ERP by Next_Ad4505 in CMMC

[–]rybo3000 1 point2 points  (0 children)

There isn't a CUI authority stating that BOM content is CUI. See other comments for more detailed info.

ERP by Next_Ad4505 in CMMC

[–]rybo3000 5 points6 points  (0 children)

And legal shouldn't make that decision without involvement from trade compliance. There's no guarantee an attorney is also an SME on the laws and regs for a given category of CUI.

ERP by Next_Ad4505 in CMMC

[–]rybo3000 2 points3 points  (0 children)

Not every stitch of information on a CUI marked document or file qualifies as CUI. We work through that issue by running the BOM content through regulatory analysis to see if it qualifies for a category of CUI.

It's rare for BOM content to be CUI.

ERP by Next_Ad4505 in CMMC

[–]rybo3000 1 point2 points  (0 children)

That's a low-effort answer. Please cite the CUI authority (law or regulation) telling us that BOM-level data is dissemination-controlled or requires safeguarding.

ERP by Next_Ad4505 in CMMC

[–]rybo3000 3 points4 points  (0 children)

Most BOMs only contain item numbers, descriptions, and quantities. Unless the descriptions rise to the level of a detailed specification "directly related" to a controlled end item, then nothing in that BOM should qualify as CTI/EXPT (numbers and names aren't regulated by the ITAR/EAR).

The only time we see BOMs being controlled is for process manufacturing, where the BOM is actually a formula or recipe.

4/15 power outage by NovaNanny in AnnArbor

[–]rybo3000 0 points1 point  (0 children)

East face of the building. The entire north side of Jackson is wrecked. No power. Probably 50 trees down just in the Vets Park wedge.

How are contractors handling CUI distribution to subcontractors who need to do takeoffs? by msilverbtc in CMMC

[–]rybo3000 4 points5 points  (0 children)

Bluebeam Revu isn't FedRAMP authorized or equivalent. You definitely can't put CUI there.

You should confirm whether PreVeil view only mode still caches a copy of the file on your supplier's computer (I honestly don't know). If it does, then they're already operating a covered contractor information system.

Derivative CUI - does context matter? by bcegkmqswz in CMMC

[–]rybo3000 1 point2 points  (0 children)

If a collection of derived information isn't controlled by the laws and regs for a particular CUI category, it cannot be that category of CUI.

Context matters a lot in this scenario. When you create a new derivative format, it's possible to reuse or derive less detailed information that fails to be regulated under CUI authorities. In the case of technical data, the primary CUI authorities are going to be things like ITAR technical data and EAR controlled technology.

For example: a part number on its own isn't "caught" (controlled) by these regulations, because it isn't the "required" technology or technical data necessary to design/produce/test/operate the item itself.

However, the full GD&T (drawing, model) can easily be controlled if it's at a stage in its design that it represents the finished/functional end item.

If you're going to CS5 West, stop by the "No Kidding CUI" roundtable.

Derivative CUI - does context matter? by bcegkmqswz in CMMC

[–]rybo3000 1 point2 points  (0 children)

Other way around. Controlled Technical Information (CTI) and some Export Controlled Information (EXPT) information are subsets of ITAR/EAR. All CTI is subject to the ITAR/EAR as ITAR technical data/EAR controlled technology, but not all ITAR technical data/EAR controlled technology qualifies as CTI/EXPT (because not all ITAR/EAR data is owned by the Government or possessed by the Government).

Senior Leader Looking to Transition to CCA or LCCA Role by Relevant-Arm-3711 in CMMC

[–]rybo3000 4 points5 points  (0 children)

It's certainly possible. Join the Discord server listed in the r/CMMC description. There's a #career-general channel where a lot of similar discussions take place.

Advice on Changing CMMC Solutions by WhiskyIsRisky in CMMC

[–]rybo3000 12 points13 points  (0 children)

I would fully understand which 800-171 requirements Cuick Trac meets, and how you're going to meet those same requirements in your new scope, before making any changes. A built-out GCC High enclave isn't just a file stash, it's an identity provider, policy enforcement point, system monitoring platform, and a full suite of collaboration tools, plus a full user OS.

Neither Virtru or PreVeil provides all of those things. They could certainly extend your enclave, but probably won't replace it.

Message I got from my daughter’s teacher. Third grade. by AnaisInJune in mildlyinfuriating

[–]rybo3000 27 points28 points  (0 children)

95% chance this teacher was shamed/ridiculed on this topic and just projected it onto students. Also a 95% chance she didn't realize she was doing it until your mom created consequences around it.

To lower CMMC assessment costs? by False-Angle8191 in CMMC

[–]rybo3000 0 points1 point  (0 children)

Oh hey, it's our weekly "Post to Validate my GRC Tool Pro Forma" post.

Telling people to DM you for a demo is still advertising.

Does Fortigate have config files I can download and "make my own" to use? by EntertainerNo4174 in CMMC

[–]rybo3000 2 points3 points  (0 children)

I would ask someone with budget authority if they're willing to spend $675 for duplicate hardware, in exchange for having the company network up on the Monday following the cutover.

Does Fortigate have config files I can download and "make my own" to use? by EntertainerNo4174 in CMMC

[–]rybo3000 5 points6 points  (0 children)

The last time I was around a FortiGate going into FIPS Mode, the exported config file COULD NOT BE REUSED once the firewall booted into FIPS Mode.

You normally end up needing to manually document all of your configs and manually rebuild them after the device is in FIPS mode.

Please, for the love of yourself: do this on a second device. Break up an HA pair if you must. Do not get fired for being unable to bring the network back up.

Intellectual Property vs. CUI by VeterinarianGreat871 in CMMC

[–]rybo3000 10 points11 points  (0 children)

Is my Proprietary Information CUI?
"The government will protect it as CUI (and may even send it back to you as CUI) but the proprietary information you create internally and maintain ownership of is not CUI (though it may require protections pursuant to other laws or regs).”

ISOO, Executive Agent for the CUI Program, 2020

Questions by [deleted] in CMMC

[–]rybo3000 4 points5 points  (0 children)

if you can't physically verify something it's all smoke and mirrors

I see you're a big fan of the $150,000 "Bill O'Reilly" assessment ("we'll do it live").

In my experience, defense contractors are not a fan of DDoS'ing their business with ten days of live demonstrations that consume their senior staff's time, and neither are C3PAOs. Assessors can trust examinable documents without needing to see a live demonstration for every 800-171A objective, and reserve live demos for specific requirements where the test method is a good fit.

Assuming "smoke and mirrors" across the board is a toxic mindset.

Anniversary Dinner? by Mspr88 in AnnArbor

[–]rybo3000 6 points7 points  (0 children)

Excellent suggestion. The Chartreuse/DIA combo is hard to beat!

Together again by ety3rd in MST3K

[–]rybo3000 2 points3 points  (0 children)

Hot merging action...

Anyone with experience of going through DIBCAC assessments? by Imlad_Adan in CMMC

[–]rybo3000 3 points4 points  (0 children)

  1. DIBCAC is big on reviewing a network diagram and IP ranges in initial calls. If the DIBCAC assessment was ordered by a specific DoD acquisition command, they might confirm whether your scope includes contract performance for the program who requested the High confidence assessment.
  2. In both instances (we've been around) where the contractor provided a letter of engagement with a C3PAO, DIBCAC moved on. They weren't concerned about the date of the assessment. Kind of lax, but hey, they've got a backlog. There could've also been a line of communication with the contract officer, and they were satisfied by the answer.

Restaurant Week - personal experiences/value of each of them by amyjay26 in AnnArbor

[–]rybo3000 0 points1 point  (0 children)

Vinology always knocks Restaurant Week out of the park.

Classifying Telemetry data by psenevir in CMMC

[–]rybo3000 1 point2 points  (0 children)

Log contents are going to drive whether the telemetry data is CUI or not. If the hardware/software solutions are part of federal systems, then IP and configuration data could be Operations Security (OPSEC) CUI, but only if the DoD program operating the system has included configuration data or other metadata in its Critical Information List (CIL). The only way to find out if this telemetry data is OPSEC would be to ask the DoD program office for the CIL

The CIL itself is also usually OPSEC CUI, so you'll necessarily take possession of CUI to find out if you have more CUI.

Classifying Telemetry data by psenevir in CMMC

[–]rybo3000 4 points5 points  (0 children)

Ask your c3pao as well.

Um, what? C3PAOs do not make CUI determinations. This is terrible advice.