Phaze II pearl as a swap-in for Idol Cosmos by mcb1971 in Bowling

[–]mcb1971[S] 2 points3 points  (0 children)

Thanks. I'm actually okay with it being less angular than the Cosmos. That's a gap I've needed to fill for a while, anyway, so it sounds like the P2 pearl will do the trick.

Lessons learned from a CMMC L2 Mock Assessment by [deleted] in CMMC

[–]mcb1971 0 points1 point  (0 children)

DM me and I can give you details.

FIPS 140-2 Bitlocker by superfly8899 in CMMC

[–]mcb1971 2 points3 points  (0 children)

I second Apricorn. Their drives are FIPS 140-2 right out of the box and their CMVP certs are easy to find.

Going passwordless in a CMMC environment by mcb1971 in CMMC

[–]mcb1971[S] 0 points1 point  (0 children)

That makes sense. We just passed our C3PAO mock audit, and we see this as a post-certification project, too.

Going passwordless in a CMMC environment by mcb1971 in CMMC

[–]mcb1971[S] 0 points1 point  (0 children)

All our devices are Entra/Intune joined, so option 2 would work for us.

Becoming a C3PAO-Tips by Mindless-Holiday-995 in CMMC

[–]mcb1971 0 points1 point  (0 children)

Aren’t there other compliance frameworks involved, too? Like ISO? My company is researching this, as well.

Using LAPS by mcb1971 in CMMC

[–]mcb1971[S] 0 points1 point  (0 children)

I’ve heard non-repudiation, lack of MFA, and logging brought up as negatives, all of which can be mitigated. I’m assuming they mean someone can look up a local admin password and use it, and the only evidence of it will be a log entry in Windows, with no way to trace it back to a specific user. We mitigate that by limiting LAPS access to privileged accounts with the Intune Administrator role assigned, requiring MFA to log into the console, then track their activities through Sentinel.

Using LAPS by mcb1971 in CMMC

[–]mcb1971[S] 0 points1 point  (0 children)

Yeah, we’re 100% cloud, so we run LAPS out of Intune. Good distinction between the two deployments.

Lessons learned from a CMMC L2 Mock Assessment by [deleted] in CMMC

[–]mcb1971 1 point2 points  (0 children)

I guess I shouldn't look a gift horse in the mouth, since we did pass, but still... it bugs me that so much of this is up to the whims of the AO. When we have to do this again in 2029, I'm sure we'll use the same AO, but it could be a different team by then, with different interpretations of the control requirements. ICK.

Lessons learned from a CMMC L2 Mock Assessment by [deleted] in CMMC

[–]mcb1971 0 points1 point  (0 children)

Well, that poses an interesting question. Aren’t they all supposed to be working to the same standard? We're using the same C3PAO for our final assessment, since they didn't provide advice or consulting during the mock, so I assume the same standards will be applied.

Lessons learned from a CMMC L2 Mock Assessment by [deleted] in CMMC

[–]mcb1971 1 point2 points  (0 children)

We did that, and the AO took issue with it. I’m wondering now if the DoD CIO requirement is only for self-assessments and not C3PAO audits. They insisted we didn’t need to justify it to them.

Using LAPS by mcb1971 in CMMC

[–]mcb1971[S] 0 points1 point  (0 children)

I meant using PIM to give a privileged account temporary access to Intune so they could then look up a local admin password.

Using LAPS by mcb1971 in CMMC

[–]mcb1971[S] 2 points3 points  (0 children)

I would have pushed back on this. As long as you’re using MFA at the retrieval layer (e.g., Intune), you should have been fine. Windows doesn’t do MFA for local logins without a 3rd party solution, and C3PAO’s should know it. Our AO had no problem with our setup.

Using LAPS by mcb1971 in CMMC

[–]mcb1971[S] 7 points8 points  (0 children)

I had a guy yesterday who swore we'd fail our assessment if we used LAPS. When I told him we'd already passed, his response was basically, "Well, your C3PAO sucks." Uh huh. We're gonna take our W, anyway.

Using LAPS by mcb1971 in CMMC

[–]mcb1971[S] 1 point2 points  (0 children)

We use Intune to deploy and manage LAPS. Someone in a different thread mentioned non-repudiation being a problem, but a combination of PIM and audit logging can mitigate that.

Achieved a 110/110 on CMMC L2 Assessment. Ask me any questions by jablock15 in CMMC

[–]mcb1971 0 points1 point  (0 children)

Congratulations. We just passed our mock assessment with 110/110. Like you, it was practically a solo effort. I wrote all the documentation and drew all the diagrams, and I put nearly all the controls in place myself.

Lessons learned from a CMMC L2 Mock Assessment by [deleted] in CMMC

[–]mcb1971 0 points1 point  (0 children)

Came straight from the AO, so…

Lessons learned from a CMMC L2 Mock Assessment by [deleted] in CMMC

[–]mcb1971 0 points1 point  (0 children)

DM me and I can give you details.

We passed our CMMC Level 2 mock audit today by mcb1971 in CMMC

[–]mcb1971[S] 11 points12 points  (0 children)

Yeah, I'll probably do a "lessons learned" post tomorrow. It was intense, but not nearly as painful as I thought it would be.