For many small entrepreneurs the cost of CMMC drives your scope. You may engineer a solution that allows you to buy inherited solutions so you do not have to build every security control yourself. Microsoft GCCH will always have lower lifetime costs, but not every contractor can …
J. Gregory McVerry
-
-
One Laptop Does Not Need an Enterprise Security Program
A one-person company struggles to prepare for CMMC. Often, folks begin in the wrong place. All month long I am focusing on how a single-user company can create controls that meet NIST SP 800-171 security requirements and pass a CMMC assessment using the NIST SP 800-171A …
-
CMMC for a Company of One: Building a Business Not a Burden
If you are a founder, independent consultant, or owner of a very small defense contractor, NIST SP 800-171 feels overwhelming. You stare at the CMMC scoping guide and know someone wrote it for a company much larger than yours. You may have one employee, one laptop, no server …
-
Vulnerability Scans and a Single Device Scope: Examining A System Security Plan Example
Your System Security Plan needs to tell your compliance story. We often encounter small micro-businesses who may have just a few single laptops. These companies often rely on FedRAMP File Sharing services due to the lower start up costs. Yes, a GCCH environment may have lower …
-
Can I Walk Alone? Vulnerability Scanning and NIST 171
Often times for small businesses it feels as if NIST-SP-800-171 does not scale down. It seems to protect the confidentiality of Controlled Unclassified Information the Government built an overlay, meant for large organizations, from NIST-SP-800-53 For example, small and …
-
You want me to Count What? CMMC and Inventory
What counts when counting for CMMC? The thing about the CMMC pause, it hasn’t really changed how one should get started with building systems that meet NIST-SP-800-171 requirements. Getting started involves getting better at doing the basics. Staying compliant for CMMC just …
-
Stacking Procedures Like Legos to Build Foundations of a Security Program
As a small organization creating a security plan knowing where to begin can feel overwhelming. Especially when you must also protect the confidentiality of Controlled Unclassified Information within your cybersecurity program. Do not open up NIST-SP-800-171a and begin at 3.1.1. …
-
-
Doing the Do: Verbs and the Source of Truth with Your System Security Plan
When writing a NIST-SP-800-171 System Security Plan we have a mantra, “Say what you do, Say how it gets done, Prove you do it.” Lot of action in that sentence, but in the end six verbs drive how you protect the confidentiality of Controlled Unclassified Information …
-
You Want Me to Track What? Configuration Management and CMMC
CMMC does not scale down, because NIST-SP-800-171 did not get built for small and micro-businesses. 171 got carved from NIST-SP-800-53 which nerds and academics trained in gov speak genres wrote for the federal government. NIST-SP-800-171 also assumes you do things as a small …
-
CUI vs ITAR in your shop work flow
-
Creating Role Based Training Programs
When you compare the evolution of NIST-SP-800-171 rev 2 to NIST-SP-800-171 rev 3 you can see the emphasis on training grow. We now focus not just on awareness and training, but on security literacy and awareness. Patching the people has become an even greater priority. Yet …
-
Make it Your Plan: Take Back Control of Your POAM
You may toil with a consultant for hours over your System Security Plan. You have probably marked a dozen snakeoil emails as spam after they promised to get plans in place in hours or minutes. But have you ever used your SSP as the document to guide your CUI protection? Have you …
-
Patching your People with Rev Three ODPs
I don’t have a naughty nature, so I will refrain from ODP puns and discuss how Patching your People through your Security Training program needs to evolve with the transition to NIST-SP-800-177 Rev 3 from Rev 2. NIST SP 800-171 Revision 3 introduces both theoretical and …
-
Updated the “Is it CUI” decision tree again with feedback from Discord. Added a a contract review step once unmarked files are stored in systems meant for Controlled Unclassified Information.
-
Updated draft of “Is it CUI?” Flowchart.
-
Very early draft of a CUI marking decision tree. Not an export lawyer. Welcome feedback.
-
Draft of Scoping Decision Tree
-
What Goes into Your System Security Plan?
Folks often bemoan compliance or security as paperwork and checkbox exercises, but that misses the point of Document Control. Policies, plans, and procedures exist to ensure your business does work in ways that meet laws and regulations. They also exist to describe how you get …
-
alright @manton still no web ring plug-in…we gotta find a community member to fix that.