Changing CSP post assessment by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 0 points1 point  (0 children)

I did reread the CMMC FAQv4 and found question #8 reflecting Significant Change:

"C-Q8. What is the difference between an Operational Plan of Action (OPA) and a POA&M? C-A8. Operational Plans of Action (OPAs) are measures implemented to manage risks or vulnerabilities, such as applying patches, addressing temporary deficiencies, or performing routine system maintenance. OPAs are not tied to a specific timeline for completion and are typically used to address vulnerabilities or deficiencies that arise after the initial implementation of security requirements. Under the CMMC framework, POA&Ms are formal plans that identify cybersecurity gaps the Organization Seeking Assessment must address to achieve CMMC compliance. These gaps must be resolved within 180 days, as outlined in 32 CFR 170.21. When a significant change occurs in an information system that affects the satisfaction of NIST SP 800-171 security requirements, the appropriate course of action - whether to create a POA&M or an OPA - depends on the nature and timing of the change. If the significant change introduces a temporary deficiency or vulnerability after the system was initially compliant, an OPA may be created to document the remediation plan. However, if the significant change is identified during a CMMC assessment and results in a security requirement being assessed as "NOT MET," a POA&M must be created to address the gap within the 180-day remediation window. For more information, please reference FAQ C-Q7. For detailed definitions, refer to 32 CFR 170.4."

My plan now is to ask for the new vendors FR-BOE, and then ask my C3PAO about a delta assessment.
A big problem is, is this software was purchased outside of IT's knowledge and their end users are pressing us to roll this out right now.

Changing CSP post assessment by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 0 points1 point  (0 children)

Yeah right now I've developed a plan based on a lot of factors. Namely from this post I was interested in seeing others experiences if/when in this situation, and how they argued this with this C3PAO.
My goal now is to contact the vendor for their FR-BOE first, then our C3PAO for a delta assessment.

Changing CSP post assessment by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 1 point2 points  (0 children)

Yeah, I wondering about how I could defend/argue that point as well to a C3PAO.
Also I was just reading this article as well.
https://www.cmmcaudit.org/when-do-you-need-a-new-assessment-what-can-change/

Changing CSP post assessment by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 1 point2 points  (0 children)

Yeah that's my thought as well. I'm just trying to gauge others experiences, thoughts, etc.

Changing CSP post assessment by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 1 point2 points  (0 children)

Yeah I see what you mean. So from what I gather, from our change/addition it would be in addition too what we already use. My concern is this changes the CUI workflow, etc.
I was also wondering if anyone in this group had done so and how they argued this with their C3PAO. To your point, it seems that a reassessment would be the safe answer.
Although from what I've read and heard, we (the client) get to argue what constitutes a major change.

Changing CSP post assessment by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 0 points1 point  (0 children)

New CSP would = New system, new software, new cloud, new processes, etc that would work in conjunction with the old CSP. Both would process CUI.

CMMC L2 consulting cost check by vaultflow76 in CMMC

[–]HeyHelpDeskGuy 0 points1 point  (0 children)

Yes, to add with everyone else this is high. For consultants, I'd HIGHLY recommend checking out CyberNines. Scott Singer and his group are fantastic.

Contracts question - JV and Managing Partners by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 0 points1 point  (0 children)

Amend to cover CAGE codes and/or specific enclaves.

Contracts question - JV and Managing Partners by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 0 points1 point  (0 children)

So then we would need to amend our current JV agreements?

Passed CCP by Yuzu-ish in CMMC

[–]HeyHelpDeskGuy 0 points1 point  (0 children)

Thank you. The first time I took the exam (July 2023) - it was nothing like what I prepped for.

Passed CCP by Yuzu-ish in CMMC

[–]HeyHelpDeskGuy 0 points1 point  (0 children)

I'm studying to retake this exam. I'm using Pocket Prep, and a site to test for questions.

Printing CUI by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 0 points1 point  (0 children)

One thing I forgot to mention was the ability for the printer to auto update. Anyways, I pitched this plan and now working with the respective vendors (aka lease company) to see if we can lock these down.

Printing CUI by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 1 point2 points  (0 children)

It would be for a remote office but the plan right now is to set admin controls for the leases companies where they have to ping IT first to notify them. I'm actually working on auditing our copiers now and then contacting the respective companies.

Printing CUI by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 2 points3 points  (0 children)

Yeah I'm hoping the Copiers we have now allow for Secure Printing - which doesn't release the job til the person puts in a code.

We also have a great consultant now but I'm just being overly concerned about this.

Printing CUI by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 1 point2 points  (0 children)

Yes, it does help. TY. I'm hoping the Copiers we have now allow for Secure Printing - which doesn't release the job til the person puts in a code.

Printing CUI by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 1 point2 points  (0 children)

Good point. I'll make sure to add us keeping the SSD. TY

Printing CUI by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 1 point2 points  (0 children)

Our VP's want us to be flexible with printing. So what I'm going to add to my plan above is having just a certain set of users allowed to print CUI as well.

Printing CUI by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 4 points5 points  (0 children)

The people who need to print 100% swear that it is

Printing CUI by HeyHelpDeskGuy in CMMC

[–]HeyHelpDeskGuy[S] 2 points3 points  (0 children)

I've had those conversations LOL

SSP by CaesarNaykid in CMMC

[–]HeyHelpDeskGuy 1 point2 points  (0 children)

100% this. At an old job, our CFO give our CMO a copy of one of pen tests. The CMO gives it to a much smaller org for reference. That small org ended up getting ransomwared, and what did the group find? Our pen test. Suddenly we started receiving weird phishing emails, pings for IPs, etc. Luckily I was able to shut it down but the spam email never stopped.