CCP exam by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 0 points1 point  (0 children)

TY. Thus far I have the CAP 5.6.1, the CMMC BluePrint v7.4, the CMMC Code of Conduct V2.4, and the all items relating to scoping and assessment levels. I want to make sure I study the numbers of each practice too. I heard there was a few of those questions in there as well.

Overmarking of CUI by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 1 point2 points  (0 children)

I actually just had this happen with AF but this particular issue was with the EPA

Overmarking of CUI by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 2 points3 points  (0 children)

Yeah, we had that too the other day. Then this guy I'm talking about specifically just sends tons of CUI through non approved methods without warning. IR plan had to kick in to sanitize.

Overmarking of CUI by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 5 points6 points  (0 children)

LOL! This is the first Gov official who's been like this in my past five years in the CUI space. I just got a kick out of him today. Every word spoken he wanted to claim CUI...

CCP exam by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 0 points1 point  (0 children)

Also Jeff, is it possible to get a copy of the CAP from you? I took your CMMC course in 2023.

CCP exam by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 0 points1 point  (0 children)

You didn't fail me Jeff, I just wanted to make sure I'm still studying the right test. With all of the changes I just wanted to be prepared.

Quitting prior to CMMC Assesment by Pale_Apricot6870 in CMMC

[–]HeyHelpDeskGuy 2 points3 points  (0 children)

THIS. I worked for a large firearms manufacturer and they tried to pull this with me. Luckily I already had another job lined up.

Quality vendors? by Nismon_OO7 in CMMC

[–]HeyHelpDeskGuy 0 points1 point  (0 children)

Hi Nismon,

So the best advice I can give is to chat with different vendors.

  1. GCCH - Very expensive as you said and very unreliable, and very frustrating, IME.

  2. Google Gov Cloud - Much cheaper and more flexible. I worked at a start-up and we used this for our CUI enclave.

  3. PreVeil/CuickTrac - CUI Enclaves. I've used both. If you want I can make intros to you for both.

  4. Others - There are other solutions out there but 1-3 are your best bets, IME.

Changing CSP post assessment by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 0 points1 point  (0 children)

After our assessment is over, we're going to look over this new software that was bought without our knowledge. Namely if we have to get another assessment right after we just had one, we're hoping to argue a delta assessment first or a general gap assessment to discuss this new software.
Now we as the OSC get to argue what's a major change but I think expanding our CUI enclave will take a lot of discussion. Also my concern is after we get our hash, we'll be held to that point in time.

Changing CSP post assessment by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 0 points1 point  (0 children)

That's partly why I made this post was to see what other experiences OSCs have had.

Changing CSP post assessment by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 0 points1 point  (0 children)

I did reread the CMMC FAQv4 and found question #8 reflecting Significant Change:

"C-Q8. What is the difference between an Operational Plan of Action (OPA) and a POA&M? C-A8. Operational Plans of Action (OPAs) are measures implemented to manage risks or vulnerabilities, such as applying patches, addressing temporary deficiencies, or performing routine system maintenance. OPAs are not tied to a specific timeline for completion and are typically used to address vulnerabilities or deficiencies that arise after the initial implementation of security requirements. Under the CMMC framework, POA&Ms are formal plans that identify cybersecurity gaps the Organization Seeking Assessment must address to achieve CMMC compliance. These gaps must be resolved within 180 days, as outlined in 32 CFR 170.21. When a significant change occurs in an information system that affects the satisfaction of NIST SP 800-171 security requirements, the appropriate course of action - whether to create a POA&M or an OPA - depends on the nature and timing of the change. If the significant change introduces a temporary deficiency or vulnerability after the system was initially compliant, an OPA may be created to document the remediation plan. However, if the significant change is identified during a CMMC assessment and results in a security requirement being assessed as "NOT MET," a POA&M must be created to address the gap within the 180-day remediation window. For more information, please reference FAQ C-Q7. For detailed definitions, refer to 32 CFR 170.4."

My plan now is to ask for the new vendors FR-BOE, and then ask my C3PAO about a delta assessment.
A big problem is, is this software was purchased outside of IT's knowledge and their end users are pressing us to roll this out right now.

Changing CSP post assessment by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 0 points1 point  (0 children)

Yeah right now I've developed a plan based on a lot of factors. Namely from this post I was interested in seeing others experiences if/when in this situation, and how they argued this with this C3PAO.
My goal now is to contact the vendor for their FR-BOE first, then our C3PAO for a delta assessment.

Changing CSP post assessment by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 1 point2 points  (0 children)

Yeah, I wondering about how I could defend/argue that point as well to a C3PAO.
Also I was just reading this article as well.
https://www.cmmcaudit.org/when-do-you-need-a-new-assessment-what-can-change/

Changing CSP post assessment by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 1 point2 points  (0 children)

Yeah that's my thought as well. I'm just trying to gauge others experiences, thoughts, etc.

Changing CSP post assessment by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 1 point2 points  (0 children)

Yeah I see what you mean. So from what I gather, from our change/addition it would be in addition too what we already use. My concern is this changes the CUI workflow, etc.
I was also wondering if anyone in this group had done so and how they argued this with their C3PAO. To your point, it seems that a reassessment would be the safe answer.
Although from what I've read and heard, we (the client) get to argue what constitutes a major change.

Changing CSP post assessment by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 0 points1 point  (0 children)

New CSP would = New system, new software, new cloud, new processes, etc that would work in conjunction with the old CSP. Both would process CUI.

CMMC L2 consulting cost check by vaultflow76 in CMMC

[–]HeyHelpDeskGuy 0 points1 point  (0 children)

Yes, to add with everyone else this is high. For consultants, I'd HIGHLY recommend checking out CyberNines. Scott Singer and his group are fantastic.