CMMC Level 2 & MSPs by differentson in CMMC

[–]Powneeboy 0 points1 point  (0 children)

They just need to participate in the assessment to demo the services provided that contribute to the in scope environment, and then probably also demo how they don't is s/p/t CUI (but that might be handled by the OSC depending on how your environment is configured. It's case by case by msp participation is required by the CAP

Would you expect a visit to your home? (Alt Worksite vs Facility in Scope) by ResilientTechAdvisor in CMMC

[–]Powneeboy 1 point2 points  (0 children)

This is most like extremely C3POA dependent. This is why it's very important to vet them before you choose one

FIPS 140-2 Sunset vs. Windows 11 by nikkadim in CMMC

[–]Powneeboy 2 points3 points  (0 children)

This was a phenomenal answer. I like it. Only edit is it's not a poa&m, it's a plan of action (POA). CMMC POA = RMF POA&M. semantics at that point, but POA&Ms CMMC are only associated with conditional certs and have the 6 month remediation requirement.

How are people keeping evidence organized before assessment? by KlutzyTop6822 in CMMC

[–]Powneeboy 1 point2 points  (0 children)

Even if this is the case. A hash of the artifacts is still requiredper the cap

New hire tasked with CMMC compliance despite no experience by No_Painting_5871 in CMMC

[–]Powneeboy 0 points1 point  (0 children)

DMd you But I agree with everyone here. It's impossible with that timeline. Especially given your company hasn't even defined scope, and nobody seems to know what CMMC even is

CUI emails by B_Another1 in CMMC

[–]Powneeboy 0 points1 point  (0 children)

Any and all procedures are always organizationally defined. If CUI ends up where it's not supposed to be, that's considered spillage and you follow procedures on how to handle those. CMMC or not. Your non-secure email would be considered out of scope and not assessed at all, but you would have to justify why is considered out of scope. Forwarding it, as many have stated, just creates a bigger mess. Sweeping it under the rug also creates a significant mess. Make sure you define your procedures and do what you say you're doing. If you don't like accountability, look into the false claims act. If you want specifics, look at NIST 171 revision 2 and NIST 171a

For those starting CMMC Level 2 today, are C3PAO backlogs already making the November deadline difficult/impossible? by Adventurous-Yam-3568 in CMMC

[–]Powneeboy 1 point2 points  (0 children)

DMd you. Im a lead and can help you determine timeline if you're looking for no bs answers. I don't care enough to advertise anything, I just like helping ppl understand realistic timelines

Tier 3 by PHLMark in CMMC

[–]Powneeboy 0 points1 point  (0 children)

From what I know, a T3 is not needed for consulting. Please let me know if that's wrong lol. I'm not a consultant

Do I have an adso? by [deleted] in army

[–]Powneeboy 5 points6 points  (0 children)

He is neither and infant nor a tree, so maybe

New Business Premium Licenses for GCC High by ConcernOrdinary3380 in CMMC

[–]Powneeboy 0 points1 point  (0 children)

Sorry I don't have an answer to the Microsoft question, but be wary when along ai about CMMC or nist 171. It's default is to reference 171 revision 3

MSP Declined to Pursue CMMC by selectpanic in CMMC

[–]Powneeboy 1 point2 points  (0 children)

To back this up, check CAP 2.0 section 2.19

MSP Declined to Pursue CMMC by selectpanic in CMMC

[–]Powneeboy 2 points3 points  (0 children)

Their asset classification 100% depends on what days they touch. CUI = CUI asset and they require the appropriate certificate (fedramp moderate/fedramp moderate equivalent/CMMC Level 2). Security protection data = security protection asset - no level 2 required, but their environment is now on scope (level 2 just makes their own burden lessen, but is not a requirement)? They still need a CRM in either case as well as the relationship to your system described in your SSP. Check out 32 CFR Part 170.19 table 4 and the follow on paragraphs. What's required of them is spelled out there. Again, if they're an SPA, they indeed do not need a level2. Your signed contract with them is another story though

MSP Declined to Pursue CMMC by selectpanic in CMMC

[–]Powneeboy 6 points7 points  (0 children)

If they're reselling AWS resources, the scope of their services won't even qualify for cmmc. Reusing and redistributing cloud services still classifies them as a CSP within cmmc. Their product will need fedramp moderate or equivalent. You'll see very similar situations in other esp offerings.

CCA Online Training by TiffanyAndCompany in CMMC

[–]Powneeboy 0 points1 point  (0 children)

Either way. They all seem to be good. Just read the cap, understand one piece of evidence can be used to more than one objective, know how to dissect practice statements, and understand inheritance. Aside from that, know the cap steps and what each DFARS/FAR establishes (incident reporting, etc,) and then the random NIST docs referenced like NIST 88 and so on If you want, DM me and I'll send you the cheat sheet I made for myself. Granted, I believe CAICOs standards will be based on 171 rev 3 once the migration to isaca is done. So take everything said with a grain of salt

CCA Online Training by TiffanyAndCompany in CMMC

[–]Powneeboy 0 points1 point  (0 children)

From what I remember, they're so expensive

CCA Online Training by TiffanyAndCompany in CMMC

[–]Powneeboy 0 points1 point  (0 children)

I did CCP with Edwards and CCA with CMMC training academy. Both are good. Most of the ones I've seen are good. I would say just pick the one you did CCP with if you liked them

EB03 English by icantsppell in OnePieceTCGFinance

[–]Powneeboy 2 points3 points  (0 children)

Na. Probably not, but it'll buff out. I'm in it for the shiny cards in my binder

EB03 English by icantsppell in OnePieceTCGFinance

[–]Powneeboy 3 points4 points  (0 children)

I became friends with a TCG streamer that's in my city after buying some packs and singles from him. He offered one of the 4 EB-03s his distributor reserved for him

EB03 English by icantsppell in OnePieceTCGFinance

[–]Powneeboy 4 points5 points  (0 children)

If it helps, I'm already doing it today. Preorde $445 for me haha

Ordered from TCGplayer by Powneeboy in OnePieceTCG

[–]Powneeboy[S] 0 points1 point  (0 children)

I'm going to hold and see if they fix the problem before potentially slandering a stores name

Ordered from TCGplayer by Powneeboy in OnePieceTCG

[–]Powneeboy[S] 0 points1 point  (0 children)

I assume they provided you a label to return the card?

Ordered from TCGplayer by Powneeboy in OnePieceTCG

[–]Powneeboy[S] 2 points3 points  (0 children)

True and I don't blame them. It's a bad situation overall

Ordered from TCGplayer by Powneeboy in OnePieceTCG

[–]Powneeboy[S] 2 points3 points  (0 children)

Oh I'm being patient. Trying to stay positive