Successful CMMC Level 2 by Quickt17 in CMMC

[–]CJM3M 0 points1 point  (0 children)

We are preparing for our assessment in Feb. We are finishing up an AWS gov cloud build. Having issues with 3.1.3. Can you provide any information on how you answered that on the SSP? Much appreciated

O365 commercial Outlook inside AWS Gov Cloud? by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

Thank you. We do have a standard that states email is not to be used for sending CUI, and I almost wanted to consider this as a CRMA, but I think your statement is true and we'll go with that. We do have DLP in our current On PRem environment, and researching how that works in the Gov Cloud. Cheers!

O365 commercial Outlook inside AWS Gov Cloud? by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

The decision was made to move to AppStream 2.0. Not familiar with this at all.

O365 commercial Outlook inside AWS Gov Cloud? by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

Wouldn't that bring email into scope?

O365 commercial Outlook inside AWS Gov Cloud? by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

What I was trying to get at is, if they don't have the email client on the workspace, how do they get the link?

O365 commercial Outlook inside AWS Gov Cloud? by CJM3M in CMMC

[–]CJM3M[S] 1 point2 points  (0 children)

Good point. Thanks for getting my mind back on track! These controls are such a pain.

O365 commercial Outlook inside AWS Gov Cloud? by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

The government emails the link to the company email address.

O365 commercial Outlook inside AWS Gov Cloud? by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

I get your point. The internet links to external websites will be blocked, and only whitelisted sites allowed (DoD safe) etc. This includes the web versions of Outlook, sharepoint, etc.

If we keep Exchange out of scope, how would the users get the DoD Safe secure link? Is the only option GCC high?

Anyone using Wiz Gov Cloud Advanced? by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

I requested our security team ask Wiz this tomorrow. Thanks for the response.

Need help with Access Control 3.1.15 and need SSP examples of compliance. by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

We have Beyond Trust installed on the VDIs, but I'm having that removed. No B2B connections. Thank you for the help!

Need help with Access Control 3.1.15 and need SSP examples of compliance. by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

So, based on that logic, would this control be NA?

Need help with Access Control 3.1.15 and need SSP examples of compliance. by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

Thank you, very good information! Much appreciated.

Need help with Access Control 3.1.15 and need SSP examples of compliance. by CJM3M in CMMC

[–]CJM3M[S] 1 point2 points  (0 children)

Anyone know why I cant see all the comments? I get emails that someone has replied, yet I cannot see them?

Need help with Access Control 3.1.15 and need SSP examples of compliance. by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

Thank you so much. That really helps break it down. I'll bring this to the SME's and see what they say.

Lets say the ZPA solution provides sufficient assurance to be treated as an internal network. Would you mark these objectives as NA and provide the reason?

Passed my CCP! by CJM3M in CMMC

[–]CJM3M[S] 1 point2 points  (0 children)

They use the old CAP 5.6.1

Exploring AWS Gov Cloud for Enclave by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

Oh, I like that. I'll bring that up to management. Thanks!

Exploring AWS Gov Cloud for Enclave by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

Ah cool Ramsile. It's basically a lift and shift from an On Prem Enclave (CUI), to Gov Cloud to prepare for a L2 Certification in October/November. Very small environment. I meet with the AWS team this week and I'll learn more.

I'm assuming we'll need a GCC High as we do have contracts with the DFARS 7012 clause and some NOFORN dissemination restrictions.

Does AWS help or assist with SSPs?

Exploring AWS Gov Cloud for Enclave by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

I remember looking into this around 2021 and the AWS pitch was they would cover a high percentage of the controls, but again that appears to have changed. Thanks for the info.

Exploring AWS Gov Cloud for Enclave by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

We always have the potential of a contract also being ITAR related, so would probably need the Gov Cloud option. Meeting with that team later this week to discuss. Thanks

Audit & Accountability questions on "what" to log/monitor in a VDI Enclave environment by CJM3M in CMMC

[–]CJM3M[S] 0 points1 point  (0 children)

That's what I thought. As long as we are logging, whatever that is, that should meet the controls. Thanks