Just had a wonderful conversation with all the #HigherEd folks at Summit 7 #CS2 event at Tampa after Jacob Horne
These are the take-aways:
-We are talking about way more than DOD. Forget the CUI and FAR. We get hit by 171 across so many Departments and Agencies
-Everyone prefers cleared contracts over controlled contracts. Difference between black and white rules and a box of 171 broken crayons.
-People forget research was the OG goal for the 7000 series of DFARS
-Physical security controls the hardest.
-Rules around public release around policies and procedures makes MSPs nervous
-CMMC 2.0 is good because it removed DoD specific controls. We all have to deal with 171 for DHS, NSF, DOE, DoeD. If other departments use CMMC as their program we will not have 17 different frameworks for the same standard. For example every University needs to do a 171 self-assessment for Dept of Ed by end of the academic year.
(We all think the deadline will get pushed back. FERPA makes a ton of stuff CUI)
-Auditors do not have enough experience with 171.
-Consider Sponsored Research and not IT to run your #cmmc/171 compliance. This is not an IT problem.
- (my opinion) IT or SPAR should have a multi-tenant cloud enclave. Depts have to “buy” into the system and can then include the cost in their contracts. Each contract/dept gets it’s own tenant.