n<p>The CMMC model has five levels of maturation:</p>\n<pre><code>Level 1: Safeguard Federal Contract Information (FCI) \nLevel 2: Serve as transition step in cybersecurity maturity progression to protect CUI \nLevel 3: Protect Controlled Unclassified Information (CUI) \nLevels 4-5: Protect CUI and reduce risk of Advanced Persistent Threats (APTs)\n</code></pre>\n<p>The Cybersecurity Maturity Model Certification program has 17 total Domains across these five levels.</p>\n<p>Almost all of the domains come from NIST 800-171 and Federal Information and Processing Standards 200.</p>\n<p>To these 14 domains, the CMMC model adds Asset Management (AM), Recovery (RE), and Situational Awareness (SA) from other Interational and Risk Management Frameworks.\nPractices and Processes</p>\n<p>Across these Domains the model has 171 practices. In oder to be compliant with each practice, you must demonstrate compliance with every single objective taken from the 171a methodology. For Level 3 maturation, the practices in each of the Domains of CMMC require someone to meet compliance on 362 objectives.</p>\n<p>The CMMC model also requires an assessor to establish process maturity.</p>\n<p>Maturity Level 1 allows you to demonstrate processes in an ad hoc manner, and will not require poilcy in place for compliance. However, every company will find security impossible to meet without good policy. So, while you are not technically required to show policy for Level 1 compliance, it will be hard to reach without it.</p>\n<p>Level 2 maturity requires an organization to establish and document practices within a Domain. This does not mean you must write a process documentation for each Domain. Many of the objectives used to measure process maturity will exist across your portfolio.</p>\n<p>Level 3 maturity is required to handle CUI. An organization must establish, maintain, and resource a plan for managing cybersecurity. CUI activities must be defined in the plan.</p>\n<p>Level 4 requires an organization to review and measure practices for effectiveness. They must look for vulnerabilities and address them when found.</p>\n<p>Level 5 requires a company to standardize and optimize process implementation throughout the organization. Most Level 5 organziations will be better prepared through experience handling Classified or nuclear information.</p>\n<h2>CMMC Cost</h2>\n<p>The CMMC Model includes several assumptions about the cost of implementing CyberSecurity.</p>\n<p>As Jacob Horne of DefCert notes, the Interim Rules assume Defense contractors have implemented the controls of 171, although few have managed to do so.</p>\n<p>In fact, NIST-800-171 itself assumes that many of the controls required in FAR-21 just happen as part of the way we do business in the modern world. The Department of Defense knows the web has existed for 30 years or longer. They used to call it ARPANet.</p>\n<p>Can you blame the Department of Defense for not wanting to use contractors who have done nothing to address cybersecurity in 30 years? They will not accept excuses for a lack of cybersecurity, and have published some pricing guidance. Jacob warns us to understand that these prices also include the assumptions built into the CMMC model. Still even if these number represent the floor and not the ceiling, it will still cost a pretty penny for a sheen of cyber hygiene</p>\n<p>The cost CMMC certification consists of 3 things (based off of DoD estimates (assuming you are already 171 compliant):</p>\n<pre><code>The cost of the assessment itself; \n\nFirst year, non-recurring engineering costs; \n\nRecurring engineering costs split over five years. \n</code></pre>\n<p>Level 1 Certification: $2,999.56</p>\n<pre><code>Assessment: $2,999.56 \nNonreccuring Engineering: N/A \nRecurring Engineering: N/A \n</code></pre>\n<p>Level 2 Certification: $50,755.88</p>\n<pre><code>Assessment: $22,466.88 \nNonreccuring Engineering: $8,135.00 \nRecurring Engineering: $100,770.00 ($20,154.00 per year x 5 years) \n</code></pre>\n<p>Level 3 Certification: $118,975.60</p>\n<pre><code>Assessment: $51,095.00 \nNonreccuring Engineering: $26,214.00 \nRecurring Engineering: $208,330.00 ($41,666.00 per year x 5 years \n</code></pre>\n",
        "date_published": "2021-04-28T09:01:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2021/04/28/what-is-cmmc.html",
        "tags": ["How To CMMC"]
      },
      {
        "id": "http://DoctorMac.micro.blog/2020/10/18/future-of-cyberesecurity.html",
        "title": "Future of Cyberesecurity: CMMC and the DFARS Interim Rule",
        "content_html": "<p>This post is co-written by <a href=\"https://www.linkedin.com/in/terry-lehman-mba-technology-management-72090756/\">Terry Lehman</a></p>\n<h2 id=\"nation-under-attack\">Nation Under Attack</h2>\n<p>As American combat  pilots scream across the sky flying an F-35, the finest fighter jet in the world, they may have to engage a Chinese cousin, the J-20. The NSA reported  sophisticated cyber security attacks allowed the adversaries in China to steal critical information bit by bit.</p>\n<p>The F-35 plans did not fall into Chinese hands by hacking a single computer or company. No, instead thousands of cyber attacks were launched against the networks of  small government contractors who moved plans and files, such as key radar information, back and forth between emails and servers.</p>\n<p>A lot of data. Government estimates, based on plea deal of a convicted Chinese spy suggest that since 2008 China has stolen terabytes of data and schematics from the F-35 and F-22 stealth fighter jet programs.</p>\n<p>Chinese cyber criminals, working for the Chinese army, raided the computer systems of Boeing and many subcontractors to steal key national intelligence one bit of data at a time. Adversaries t then reassembled information from many sources. These efforts did not stop with the F-35. In fact according to a Government Accountability Office:</p>\n<p>“The Department of Defense (DOD) faces tens of millions of attempted malicious cyber intrusions per year as adversaries seek to take advantage of the department’s reliance upon computer networks.”</p>\n<h2 id=\"defense-industrial-base\">Defense Industrial Base</h2>\n<p>Our soldiers do not stand on the front line of cybercrime. More often the target for these attacks focuses on the 300,000 contractors who make up the Defense Industrial Base (DIB). According to the Cybersecurity &amp; Infrastructure Security Agency DIB  is the” industrial complex that enables research and development, as well as design, production, delivery, and maintenance of military weapons systems, subsystems, and components or parts, to meet U.S. military requirements.”</p>\n<p>Basically if more companies in the DIB took steps to protect data, even just adding two factor or multi factor authentication many of the F-35 secrets would not have reached Chinese adversaries.</p>\n<h2 id=\"dangers-of-cyber-crime\">Dangers of Cyber Crime</h2>\n<p>According to the Federal Bureau of Investigation cyber crime involves cyber activity that threatens and compromises U.S. networks, steal financial and intellectual property, and put critical infrastructure at risk. These attacks put every sector of the economy under threat.</p>\n<p>In fact according to the 2016 Global State of Information Security Survey cyber crime has increased 38% since 2014. The impacts of these attacks strain our economy. Victims of successful attacks have reported downtime (46%), loss of revenue (28%), reputational damage (26%), and loss of customers (22%). The threat of cyber crime costs private companies $400 billion every year and Juniper Research estimates this cost reached two trillion dollars last year.</p>\n<h2 id=\"cyber-warfare\">Cyber Warfare</h2>\n<p>The attacks on the defense industrial database have escalated to the point of daily warfare fought on network systems across the globe. According to Ellen Lord, the undersecretary of defense for acquisition and sustainment, “It&rsquo;s no secret that the U.S. is at cyber war every day.”</p>\n<p>The Honorable Ellen Lord continued, “Cybersecurity risks threaten the industrial base, national security, as well as partners and allies.” In fact the Department of Defense estimated stolen data cost the DIB over 700 billion dollars in 2015. In fact the Government Accountability Office reported DoDfaces tens of millions of attempted malicious cyber intrusions per year as adversaries seek to take advantage of the department’s reliance upon computer networks.”</p>\n<p>A private and public partnership must harden the networks across the DIB to ensure adversaries to not weaken our nation through cyber warfare. BI Director Christopher Wray, in Senate testimony noted “An important part of fighting back against our foreign adversaries in the cyber realm is offense as well as defense.”</p>\n<p>In recognition that prior efforts to protect the DIB from cyberwarfare have failed  the Office of the Under Secretary of Defense for Acquisition and Sustainment (OUSD(A&amp;S)) has developed the Cybersecurity Maturity Model Certification (CMMC) framework. This new effort represents the largest cybersecurity public/private partnership in US History. Development of  the CMMC involved   i DoD stakeholders, University Affiliated Research Centers (UARCs), Federally Funded Research and Development Centers (FFRDCs), and the DIB sector.</p>\n<h2 id=\"what-is-cmmc\">What is CMMC?</h2>\n<p>In 2019 the Department of Defense announced the creation of the Cybersecurity Maturity Model Certification (CMMC) to replace the self reporting of cyber hygiene that used to govern the DIB. The CMMC puts an end to self-assessment and requires a third party assessor to verify the cybersecurity maturation level.</p>\n<p>All DoD contractors must comply with the  Federal Acquisition Regulation (FAR) and the Defense Acquisition Regulation Supplemental (DFARS). These regulations require companies to meet specific security standards from the National Institutes Standard of Technology. If a company connects to the Government network they must meet the NIST 800-53 standards. Companies not connected to a network were required to self certify that they met the 110 controls, actions to increase cyber hygiene as laid out in NIST 800-171.</p>\n<p>The CMMC builds off of NIST 800-171 but also includes controls from other cybersecurity frameworks. Where CMMC differs is in both the maturation model and the role of third party assessors.  The CMMC defines 17 domains of cyber hygiene that are comprised of 43 capabilities. These capabilities get institutionalized through 171 practices across five levels of maturation.</p>\n<p>The Office of the Under Secretary of Defense for Acquisition and Sustainment defines maturation as, “set of characteristics, attributes, indicators, or patterns that represent capability and progression in a particular discipline.” The CMMC contains five levels of maturation.</p>\n<style type=\"text/css\">\n.tg  {border-collapse:collapse;border-spacing:0;}\n.tg td{border-color:black;border-style:solid;border-width:1px;font-family:Arial, sans-serif;font-size:14px;\n  overflow:hidden;padding:10px 5px;word-break:normal;}\n.tg th{border-color:black;border-style:solid;border-width:1px;font-family:Arial, sans-serif;font-size:14px;\n  font-weight:normal;overflow:hidden;padding:10px 5px;word-break:normal;}\n.tg .tg-0lax{text-align:left;vertical-align:top}\n</style>\n<table class=\"tg\">\n<thead>\n  <tr>\n    <th class=\"tg-0lax\"><span style=\"font-weight:400;font-style:normal;text-decoration:none;color:#000;background-color:transparent\">Maturity Level</span></th>\n    <th class=\"tg-0lax\"><span style=\"font-weight:400;font-style:normal;text-decoration:none;color:#000;background-color:transparent\">Processes</span></th>\n    <th class=\"tg-0lax\"><span style=\"font-weight:400;font-style:normal;text-decoration:none;color:#000;background-color:transparent\">Practices</span></th>\n  </tr>\n</thead>\n<tbody>\n  <tr>\n    <td class=\"tg-0lax\"><span style=\"font-weight:400;font-style:normal;text-decoration:none;color:#000;background-color:transparent\">1</span></td>\n    <td class=\"tg-0lax\"><span style=\"font-weight:400;font-style:normal;text-decoration:none;color:#000;background-color:transparent\">Performed</span></td>\n    <td class=\"tg-0lax\"><span style=\"font-weight:400;font-style:normal;text-decoration:none;color:#000;background-color:transparent\">Basic Cyber Hygiene</span></td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"><span style=\"font-weight:400;font-style:normal;text-decoration:none;color:#000;background-color:transparent\">2</span></td>\n    <td class=\"tg-0lax\"><span style=\"font-weight:400;font-style:normal;text-decoration:none;color:#000;background-color:transparent\">Documented</span></td>\n    <td class=\"tg-0lax\"><span style=\"font-weight:400;font-style:normal;text-decoration:none;color:#000;background-color:transparent\">Intermediate Cyber Hygiene</span></td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"><span style=\"font-weight:400;font-style:normal;text-decoration:none;color:#000;background-color:transparent\">3</span></td>\n    <td class=\"tg-0lax\"><span style=\"font-weight:400;font-style:normal;text-decoration:none;color:#000;background-color:transparent\">Managed</span></td>\n    <td class=\"tg-0lax\"><span style=\"font-weight:400;font-style:normal;text-decoration:none;color:#000;background-color:transparent\">Good Cyber Hygiene </span></td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"><span style=\"font-weight:400;font-style:normal;text-decoration:none;color:#000;background-color:transparent\">4</span></td>\n    <td class=\"tg-0lax\"><span style=\"font-weight:400;font-style:normal;text-decoration:none;color:#000;background-color:transparent\">Reviewed</span></td>\n    <td class=\"tg-0lax\"><span style=\"font-weight:400;font-style:normal;text-decoration:none;color:#000;background-color:transparent\">Proactive</span></td>\n  </tr>\n  <tr>\n    <td class=\"tg-0lax\"><span style=\"font-weight:400;font-style:normal;text-decoration:none;color:#000;background-color:transparent\">5</span></td>\n    <td class=\"tg-0lax\"><span style=\"font-weight:400;font-style:normal;text-decoration:none;color:#000;background-color:transparent\">Optimizing</span></td>\n    <td class=\"tg-0lax\"><span style=\"font-weight:400;font-style:normal;text-decoration:none;color:#000;background-color:transparent\">Advanced /Progressive</span></td>\n  </tr>\n</tbody>\n</table>\n<p>Third party assessors, who must complete coursework and obtain a certification will then measure what maturity level a contractor has met. An organization must demonstrate the institutionalization of the process and the utilization of the practices. Furthermore the maturation model is cumulative, meaning a contractor must demonstrate they have met the practices and processes of lower levels as well.</p>\n<h2 id=\"cmmc-timeline\">CMMC Timeline</h2>\n<p>Development of the Cybersecurity maturation model has reached its final stages before going live. Groups of provisional assessors have completed course work. Licensed companies have entered an approved marketplace and as of November 2020 the licensed training partners awaited finalization of certification exams.</p>\n<p>By the year 2025 all DoD solicitations will require companies to hold CMMC certification. This means that over 300,00 companies and universities who touch sensitive data must rely on third party assessors to determine their maturation level. The more sensitive and mission ready the sata the higher the level required.</p>\n<h2 id=\"dfars-interim-rule\">DFARS Interim Rule</h2>\n<p>Since December 13, 2017 companies could lose DoD contracts due to lax cybersecurity. Yet until recently DFARS requires organizations to self assess. Companies had to to provide documentation on meeting the 110 controls of NISt 800-171 by collecting artifacts into a Body of Evidence.</p>\n<p>A Body of Evidence contained three major items. The first a Systems Security Plan describes a company&rsquo;s infrastructure such as the hardware and software utilized.  The Plan of Action and Milestones (POAM) documented any shortcomings and described a remediation plan. A company would also submit their procedures and policies as part of the Body of Evidence.</p>\n<p>DFARS required a contractors POAM to get shared with the DoD. A major change in the CMMC is the removal of POAM and having third party rather than self assessments.</p>\n<p>Yet with total compliance of the CMMC not required until 2025 how do we protect the trillions of dollars of data currently vulnerable across the DIB? In October of 2020 the Office of the Under Secretary of Defense for Acquisition and Sustainment published an interim rule as an update to Defense Acquisition Regulation Supplemental.</p>\n<p>This interim rule, currently under public review will go into effect immediately. DIB contractors need to take immediate action to learn about the interim rule and the difference between the CMMC assessments.</p>\n<p>(This post is a pre-publication and draft of chapter one of a handbook I and <a href=\"https://www.linkedin.com/in/terry-lehman-mba-technology-management-72090756/\">Terry Lehman</a> will publish on completing the Basic level self-assessments that comply with the DFARS Interim rule  252.204-7019 and the medium and high levels of 252.204-7020 and 7021  while also preparing for a CMMC future. We welcome feedback and corrections.) .</p>\n<h3 id=\"citations\">Citations:</h3>\n<p>Carnegie Mellon University and The Johns Hopkins University Applied Physics Laboratory (2020). CYBERSECURITY MATURITY MODEL CERTIFICATION (CMMC). Version 1.02. Department of Defense under Contract No. FA8702-15-D-0002.</p>\n<p>DOD Focuses on Minimizing Cyber Threats to Department, Contractors. (2016, September). Retrieved October 11, 2020, from <a href=\"https://www.defense.gov/Explore/News/Article/Article/2312512/dod-focuses-on-minimizing-cyber-threats-to-department-contractors/\">www.defense.gov/Explore/N&hellip;</a>\nFederal Bureau of Investigation. (2020) Cyber Crime — FBI. Retrieved October 18, 2020, from <a href=\"https://www.fbi.gov/investigate/cyber\">www.fbi.gov/investiga&hellip;</a>\nFBI Strategy Addresses Evolving Cyber Threat. (2020, September 16). Retrieved October 11, 2020, from <a href=\"https://www.fbi.gov/news/stories/wray-announces-fbi-cyber-strategy-at-cisa-summit-091620\">www.fbi.gov/news/stor&hellip;</a></p>\n<p>Global, P. (2014). The Global State of Information Security® Survey 2016. On-line] Available: https://www. pwc. com/gx/en/issues/cyber-security/ informationsecurity-survey. html [Jul. 4, 2017].</p>\n<p>Gonzales, D., Harting, S., Adgie, M. K., Brackup, J., Polley, L., &amp; Stanley, K. D. (2020). Unclassified and Secure: A Defense Industrial Base Cyber Protection Program for Unclassified Defense Networks. RAND ARROYO CENTER SANTA MONICA CA SANTA MONICA United States.</p>\n<p>Gordon Lubold and Dustin Volz, “Chinese Hackers Breach U.S. Navy Contractors,” Wall Street Journal, December 14, 2018.</p>\n<p>Government Accountability Office. (2020) GAO-17-512, Defense Cybersecurity: DOD&rsquo;s Monitoring of Progress in Implementing Cyber Strategies Can Be Strengthened - 686347.pdf. Retrieved October 18, 2020, from file:///Users/jgmac1106/Downloads/686347.pdf</p>\n<p>Michael Brown and Pavneet Singh, China’s Technology Transfer Strategy: How Chinese Invest-ments in Emerging Technology Enable A Strategic Competitor to Access the Crown Jewels of U.S. Innovation, U.S. Department of Defense, Defense Innovation Unit Experimental (DIUx), January 2018</p>\n<p>Plea Agreement, United States v. Su Bin, No. SA CR 14-131 (C.D. Cal. Mar. 22, 2016), <a href=\"https://www.justice.gov/opa/file/834936/\">www.justice.gov/opa/file/&hellip;</a>\ndownload.</p>\n",
        "date_published": "2020-10-18T13:14:00-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2020/10/18/future-of-cyberesecurity.html",
        "tags": ["How To CMMC"]
      }
  ]
}
