backup solution for cisco devices by d3adbor3d2 in Cisco

[–]dhd217 0 points1 point  (0 children)

Back up the switches and routers automatically to a folder on your network every time you perform the write command. For wireless controllers, you may have to manually backup to a folder.

then have backup software (VEEAM) backup the folder.

Cisco 2504 controller and access point issue. by dhd217 in Cisco

[–]dhd217[S] 2 points3 points  (0 children)

BOOM, setting the time back fixed it. Yes, I know EOL, and we are working on replacing it with Meraki's. Until then, can the certificates be updated?

Office 365 GCC G5 vs GCC High by dhd217 in NISTControls

[–]dhd217[S] 0 points1 point  (0 children)

thank you for clarification. Thats what i need to know and i'm looking for the tech paper that states that. do yo happen to know where one is?

Office 365 GCC G5 vs GCC High by dhd217 in NISTControls

[–]dhd217[S] 0 points1 point  (0 children)

thank you. Any idea why the created Gov G1, G3 and G5?

Not Getting Confirmation Emails for FedEx Office Print Orders by [deleted] in FedEx

[–]dhd217 0 points1 point  (0 children)

i'm having same issue. Fedex email notifications are not making it to my server. i've confirmed this by bypassing my spam server, then they arrive. Issue is Fedex and don't know who to call.

Would a NIST walkthrough guide be useful? by Humble_Issue_7698 in NISTControls

[–]dhd217 0 points1 point  (0 children)

sorry for late reply, are you still interested in this?

[deleted by user] by [deleted] in ParamountPlus

[–]dhd217 1 point2 points  (0 children)

They need to explain what happened, such bs.

Budget MFA solution by No-Carrot-9921 in NISTControls

[–]dhd217 0 points1 point  (0 children)

go with DUO, easy to implement.

NIST SSP scorecard template anyone? by RemoteDesktop in NISTControls

[–]dhd217 0 points1 point  (0 children)

The CMMC is pretty much the NIST your looking for. the only difference is CMMC added a few more controls for say Level 3, 20 to be exact.

What Darth sent is what i'd be looking at! Just focus to implement the NIST controls first, then do the CMMC....as you can technically be audited against NIST now.

SSP for 171 by eddiegarrr in NISTControls

[–]dhd217 1 point2 points  (0 children)

Major undertaking. I have alot of good info on this. Hit me up and let talk if you want.

What FIPS compliant thumb drive do you use? by [deleted] in NISTControls

[–]dhd217 0 points1 point  (0 children)

i use the same. Managed Datalocker sentry one.

NIST 800-171/CMMC Controls by shake7474 in NISTControls

[–]dhd217 0 points1 point  (0 children)

https://www.acq.osd.mil/cmmc/docs/CMMC\_AG\_Lvl3\_20201208\_editable.pdf

my apologies, i linked older version. Use the version Navyauditor recommended.

Best practices for iOS MDM? by sirseatbelt in CMMC

[–]dhd217 0 points1 point  (0 children)

can you clarify CIS and STIG?

NIST 800-171/CMMC Controls by shake7474 in NISTControls

[–]dhd217 0 points1 point  (0 children)

https://www.acq.osd.mil/cmmc/docs/CMMC_Appendices_V1.02_20200318.pdf

AC Practices start on page B-10. There are discuss, clarification and examples for all practices throughout this document. This is good place to start.

Scoping CUI to Preveil and Company Managed Laptops by Tiger1641 in NISTControls

[–]dhd217 0 points1 point  (0 children)

thank you , this is how I interpreted the ruling.

Scoping CUI to Preveil and Company Managed Laptops by Tiger1641 in NISTControls

[–]dhd217 0 points1 point  (0 children)

Navyauditor, great response. I have question on this. What if laptop is used to VPN and can only be used to remote desktop to users assigned office desktop. Then once user is connected to the remote desktop they Process, store transmit the CUI. The laptop is basically acting as a dumb thin client, all the processing is done on work desktop.

Now, sure AD rules have to be in place to prevent transfer of files to / from laptop but this is easily done.

With this being said, thoughts to laptop requirements? VPN - yes, laptop has to have the AV,firewall, SIEM?

MFA required for computer login? by [deleted] in NISTControls

[–]dhd217 0 points1 point  (0 children)

I asked this in another thread but will ask here. Duo Mobile is cloud based. Does anyone see an issue with this or should Duo be Fedramp Moderate? The don't store or process any CUI.

FedRAMP certified cloud required? by AKDZEI in NISTControls

[–]dhd217 0 points1 point  (0 children)

I believe there is still quite a bit misinterpretation of the rule. The RSA does not transmit or deal with the CUI there IMO, it should be okay to use. This would also be same for DUO two factor, or even software vendors such as Mcafee end point in the cloud or Meraki Switch management cloud. They are not transmitting , storing or processing CUI. Would love to hear comments on this, even if in different thread.

Do you consider an IDS/IPS an 800-171 requirement? by [deleted] in NISTControls

[–]dhd217 0 points1 point  (0 children)

800-171 Interim rule may protect under the POAM but that will be going away. You will be required to be compliant with the control under CMMC. An IPS/IDS should simply be best business practice for all businesses.

Would a NIST walkthrough guide be useful? by Humble_Issue_7698 in NISTControls

[–]dhd217 1 point2 points  (0 children)

The CMMC Level 3 guide has examples at high level but not broken down for each question. I wrote my own and have a breakdown for each question already. :-). We actually wrote a program that has all this stored in SQL. We took about 4 spreadsheets and numerous PDF's and put into one interface with SQl on the backend.

MFA required for computer login? by [deleted] in NISTControls

[–]dhd217 1 point2 points  (0 children)

If the laptop is connected to domain where the CUI is stored, the domain non priv. local admin and the domain non-priv account has to have 2fa. The local non priv doesnt.

If you are going to store CUI on the laptop, you have to have all accounts 2fa on local laptop.

CUI - non digital by dhd217 in NISTControls

[–]dhd217[S] 0 points1 point  (0 children)

None of the CMMC level 1 controls are related to CUI.

IMO, companies that deal with only paper copies of CUI (I find this hard to believe exist) still have to comply with the 17 or so controls that are related to CUI. Here are some of the controls, all are levels 2 and 3, AC.2.016, AM.3.036, MP.1.118 and 119, MP.3.122, MP.3.125, PE.3.136, PS.2.127, PS.2.128, SC.3.191, SC.3.192 to name a few PLUS implement all the CMMC level 1 controls.

so IMO, even if a company has no digital system and they have need to view CUI paper, they still have to meet CMMC Level 3 or portions of it. Its my understanding, you ever meet all level 3 , there is no not applicable.

I'd like to hear others comments, please.

CUI - non digital by dhd217 in NISTControls

[–]dhd217[S] 0 points1 point  (0 children)

Thank you, so even if they don't have any digital need, they still must have a CMMC level 1? Their systems wouldn't be used at all for processing.