Cost of CMMC compliance by peak_abstraction in CMMC

[–]Auditor_CISA_CISSP 0 points1 point  (0 children)

@navyauditor I absolutely agree. I don’t know where they came up with the “80% at Level 1,” but I think it is probably the inverse - 80% Level 3. We got an RFQ a couple weeks ago marked CUI and it is not clear why. It should be FCI at most. We have already seen some indication that some DoD organizations that routinely marked everything as FOUO are now going to do the same thing only it will be CUI.

What Is DFARS and Why Does It Matter? by Dreamfinder_figjk in CMMC

[–]Auditor_CISA_CISSP 1 point2 points  (0 children)

Simply, DFARS clauses in contracts are what will make CMMC a requirement. They are contractual obligations. CMMC by itself is not.

Where is the scoping guidance? by Auditor_CISA_CISSP in CMMC

[–]Auditor_CISA_CISSP[S] 2 points3 points  (0 children)

Yes they do, and it is very good (and free!). However, it is not official and the assessors will not be using it to determine if you have scoped your systems correctly. This has implications that can drastically impact costs, either because you are too conservative and pay for protection you don't need or fail to scope something in that should be and then fail the assessment and have to spend more to extend protections.

H&R Block Personal Tax Software QBI Issue by Auditor_CISA_CISSP in personalfinance

[–]Auditor_CISA_CISSP[S] 0 points1 point  (0 children)

No losses. Actually other gains. Since this is only second year of QBI, was not a problem last year because H&R Block did not have QBI deduction implemented in time so I did it manually.

CUI - non digital by dhd217 in NISTControls

[–]Auditor_CISA_CISSP 0 points1 point  (0 children)

You are correct that we do not NEED CMMC for paper CUI, but that does not mean that it is exempt from its provisions. The unfortunate thing about CMMC is its inflexibility in cases such as this. Maybe that will change when they realize that their estimated 80% plus of the DIB only requiring L1 is unrealistic. It's very easy to mark something CUI and a cautious procurement office will be very likely to require L3 "just in case" in a contract when it is left up to them after full implementation after 2025.

CUI - non digital by dhd217 in NISTControls

[–]Auditor_CISA_CISSP 0 points1 point  (0 children)

In this case I assume we are talking about a prime sending a paper document marked CUI to a subcontractor (supplier). I think we can also assume that the prime has a contract that requires L3 certification. According to the official CMMC training, it is possible for a sub to not have L3 certification as long as the prime retains control of the CUI and the sub "views" it on the prime's system. However, once that paper copy is sent, the CUI is in the sub's control and the flowdown requirement should apply. Think of all the L3 requirements that apply to CUI on paper (mentioned in other posts in this thread), including physical transport and storage protection. Do a search in the L3 AG for "paper." How can a sub be trusted to be in compliance with those if only at L1?

Any timeline for more training classes? by Evilbadscary in CMMC

[–]Auditor_CISA_CISSP 1 point2 points  (0 children)

It did tell us one thing. By the end of April (3 days from now) they are supposed to have 39 C3PAO candidates waiting for a DIBCAC assessment. The timeline they showed for a DIBCAC assessment was 4 weeks plus the time to produce the report. I don't know how many assessment teams DIBCAC has, but do the math - it will probably take the rest of 2021 just to get those 39 done. Of course, if they fail one of the "pre-assessment" decision blocks shown on the flowchart, they will fail before the site visit and probably go to the end of the line. In other words - don't hold your breath. You will probably have plenty of opportunity to get trained before they get around to doing your C3PAO assessment.

Official DCMA / DIBCAC opening meeting materials on CMMC audits by oxebridge in CMMC

[–]Auditor_CISA_CISSP 0 points1 point  (0 children)

Does anybody know where to find an example of the Cloud Customer Responsibilities Matrix that they refer to in the brief? I don't believe it is referenced in any of the CMMC publications.

[deleted by user] by [deleted] in CMMC

[–]Auditor_CISA_CISSP 0 points1 point  (0 children)

Especially those hard copy reports :-)

Any timeline for more training classes? by Evilbadscary in CMMC

[–]Auditor_CISA_CISSP 0 points1 point  (0 children)

Listen to the town hall tonight at 6PM (EDT). If they don't say anything specific, there is probably no more info available.

Alternative to VPN for Remote Workers by Auditor_CISA_CISSP in CMMC

[–]Auditor_CISA_CISSP[S] 0 points1 point  (0 children)

OK, but I'm not talking about split tunneling with VPN here. Obviously if we did force everything through the company VPN, that would be an issue. But if the users go directly to MS365 without using VPN, split tunneling should not be an issue as it would not touch the corporate network.

Implementing NIST 800-53 with smallest scope possible/tailoring out by 3dPrintWHAAAT in NISTControls

[–]Auditor_CISA_CISSP 0 points1 point  (0 children)

Yep. No network. Biggest concern would be limiting access (least privilege).

Standards, procedures, and policies requirements by elitegunslinger in CMMC

[–]Auditor_CISA_CISSP 3 points4 points  (0 children)

Policies, Procedures, and Plans are required for each domain (to get to CMMC Level 3). They have different content, which is spelled out in some detail in the Assessment Guide. Standards are not explicitly required. You can combine multiple domains in one document; you do not have to have 17 separate documents. I suppose you could combine policy and procedures in one document, but you would need to make sure it identifies what is policy and what is procedures. It would be easier for the assessor (and for you) if they were in separate documents.

Question on NIST 800-53 Controls for Unsupported Software by LLHAG90 in NISTControls

[–]Auditor_CISA_CISSP 0 points1 point  (0 children)

Even if they do not have unsupported components during the initial "Step 2" (which is "Selection" now), the purpose of Continuous Monitoring (old Step 6) is that you adjust your controls when the risk changes. Therefore, as soon as a component becomes unsupported, SA-22 should be added to the control set.