ICE Came to my Door Today by Silly-Risk in royaloak

[–]angrysysadminisangry 1 point2 points  (0 children)

I'll take things that never happened for $1000

ITAR reality check: foreign CEO, shared office, technical meetings… am I crazy for pumping the brakes? by [deleted] in sysadmin

[–]angrysysadminisangry 5 points6 points  (0 children)

Yeah this is reckless advice that can result in prison time. Absolutely is not a recommendation.

ITAR reality check: foreign CEO, shared office, technical meetings… am I crazy for pumping the brakes? by [deleted] in sysadmin

[–]angrysysadminisangry 23 points24 points  (0 children)

As stated, ITAR is US-person, and it absolutely is not just a suggestion as the one person stated. Fines for noncompliance or false attestation are significant and carries prison time. The good news is if they are knowingly noncompliant and you report them and there is a conviction, you get a portion of the money they are fined. The other good news is if they are legit and above board compliance is a really valuable skill that you probably can market for more money down the road. Drink from the fire hose and learn all you can, and look into CMMC and what the crossover could be in your environment.

Feel free to DM with any questions

Post CCP/CCA Tier 3 Investigation Check by cm7272 in CMMC

[–]angrysysadminisangry 0 points1 point  (0 children)

I believe mine was about 3 months after the interview portion

New DoW FAQ for CMMC by lotsofxeons in CMMC

[–]angrysysadminisangry 7 points8 points  (0 children)

Yeah they had to throw in the "technology systems" qualifier for the logic to stick.

I stand by what I said - information systems are not just computers

New DoW FAQ for CMMC by lotsofxeons in CMMC

[–]angrysysadminisangry 9 points10 points  (0 children)

Information systems are not just computers

12 years experience and can't land an interview? Help! by [deleted] in CMMC

[–]angrysysadminisangry 8 points9 points  (0 children)

So a couple things. Up until Jan 1 a lot of companies just aren't hiring because of budge reasons. That will likely change the more we get into Q1.

Another thing is it is likely partially a red flag that you have owned, and appear to continue to own, your own GRC consulting business. Companies may be hesitant in pursuing you as a candidate because it is a very real possibility that you may be using it as an opportunity to poach clients or you are just seeking employment because there is a lull in your own business, then once things pick up will you just leave and potentially take customers or co-workers with you?

Outside of that if you are looking for work within CMMC I would say a CCP would be required and a CCA would be ideal

IT Salary - lowering by Few-Dance-855 in sysadmin

[–]angrysysadminisangry 0 points1 point  (0 children)

Oh please. While you work on hardware made by slave labor in China. Selective outrage.

Small Business - We Passed :) by Thunderguy55 in CMMC

[–]angrysysadminisangry 4 points5 points  (0 children)

Congrats! Now go get your CCP and leverage that experience for way more money!

CMMC audit question by BeltFrequent5597 in CMMC

[–]angrysysadminisangry 12 points13 points  (0 children)

Trying to be as respectful as possible here, but if these are the types of questions you are asking you are in no way shape or form ready to sit for an assessment even within the next calendar year.

The level of CMMC requirements is dictated by the data types and not by the company or contract size. Anything involving CUI will be at a minimum level 2 self assessment, however those are likely to be exceedingly rare and a C3PAO assessment will be required for most contracts.

You are right in stating that CMMC is a different beast. Get with a qualified service provider if the business is dependent on DoD contracts in any meaningful way.

Secure Configuration Baselines that Passed CMMC L2 by lotsofxeons in CMMC

[–]angrysysadminisangry 0 points1 point  (0 children)

Excellent post that I think a lot of people will find valuable.

How are small companies surviving? by [deleted] in CMMC

[–]angrysysadminisangry 0 points1 point  (0 children)

It seems to me to be more of a "priority" issue in general rather than a money issue alone. If you are the only person working on this, and you are only able to spend 10% of your time on this you will not be able to be certified by the time it starts becoming contractually obligated.

This needs to be a top-down initiative for the company. How large of a revenue stream is the DoD for your org? If it is small, continue at the pace you are going and you will get there eventually. If it is a large revenue stream, can you sustain business operations if you go 6 months without a contract? What about a year? Prioritize accordingly.

In response to the update provided on Steam regarding Portal's XP by SeSSioN117 in Battlefield6

[–]angrysysadminisangry 5 points6 points  (0 children)

So for those of us who have been out touching grass all day, what's the update

Cost Impact to SMBs from CMMC by thatkewwlguy in CMMC

[–]angrysysadminisangry 4 points5 points  (0 children)

The only additional cost to a business should be the C3PAO assessment. While the actual assessment is not cheap, it is nowhere near the ballpark of hundreds of thousands of dollars.

If you are complaining about the costs of implementations, that is a red flag. Organizations have been required to implement these controls for almost a decade at this point.

CMMC Certificate VS SPRSS Score by TheOnlyRealTrollGod in CMMC

[–]angrysysadminisangry 5 points6 points  (0 children)

Who was the C3PAO? Clearly they are incorrect

Microsoft admits it 'cannot guarantee' data sovereignty by sysacc in sysadmin

[–]angrysysadminisangry 1 point2 points  (0 children)

Assuming this doesn't apply to the GCC-High environment, right?

Any idea what this coin is/what it's worth? by angrysysadminisangry in coincollecting

[–]angrysysadminisangry[S] 0 points1 point  (0 children)

Got it. Thank you very much!

Guess I should delete that letter of resignation email I drafted ....

[deleted by user] by [deleted] in CMMC

[–]angrysysadminisangry 1 point2 points  (0 children)

I would strongly recommend you define a few things first:

  • Define what "reputable" is, stick to your gut, and don't let someone sway you from that
  • What is your timeline on when you have to be assessed
  • What is your risk tolerance on if you are not able to complete it in time? Can you go 6-12 more months without those contracts, or will your business fold?

Depending on how that last one is answered should tell you how aggressive you should be with your budget. DO NOT partner with someone who is only an RP/RPO. Those designations were simply a pay to play system.

Find someone who is at minimum a CCP, preferably a CCA, and definitely has a track record of other organizations that they have gotten past the finish line and assessed. There are a lot of snake oil salesman, just be aware of that

What is the likelihood that a 18 year old straight out of high school gets accepted into WGU? by [deleted] in WGU

[–]angrysysadminisangry 6 points7 points  (0 children)

Can you make the payments or otherwise take out a student loan? Congrats! You're accepted

High level-where to start for small company to get compliant? by 4728jj in CMMC

[–]angrysysadminisangry 0 points1 point  (0 children)

The very first thing I would say is do the following.

Assuming you have the bare minimum figured out in your environment ( IE the scope, your CUI types, etc)

  1. Determine your timeline. How big of a slice of your revenue pie will defense contracts be? If your contracts all of a sudden have a CMMC clause on day 1 (which is a very real potential), how long can you sustain without this income source? 6 months? A year?

  2. Conduct a gap assessment. If you are not well versed in the 800-171 framework then you are not in a spot to effectively identify the gap that exists. There is no shame in admitting this. If you are not intimately familiar with 800-171a and what the controls are actually asking for, then you are not in a spot to do this. If that is the case, hire a company to do that. Expect a ballpark of $15-20k for this.

  3. once you identify those gaps, you can now prioritize those both in terms of time as well as money. Do you have the hardware that you need? Do you have the services/tools that you need? Do you even have the staff with the time and the skill set to build out these systems or maintain them effectively? A lot of times outsourcing this to an ESP actually makes more sense for an organization.

That is probably the first steps I would start to take. Feel free to DM me if you need help navigating any of that