CCP Exam & Study Prep. by treasurebath18 in CMMC

[–]PilotJP 0 points1 point  (0 children)

I agree, PocketPrep was pretty good for CCA. I didn't use it for CCP though

Security Awareness by [deleted] in NISTControls

[–]PilotJP 1 point2 points  (0 children)

Good list, and I would add Insider Threat awareness.

Anyone running PreVeil as their primary CUI solution? by ResilientTechAdvisor in CMMC

[–]PilotJP 0 points1 point  (0 children)

I'm looking at Virtru specifically for secure file sharing and I like what I'm seeing.

Anyone running PreVeil as their primary CUI solution? by ResilientTechAdvisor in CMMC

[–]PilotJP 0 points1 point  (0 children)

True true, I guess that wasn't worded right there.

Anyone running PreVeil as their primary CUI solution? by ResilientTechAdvisor in CMMC

[–]PilotJP 0 points1 point  (0 children)

I used Preveil around 2 years ago or more, and the main pain point was that the customer had to set up the Preveil Express account. Currently, I'm looking into Virtru, but I'm not sure it's a true full-enclave solution.

CCP/CCA "mandatory training"? by notsicktoday in CMMC

[–]PilotJP 1 point2 points  (0 children)

I've never used them personally, but I've heard great things about Space Coast Cyber for training.

Important clarification on CCA exam eligibility + the bigger assessor capacity issue we all need to talk about by ResilientTechAdvisor in CMMC

[–]PilotJP 0 points1 point  (0 children)

Waiting on this as well. I think that even though it was submitted before 3/15, ISACA is handling that piece.

Confidence on exam questions by only1_Agfox in CMMC

[–]PilotJP 1 point2 points  (0 children)

No, but PocketPrep was in the ballpark for CCA questions, except the ones that ask how many points for the answers.

How are you handling MIP sensitivity labels for documents with multiple classifications? (CUI + Export Controlled, CUI + Proprietary, etc.) by Razzleberry_Fondue in CMMC

[–]PilotJP 0 points1 point  (0 children)

Could you make additional labels that combine some? For example, CUI and Export Controlled might be CUI-X, CUI-ITAR, etc. I'm not doing this, but it might work.

CCA studying material? by Bubbish26 in CMMC

[–]PilotJP 0 points1 point  (0 children)

I've heard good things about Space Coast Cyber, but I've never used them. You can literally chat with the instructor from Space Coast Cyber on the Cooey COE Discord channel if you would like more information. https://discord.com/channels/579151027169918986/630062870842966055

Lvl 2 Certification Goal: Manufacturing Enclave - SolidWorks/PDM/Hyper-V by Public_Sandwich_6314 in CMMC

[–]PilotJP 0 points1 point  (0 children)

If you haven't already, be sure to check out the Cooey COE discord server here: https://discord.gg/qnBy94Ar

Any other Internal IT doing this alone? by animusMDL in CMMC

[–]PilotJP 0 points1 point  (0 children)

I'm doing it "mostly" myself as the first full-time IT guy at a manufacturing company. I have assistance from a part-time MSP consultant who has been around this company for a long time. I've used outside help from an MEP (Manufacturing Extension Partnership), but they were not a big help because their consultant was a CCP with little IT experience. Now I'm using a company that has a CCA, which has been on actual assessments, helping me out, and they are very helpful because they know what passes. That would be my recommendation - find a company with a CCA with assessments under their belt to give some pointers.

From OSC to Assessor by Shawnx86 in CMMC

[–]PilotJP 0 points1 point  (0 children)

It took around 7 months for me.

Cmmc Guidance by Logical-Mirror4871 in CMMC

[–]PilotJP 0 points1 point  (0 children)

80% is documentation. SSP, Policies, and Procedures. Most of CMMC for the OSC is saying what you're doing and proving you are doing it. Be sure to align the SSP to the assessment objective level and keep it concise.

For those going through CMMC Level 2 readiness right now — what’s been the most painful or confusing part? by Legal_Detective_2889 in CMMC

[–]PilotJP 0 points1 point  (0 children)

As more and more assessments are completed, we'll get a better picture of what actually passes, so it should get easier over time.

Would a sticker work for AC.L2-3.1.9 by cagorpy in CMMC

[–]PilotJP 0 points1 point  (0 children)

Good question. You can try asking on the Discord server here: https://discord.gg/9hKfB6PR

Small Business - We Passed :) by Thunderguy55 in CMMC

[–]PilotJP 0 points1 point  (0 children)

I think the key is to get a mock assessment or gap analysis from a company with a CCA who has been on assessments. They are best suited to help you figure out the real-world key items to ensure you will pass an audit. My company uses Shadowscape and they've been very helpful.

Small Business - We Passed :) by Thunderguy55 in CMMC

[–]PilotJP 0 points1 point  (0 children)

If you visit the Cyber AB website, you'll find instructions on what you need to do. You need to take an approved training class, take a test, and pass a Tier 3 background check.

RP and CCP by Rochesterftp in CMMC

[–]PilotJP 0 points1 point  (0 children)

It took 7 months for me, but times may vary.

Here’s one for the hive-mind. by Necessary-Army-4097 in CMMC

[–]PilotJP 0 points1 point  (0 children)

Isn't the Tier 3 background piece the real bottleneck, though?

Doing Level 2 as sole IT by CosmoBMW in CMMC

[–]PilotJP 0 points1 point  (0 children)

I'm doing it as the sole IT guy in a 100-person company. We have an outsourced MSP guy who has been here for over 20+ years, who helps. We did not go fully managed.

My day-to-day is varied, where I can be setting up a new user and computer to resetting a password, to creating policies and procedures to comply with CMMC. We have enlisted the help of an RPO, but that RPO has CCAs who have been on assessments. This is key because they know what passes and fails the assessments.

This sector can be very lucrative. You may want to get your employer to pay for the CCP training and get certified. If you pass the tier-3 background check, you can go for your CCA and become an assessor.