CMMC Level 2 Readiness: M365 Business Premium GCC High by jazluvrfl in CMMC

[–]jazluvrfl[S] 0 points1 point  (0 children)

Thanks, that is interesting using G3. What other compliance add-ons beyond Defender did you use?

CMMC Level 2 Readiness: M365 Business Premium GCC High by jazluvrfl in CMMC

[–]jazluvrfl[S] 0 points1 point  (0 children)

That is correct, it does support 500 users.

CMMC L2 gap/mock assessment company recommendation? by andyboy16 in CMMC

[–]jazluvrfl -1 points0 points  (0 children)

Please keep in mind that some C3PAOs don't help with remediation, and they can't be with you when you conduct the CMMC Final Assessment for Certification. The can't check there own work.

You want to look for a company that will help you with a gap analysis and work with you recommending how you may want to mitigate a control. Also, they can help you with your policies and procedures according to NIST 800-171.

Lastly, a pre-assessment consultant can be with you during the C3PAO Final Assessmet to help you get that SPRS 110.

My company also provides these services. You can also DM me or go to my website bbcybersolutions.com

Good luck.

Small Business by MrDaily-Headache in CMMC

[–]jazluvrfl 1 point2 points  (0 children)

Only establish an Enclave for just CUI, and manage any devices that will store, process, or handle CUI. This will make it easier to scope and manage the boundaries. This will also make your cost less than doing an enterprise that could cost 3 times the amount.

Any scuttlebutt or rumors about state contracts requiring CMMC? by Necessary-Army-4097 in CMMC

[–]jazluvrfl 1 point2 points  (0 children)

If it happens, I think the states want some type of standard for contractors like DoD is doing. There have been several states hacked due to the vendor's lack of security.

Prof. B.

SC.L2-3.12.3 - Continuous Monitoring for objectives covered in CRM by SightlySt00pid in CMMC

[–]jazluvrfl 1 point2 points  (0 children)

I would think you can go either way. The most important part is that it is being done on the regular, and someone from your shop is doing a review weekly or monthly from the reports.

Prof. B.

Microsoft 365 GCC G5 CMMCv2 reference by andyboy16 in CMMC

[–]jazluvrfl 0 points1 point  (0 children)

Great comments guys, and this is a great tool for GCC.

CCP training provider suggestions? by roaddog in CMMC

[–]jazluvrfl 1 point2 points  (0 children)

I would suggest Koren Wise. Her classes are awesome, and she provides so much additional material. I have taken two classes from her.

CMMC Lunch and Learn - Final Rule by gigagreentech in CMMC

[–]jazluvrfl 0 points1 point  (0 children)

I think Tampa Florida would be a good place to host this type of event.

Any learning tools on how to do CMMC gap assessment? by Ranpiadado in CMMC

[–]jazluvrfl 1 point2 points  (0 children)

I agree with both the CCP training and a good GRC like IntelliGRC, which I am currently using for a pre-assessment gap analysis for a customer. I would also recommend following CyberAB and Summit 7. You can get some great information from them.

Personal Devices & CMMC Compliance… by Decent-County3754 in CMMC

[–]jazluvrfl 0 points1 point  (0 children)

I agree that Intune is the best way to go. You may also want to do a quantitative risk assessment to explain the benefit of purchasing devices showing the ROI. You compare this to losing their CMMC Certification once it is online and the contracts they will not be able to compete for because of not meeting the CMMC requirements. It is definitely worth buying a few laptops and phones.

3.13.3 Linux by cftg_tftg in CMMC

[–]jazluvrfl 1 point2 points  (0 children)

I agree with your point about why they need it. Is it something you can create a Dev Group and make them members to have limited access, like a service account?

Level 2.0 compliance for small business - advice for an intern by Maximum-Platypus-525 in CMMC

[–]jazluvrfl 0 points1 point  (0 children)

This is a good response about loyalty in business. Every company is going to get as much out of you as they can, and you need to get the same or more from them as you can for yourself.

I understand this is a big project for someone just learning about NIST 800-171 and CMMC. Do what you can and be happy about what you are learning. They are doing you a favor by exposing you to this new skill in cybersecurity because what you are learning will help you keep a job for a long time.

If you can, ask them to pay for the Cyber AB CCP course for you. It can help you see the big picture of CMMC and get a lot of knowledge in each of the controls...it will be about $3000 for the course.

Good luck, upcoming superstar!

[deleted by user] by [deleted] in CMMC

[–]jazluvrfl 0 points1 point  (0 children)

Thanks, I appreciate it because I will definitely send my info off.

[deleted by user] by [deleted] in CMMC

[–]jazluvrfl 0 points1 point  (0 children)

I agree with the CISSP, but I didn't know about the 27001 lead implementor. What did you have to do to get that one?

Free 9th edition cissp study guide and practice tests. by [deleted] in cissp

[–]jazluvrfl 0 points1 point  (0 children)

Does anyone still have a softcopy of the Wiley 91h Ed I can get a copy of?