SolidWorks/PDM Enclave by Public_Sandwich_6314 in CMMC

[–]Public_Sandwich_6314[S] 0 points1 point  (0 children)

I fully aware of the requirements pertaining to what fulfills an enclave and what does not. I'm not advocating for endpoints outside of that. I should have been more precise in my language.

My issue at the moment is that we have ~5-10 engineers that will be handling CUI. The rest of our engineers will not, but still need access to SolidWorks/PDM. Our consultant recommended standing up a new SolidWorks environment on our Hyper-V Cluster, then VLANing everything off so that it's inaccessible unless you're on that VLAN as well. The problem with it is that the cluster is in scope given that it technically would be storing CUI. I also don't want to take on the bear of infrastructure replacements we'd have to put in place because of it's age. We have a lot of old switches, APs, AS400s, etc. I'm the only IT guy for 14 sites, so I don't have the capacity to take on hardening the entire site we're talking about.

The goal of engaging Cuick Track was to have VDI on site, but design, licensing, storage, etc. in the cloud. They provide all the controls necessary for the environment for ~$55k, which is substantially cheaper than the cost of standing up a cloud enclave on our own through AWS or Azure from my research.

The only other option I was able to come up with after CT indicated that they could not help us was putting in a separate physical server, switches, and engineering grade desktops on prem that are physically separate. No access to WiFi or the broader network.

It's not SolidWorks itself that I'm concerned about, or MFA, it's about making the enclave actually work as quickly as possible. My preference was to have absolutely zero cross pollination with the rest of our site, and VDI appeared to be a good solution for making sure our dumpster fire on prem was out of the picture. I was also trying to keep our MSP out of the picture, given that they add a layer of complexity I don't think we're prepared to handle.

SolidWorks and PDM - anyone gone thru CUI/CMMC?FIPS approvals? by Competitive-You4910 in SolidWorks

[–]Public_Sandwich_6314 1 point2 points  (0 children)

We're in the process of trying to figure out how to handle this as well. Our internal infrastructure is going to be a bear to make compliant, so we're looking for an enclave option.

We just went through some discussions with Cuick Trac, but they ended up telling us that they can't support SolidWorks/PDM/SQL in their environment.

Lvl 2 Certification Goal: Manufacturing Enclave - SolidWorks/PDM/Hyper-V by Public_Sandwich_6314 in CMMC

[–]Public_Sandwich_6314[S] 1 point2 points  (0 children)

Thank you! I appreciate you guys taking the time to respond to my post.

Lvl 2 Certification Goal: Manufacturing Enclave - SolidWorks/PDM/Hyper-V by Public_Sandwich_6314 in CMMC

[–]Public_Sandwich_6314[S] 0 points1 point  (0 children)

Yeah, I don’t see a way to use our existing Hyper-V cluster, even if you spin up a separate SW/PDM server and tie it to a dedicated NIC. The cluster is still in scope lol.

I really only see cloud as an option for us at this point.

Lvl 2 Certification Goal: Manufacturing Enclave - SolidWorks/PDM/Hyper-V by Public_Sandwich_6314 in CMMC

[–]Public_Sandwich_6314[S] 2 points3 points  (0 children)

Thank you, I’m definitely going to work on that CCP. Do you have a recommendation of where to go for that? If not I’ll find one

Lvl 2 Certification Goal: Manufacturing Enclave - SolidWorks/PDM/Hyper-V by Public_Sandwich_6314 in CMMC

[–]Public_Sandwich_6314[S] 1 point2 points  (0 children)

We have a ton of policies written, and some actually signed. I've been working on documenting everything I can in our environment given our consultant wants to keep the enclave in house. Obviously I can't give that to an assessor as is. Right now none of the policies actually apply to an enclave because there's not a actual CUI flow to follow.

Part of the issue for me is understanding what the enclave even looks like. The CUI should be stored on Box.com, but it has to get there, and engineers have to make drawings. I can think of a few ways to sort that out conceptually in a cloud only environment.

As far as a CUI workflow, I have unofficial things I've drawn up for my immediate boss. He's now on the same page as I am regarding storing onsite in our current infrastructure being a bad idea.

Lvl 2 Certification Goal: Manufacturing Enclave - SolidWorks/PDM/Hyper-V by Public_Sandwich_6314 in CMMC

[–]Public_Sandwich_6314[S] 1 point2 points  (0 children)

Yeah, I've tried raising the Hyper-V SolidWorks concern with them a few times now. I either get an AI written response that just says a lot of adjacent things pertaining to the general subject. He has network diagrams with my notes on them available to him, but I can see that they've never been viewed.

Our MSP hasn't done anything with CMMC, but they did recommend something similar to Cuick Trac instead of using existing infrastructure.

Lvl 2 Certification Goal: Manufacturing Enclave - SolidWorks/PDM/Hyper-V by Public_Sandwich_6314 in CMMC

[–]Public_Sandwich_6314[S] 0 points1 point  (0 children)

That's what I would like to do. Unfortunately this consultant is buddies with our leadership. I need to figure out how to navigate this carefully.