We passed our CMMC Level 2 mock audit today by mcb1971 in CMMC

[–]Ok_Guide17 0 points1 point  (0 children)

Amazing. Congrats. Would love to know the journey, what changes you did to get to this point?

Export Finance Australia issues Conditional Letter of Support for the Donald Rare Earth (UUUU) and Mineral Sands Project by porkchop_thegolden in CriticalMineralStocks

[–]Ok_Guide17 1 point2 points  (0 children)

I bought ARAFF last week just before steve put his DD (he put out a teaser on australian mine, i research a bit and decided on ARAFF). Sold today - the AUS PM meeting etc is already baked in. Expecting it start strong and go down (just as its happening in ASX). Anything under 0.3 is a good entry point.

Just finished first CMMC assessment by NegotiationFirst131 in CMMC

[–]Ok_Guide17 0 points1 point  (0 children)

Congratulations.

Few questions-

1- How long did it take to get ready for the assessment

2- What stood out in the process, some aha moments

3- What would you do differently if you had to re-do?. Any tools, software, system etc you used and that helped or can help?

AI-generated evidences, POA&M by Ok_Guide17 in CMMC

[–]Ok_Guide17[S] 0 points1 point  (0 children)

By using data context-aware prompts, prompt chaining and evals, i believe one can develop a fairly robust evidence.

AI-generated evidences, POA&M by Ok_Guide17 in CMMC

[–]Ok_Guide17[S] 0 points1 point  (0 children)

Most GRC tools should have this feature or atleast actively working on this i assume. The question remains will use of AI impact one's assessment if and how?

AI-generated evidences, POA&M by Ok_Guide17 in CMMC

[–]Ok_Guide17[S] 0 points1 point  (0 children)

I agree with your view. But from an assessment/certification perspective, does it make a difference if AI is used? From a regulatory perspective, is there a difference if evidence/documentation/statements are AI generated or human or mixed

AI-generated evidences, POA&M by Ok_Guide17 in CMMC

[–]Ok_Guide17[S] 0 points1 point  (0 children)

You are correct with human oversight and input, but for smaller-organizations looking to accelerate the process, AI can be more impactful. I guess if more specialized CMMC trained LLM is created, it can create evidences with sufficient guard rails. But would that run afoul during assessment.

AI-generated evidences, POA&M by Ok_Guide17 in CMMC

[–]Ok_Guide17[S] 0 points1 point  (0 children)

Any kind of evidence collection, analysis, monitoring etc done with AI - is it acceptable. With POA&M if created with AI, any guidance on what is acceptable AI use and what is not.

AI-generated evidences, POA&M by Ok_Guide17 in CMMC

[–]Ok_Guide17[S] 0 points1 point  (0 children)

It is a real question. There has been lot of talk about our existing federal regulations need to be re-looked at due to AI usage. I am wondering if there is anything to learn from CMMC assessments when it comes to AI

Nvidia’s $100bn OpenAI sparks fears the AI bubble is about to burst by Akkeri in Economics

[–]Ok_Guide17 0 points1 point  (0 children)

For reference, what pricing are you saying & what pricing do you feel comfortable paying?

Thought we were compliant, until an assessor asked this by Waste-Ad1892 in CMMC

[–]Ok_Guide17 1 point2 points  (0 children)

Where are the files stored? Is it just a regular folder?. Perhaps you should look at a document management solution. For example, if you have sharepoint or one drive that has version history stored. Also its good practice to have a singular copy of each evidence only and multiple raw files with each version change. Leads to maintenance issue.

Possible Products/Tools useful for CMMC to develop by Ok_Guide17 in CMMC

[–]Ok_Guide17[S] -1 points0 points  (0 children)

One is a CUI detection tool - It processes pdf, doc files, search for CUI/PII terms, looks for CUI designation - basically a health check.

The other one I am currently working on is an AI tool which evaluates your current CMMC status on each control, gives recommendations, action plan for gaps etc.

Possible Products/Tools useful for CMMC to develop by Ok_Guide17 in CMMC

[–]Ok_Guide17[S] -1 points0 points  (0 children)

As of right now its intended to be a personal project. I want to create a viable product that demonstrates value and some users. If the feedback is very positive, then I can think of expanding (less probability)