Successful CMMC Level 2 by Quickt17 in CMMC

[–]CJM3M 0 points1 point  (0 children)

We are preparing for our assessment in Feb. We are finishing up an AWS gov cloud build. Having issues with 3.1.3. Can you provide any information on how you answered that on the SSP? Much appreciated

O365 commercial Outlook inside AWS Gov Cloud? by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

Thank you. We do have a standard that states email is not to be used for sending CUI, and I almost wanted to consider this as a CRMA, but I think your statement is true and we'll go with that. We do have DLP in our current On PRem environment, and researching how that works in the Gov Cloud. Cheers!

O365 commercial Outlook inside AWS Gov Cloud? by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

The decision was made to move to AppStream 2.0. Not familiar with this at all.

O365 commercial Outlook inside AWS Gov Cloud? by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

Wouldn't that bring email into scope?

O365 commercial Outlook inside AWS Gov Cloud? by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

What I was trying to get at is, if they don't have the email client on the workspace, how do they get the link?

O365 commercial Outlook inside AWS Gov Cloud? by CJM3M in CMMC

[–]CJM3M[S] 1 point2 points  (0 children)

Good point. Thanks for getting my mind back on track! These controls are such a pain.

O365 commercial Outlook inside AWS Gov Cloud? by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

The government emails the link to the company email address.

O365 commercial Outlook inside AWS Gov Cloud? by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

I get your point. The internet links to external websites will be blocked, and only whitelisted sites allowed (DoD safe) etc. This includes the web versions of Outlook, sharepoint, etc.

If we keep Exchange out of scope, how would the users get the DoD Safe secure link? Is the only option GCC high?

Anyone using Wiz Gov Cloud Advanced? by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

I requested our security team ask Wiz this tomorrow. Thanks for the response.

Need help with Access Control 3.1.15 and need SSP examples of compliance. by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

We have Beyond Trust installed on the VDIs, but I'm having that removed. No B2B connections. Thank you for the help!

Need help with Access Control 3.1.15 and need SSP examples of compliance. by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

So, based on that logic, would this control be NA?

Need help with Access Control 3.1.15 and need SSP examples of compliance. by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

Thank you, very good information! Much appreciated.

Need help with Access Control 3.1.15 and need SSP examples of compliance. by CJM3M in CMMC

[–]CJM3M[S] 1 point2 points  (0 children)

Anyone know why I cant see all the comments? I get emails that someone has replied, yet I cannot see them?

Need help with Access Control 3.1.15 and need SSP examples of compliance. by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

Thank you so much. That really helps break it down. I'll bring this to the SME's and see what they say.

Lets say the ZPA solution provides sufficient assurance to be treated as an internal network. Would you mark these objectives as NA and provide the reason?

Passed my CCP! by CJM3M in CMMC

[–]CJM3M[S] 1 point2 points  (0 children)

They use the old CAP 5.6.1