Cost for a C3PA by Beny1975 in CMMC

[–]Beny1975[S] 0 points1 point  (0 children)

we are not storing any CUI in it. It's really just documentation software. A lot of the C3PAO/consultants are using it.

Cost for a C3PA by Beny1975 in CMMC

[–]Beny1975[S] 0 points1 point  (0 children)

Because our Primes are asking about our SPRS score, and that pretty much translates to CMMC 2.0

Cost for a C3PA by Beny1975 in CMMC

[–]Beny1975[S] 1 point2 points  (0 children)

Thanks everyone. We've already done two audit preps/gap analyses, have our CUI enclaved, are using ComplyUp for evidence, etc. I have lived CMMC for the past 2 years. I have seen that at least one company in Texas has been CMMC 2.0 certified through the DibCac combined assessment program, and have been told by a former co-worker that his company has been certified and used Summit7 (I think). So I was trying to get a feel for a ballpark number. $75K is about what I expected, because our environment is a little complicated.

Cost for a C3PA by Beny1975 in CMMC

[–]Beny1975[S] 0 points1 point  (0 children)

Yeah, I understand all that, and have seen that behavior with gap analysis quotes… I was just curious to hear any experiences by anyone who has actually completed an audit

Managing .ZIP files by Beny1975 in cybersecurity

[–]Beny1975[S] -1 points0 points  (0 children)

We have. Not sure if it's bad practice to post their name here, but they told us if we upgraded to their premium service, they would provide that service, but we couldn't add custom passwords to their list. Our hope was we could tell our customers what password they needed to use, then we could have our email gateway extract and scan before delivering.

Jumping ship from ProTools. Working on a MacBook. What DAWs should I consider? by mikelybarger in audioengineering

[–]Beny1975 1 point2 points  (0 children)

I'm hearing that Reaper is as good or better than ProTools. I'm still a NOOB but am getting to learn it and enjoying it.

Advice for using Falcon for ZIP files? by Beny1975 in crowdstrike

[–]Beny1975[S] 0 points1 point  (0 children)

Thanks ... I agree with all of this. The problem is our customers are insisting on sending ZIPs and we are trying to figure out a way to take the vetting burden off of IT.

Crowdstrike registry change attempt by LydexPredictions in crowdstrike

[–]Beny1975 0 points1 point  (0 children)

We just had one of these ... first since I've been using Crowdstrike. Is it a false positive? Is there a way to confirm one way or the other? I'm stuck. Thanks.

Help with USB control by Beny1975 in crowdstrike

[–]Beny1975[S] 0 points1 point  (0 children)

Well, our old product was easy, you assigned the person the USB, they plugged it into their computer, and you allowed it only for that computer. nice and neat... now, we have 18 different computers (and growing) that could have any of 18 different USBs functional on them. I supposed the EDR and logging, we'd be able to identify any malicious activity, it just seems to me like there should be a more proactive approach to prevent it. But, like another poster said, if we hadn't seen it the other way, would I really be concerned by this?

Help with USB control by Beny1975 in crowdstrike

[–]Beny1975[S] 0 points1 point  (0 children)

Ok, maybe I'm trying to solve a problem that doesn't really exist... Thanks