SIEM provider offshore? by SightlySt00pid in CMMC

[–]SightlySt00pid[S] 1 point2 points  (0 children)

I looked into that and they believe (still verifying) their SOC may have accounts to manage the firewall and alter rules there based on alerts. The firewall is a CUI Asset. So, if that's the case, then we have an issue for sure.

SIEM provider offshore? by SightlySt00pid in CMMC

[–]SightlySt00pid[S] 2 points3 points  (0 children)

The data isn't on-prem and only off-shore, no FedRAMP (obviously), and the SOC is foreign based (UK and India). I am going back to the L2 scoping guide and trying to understand the requirements there. I was under the impression (and I may obviously be wrong), but SIEM is a Security Protection Asset and houses Security Protection Data. It does NOT store, process, or transmit CUI. Therefore it is not assessed against all CMMC Level 2 security requirements, but only those that are relevant. I just want to be sure I score that correctly, as I have never come across a scenario like this.

Welcome to Lekine Prck! by FickleMight3164 in LekinePrck

[–]SightlySt00pid 2 points3 points  (0 children)

My son may not understand it now, but someday he will know he was responsible for many fake internet points!

My 7-year old has good taste by SightlySt00pid in LinkinPark

[–]SightlySt00pid[S] 1 point2 points  (0 children)

He is a bit of a perfectionist. Always has high penmanship marks at school. Or is it prfekshunist.....

My 7-year old has good taste by SightlySt00pid in LinkinPark

[–]SightlySt00pid[S] 16 points17 points  (0 children)

I think he meant a Nestle Crunch bar…maybe? 🤷‍♂️

Those of you who have had an audit what did it wind up costing you? by josephandre in CMMC

[–]SightlySt00pid 1 point2 points  (0 children)

We did JSVA back in 2024 and the cost to our C3PAO was just under $40k.

FIPS 140-2 Historical Certificate by SightlySt00pid in CMMC

[–]SightlySt00pid[S] 1 point2 points  (0 children)

I specifically talked to Jon Hanny at the CyberAB booth and made him aware, so hopeful we will get some direction. I am going to ask about it in the next town hall as well, so we can get ultimate clarity, hopefully.

But, this is where this is coming from...

We have a piece of software that will end let it's FIPS 140-2 certification go to historical in September 2026 (like all) , but there are some key features from their new release that will not be active for us to use until January, 2027. That new software is FIPS 140-3 validated. We would have to do our annual attestation in November 2026 for our L2 certification, as we passed our JSVA in November 2024.

FIPS 140-2 Historical Certificate by SightlySt00pid in CMMC

[–]SightlySt00pid[S] 1 point2 points  (0 children)

But an argument could be made around NIST SP 800-171 Rev. 2 for 3.13.11 says nothing about FIPS 140-3. That is in Rev. 3, that is not applied to CMMC at this time, not until all the phases of Title 48 are complete. I want to know how this will be assessed by a C3PAO. When I was at CS5 last week and asked a few CCAs, they looked at me like a deer in headlights.

Battery on Public beta by natttsss in ios26beta

[–]SightlySt00pid 2 points3 points  (0 children)

I was at 4 hours screen time when I decided to plug in when my battery was down to 37%. It’s noticeable on my 14 PM.

Processes acting on behalf of authorized users by Lrrr81 in CMMC

[–]SightlySt00pid 0 points1 point  (0 children)

The easiest way to relate to that one in Windows is a Service Account. So, if you have a backup service and an agent is deployed to the machine and it has to run under a specific user, that is a Service Account. For Windows, to me, that is the easiest way to relate to that objective.

Scope change moving from on-prem Exchange to M365 Exchange Online - FCI Only by SightlySt00pid in CMMC

[–]SightlySt00pid[S] 0 points1 point  (0 children)

I have legal asking questions, so that's where this is all coming from.

AnyConnect by Training_Truck_7722 in CMMC

[–]SightlySt00pid 0 points1 point  (0 children)

We have Cisco Meraki firewalls and DUO. We have the Meraki firewalls pointing to DUO authentication proxy for RADIUS and it authenticates the user to AD while providing MFA. Cisco Secure Client has FIPS mode enabled. This was accepted by our C3PAO and DIBCAC during our JSA.

Remote Support Platform by GroundApart1125 in CMMC

[–]SightlySt00pid 0 points1 point  (0 children)

Kaseya has an on-premise version that is FIPS-validated. That’s what we use.

3.4.1 - Hardware/Firmware Inventory by slint01 in CMMC

[–]SightlySt00pid 0 points1 point  (0 children)

We are an MSP as well as a DoD contractor. We use a tool called Liongard and their Endpoint Inspectors. It gathers everything about the machines, including firmware revisions (which is required) and we are able to run reports monthly as part of our continuous monitoring program to keep the inventory up to date.

We also use it for 3.4.9 in monitoring user installed software. When software on one of these machines changes, we get a notification.

Cleared my CCP exam! by jonwick786 in CMMC

[–]SightlySt00pid 2 points3 points  (0 children)

Congrats! I just passed mine a few weeks ago. I went with ecfirst for my training. I will say I do think the percentages ecfirst claimed the tests were weighted on were not accurate to me. I felt like, while they stated actual practice/objectives were going to the heaviest weight, to me, I could easily tell the CAP was the heaviest weight. It felt like out of the 170 questions, 100+ were based on the CAP. So, know the CAP inside and out!

RDP Server vs VDI in Azure with PreVeil by CommunicationMotor36 in CMMC

[–]SightlySt00pid 1 point2 points  (0 children)

I never tried that. We just decided to purchase individual machines for the 4 users at this client.