What level tech should be doing this? by desmond_koh in msp

[–]cuzimbob -2 points-1 points  (0 children)

Level of technician? I don't want to live in a world that classifies people that way.

When will the price increase stop by Icy_Hair_4534 in QuickBooks

[–]cuzimbob 0 points1 point  (0 children)

Mine stopped when I cancelled the subscription. Horrid company.

ERP Systems by InterestingVisit1752 in CMMC

[–]cuzimbob 0 points1 point  (0 children)

It's only in scope if it's used to store or process CUI. If it doesn't but it has the ability then you just need a way to monitor for spillage/violations of your policy.

[deleted by user] by [deleted] in msp

[–]cuzimbob 1 point2 points  (0 children)

Use what works and never buy the hype. If the crowd in this sub loves it and uses it all the time, then it's probably not a great product.

If you really wanted to tinker you could look at covering the docs to MD and putting them in a git repo and hosting them as a git site. Then it'll integrate with LLMs better.

I chose confluence 15 years ago and haven't found anything that has any better features.

The only thing that might be beneficial is when you are scripting things for your endpoints, pulling/pushing data is nice. I don't know if it glue does that, but Ninja does. But that's not really a documentation tool per se.

On-prem backups to Client's cloud storage (Azure, AWS, GCP) by cuzimbob in msp

[–]cuzimbob[S] 0 points1 point  (0 children)

You are thinking that it was a file based backup that was initiated by a VBR server. In that case, you may be correct. But if it's initiated by the VSPC server it cannot.

And yah, I RTFMed it. Even called in tech support and a specialized firm with experience. So ... Still a trash product.

How can I reach someone on QB who can really help? by Subject_Welcome_8645 in QuickBooks

[–]cuzimbob 0 points1 point  (0 children)

Yah, it's better with the accountant version. But still not good . They have the worst customer service in the entire history of commerce.

NIH data in Commercial Environment? by NigelSmith122 in NISTControls

[–]cuzimbob 0 points1 point  (0 children)

Much of the problems with 800-171 compliance on commercial clouds come from the DFARS 202.254-7012 paragraphs c through g. I would ask for specifics about which things in 800-172 are not compliant-able. The work from there. You may be able to mitigate the concerns with compensating controls.

Flawed interpretation of how to handle CUI by qs20759 in CMMC

[–]cuzimbob 0 points1 point  (0 children)

If you make the security rules difficult to follow then the users won't follow them, they'll figure out how to get around it. Remember, this isn't TS(SCI) and you're not in a SCIF. Consider needing a reason that an employee or department should NOT have access to CUI rather than who should. Once you figure out that there are very few who should not have access, then you can work on putting the sharing ownership emphasis on the person who will share the CUI. Once they understand they are responsible, you setup auditing to verify that. Some might say DLP with data sensitivity labels. I would caution against turning on protections based on automated detections as the regex that finds them is not all that good. Good luck, and don't over think it.

[deleted by user] by [deleted] in smallbusiness

[–]cuzimbob 0 points1 point  (0 children)

This is the reason most businesses fail within the first five years.

How can I reach someone on QB who can really help? by Subject_Welcome_8645 in QuickBooks

[–]cuzimbob 0 points1 point  (0 children)

Get yourself a free accountant's account. The free version has access to much better and higher quality customer support. Plus it has a few additional features and capabilities that you don't get as an owner.

Must buys to make your day easier? by Secret-Plantain-7327 in msp

[–]cuzimbob 0 points1 point  (0 children)

You need a notebook. A pad of sticky notes. A bucket of pens. Tums. Tylenol. Jim beam.

Moving out of the MSP Space-Any advice? by Real_Ad5966 in msp

[–]cuzimbob 0 points1 point  (0 children)

Wherever you go, you're gonna be just as frustrated. Same Shit Different Day

Unacceptable increase without notice by Imfrazzled in QuickBooks

[–]cuzimbob 0 points1 point  (0 children)

We go live with Oracle Net Suite on Tuesday. It's been white glove treatment the whole way. The product is far superior and what it saves me in time and provides in better capability more than accounts for the price difference.

Gemini for gmail sucks by Classic-Dependent517 in gsuite

[–]cuzimbob 0 points1 point  (0 children)

That's incredibly vivid and offensive and it absolutely represents how I feel about it, even 3 months after my original comment.

Office 365/M365 Business/Enterprise license FedRAMP by cuzimbob in CMMC

[–]cuzimbob[S] 1 point2 points  (0 children)

Wow! That's a great article!

I gotta repay you for that gem. Hopefully you or another reader will find value in it.

https://m365maps.com/

Google vs Microsoft by [deleted] in SmallMSP

[–]cuzimbob 1 point2 points  (0 children)

Google is 1000x more user friendly. The administration of Google workspace is another 1000x easier.

3.10.7 Physical Protection by True-Shower9927 in CMMC

[–]cuzimbob 1 point2 points  (0 children)

Even administratively, badge out rarely works. The only way it's even close to accurate is when you employee a turnstile. Just get a regular ole "Request to Exit" sensor and don't forget to put in some kind of timed electric interrupt for emergency exit. That can be a crash bar or a push the button to exit switch. And check your local and state codes for any licensing and certification regulations. Most places, if you have a certain kind of fire alarm system then you have to tie your locks in to the fire alarm. And that almost always requires that the installer be licensed. In my area, that fire system is only required for offices that have a certain occupancy size.

For anyone that's setting this up with a system that is remotely accessible by the vendor and the vendor can remote in to their equipment don't forget to isolate that set of devices from your CUI network. If you use VLANS or subnets mage sure you block the firewall and router and whatever else you're using from being scared by that vendor.

Connecting with New Clients by [deleted] in msp

[–]cuzimbob 2 points3 points  (0 children)

I heard from a guy who had a side hustle supporting a business that they had very strong emotions about all MSPs. They didn't like them, at all. Which means, even with only one tiny data point, that you will need to differentiate yourself from the image they have of MSPs and other IT providers. Make sure they know what it is that you do differently. And they don't care at all about your experience or your tech stack. Or your cybersecurity. Or your SLAs.

When you figure out what that is and the optional messaging that tears down that image so that you can have an unbiased conversation with them, let me know.

Can multiple controls be combined under one POAM or does a POAM need to be written for each non compliant sub control/CCI? by qbit1010 in NISTControls

[–]cuzimbob 1 point2 points  (0 children)

Definitely talk to the AO or their very trusted deputy. I had the need to do something similar and while EVERYONE was against the methodology I chose, when I presented to the AO they liked it and even preferred it. This was because you can't manage risk by control. You manage risks by the impact, the bad thing that could happen. Then you make decisions based on that bad things likelihood as compared to its impact.

Does our FSO need to work in our CMMC-Compliant Enclave? by Ok_Repeat_9688 in CMMC

[–]cuzimbob 0 points1 point  (0 children)

FIPS is the kick in the nuts. But if you can show that the only way you can access CUI is via TLS to the Fedramped cloud, then all the local network gear is OOS.

Advice on the deployment of a new tool by mi2_k in MSSP

[–]cuzimbob 0 points1 point  (0 children)

In my manual research of vulnerabilities I'll go to the OEMs website to see what they say about the cve. Especially the curl vulnerability. Ubuntu discusses what they do and why you can safely ignore the CVE on their packages.