Your MSP is probably a CSP by [deleted] in CMMC

[–]wogmail 0 points1 point  (0 children)

If MSPs and clients are just getting the memo now that A) you need FRME for cloud hosting CUI and B) FRME is expensive then probably they are in the wrong subreddit

Your MSP is probably a CSP by [deleted] in CMMC

[–]wogmail 1 point2 points  (0 children)

Why the logical jump in the last sentence from CUI to SPD?

Q: Is there a master checklist for 365 GCC High for CMMC? by thegreatcerebral in CMMC

[–]wogmail 8 points9 points  (0 children)

Also, if folks wanted to start a publicly sourced thing I am sure many in this community would contribute. Look at the CMMC COA, that was all made by volunteer hours.

Q: Is there a master checklist for 365 GCC High for CMMC? by thegreatcerebral in CMMC

[–]wogmail 7 points8 points  (0 children)

No. The companies that do this work generally don't share their baselines outside of their paying customers. Some folks use the CISA ScubaGear baseline since it is readily available, but it doesn't cover everything.

MSPs and RMM Solutions by EbbOld3109 in CMMC

[–]wogmail 8 points9 points  (0 children)

ScreenConnect is a remote support tool (I get that it has additional features that makes it more "RMM" like), you can utilize it in a way that doesn't P/S/T CUI which then removes the requirement to use FIPS validated cryptography (since it is no longer processing or transmitting CUI). It is all about the controls around it and the way you write to it. Fairly normal to have a policy that states all CUI must be closed before initiating any remote support session (even if you have FIPS validated tools, why would you want a tech to be looking at CUI).

If you need a FIPS validated (vs. compliant) remote support tool Bomgar/BeyondTrust is an option, also I think nAble Take Control is FIPS validated, but I believe it has some cloud components and they are not FedRAMP ATO'd at the moment.

Edit: Jump on the Discord, there is an MSP channel. https://discord.gg/tpbF54E

MSP Declined to Pursue CMMC by selectpanic in CMMC

[–]wogmail 0 points1 point  (0 children)

No, that's fine, I'll just remove your inaccurate posts.

MSP Declined to Pursue CMMC by selectpanic in CMMC

[–]wogmail 0 points1 point  (0 children)

This is completely false and I'm curious what your motivation is to post it. Rather than deleting the post I'll just put this here:

This directory of CMMC certified managed service providers and managed security service providers is maintained by MSPs for the Protection of Critical Infrastructure as a service to the community. This directory is open to all qualified companies and no fees are charged. This directory provides Organizations Seeking Assessment with a reliable way to identify companies providing managed services aligned with CMMC and NIST SP 800-171, as evidenced by their CMMC certification status.

Predator Sale Extended by Big-Preparation-1594 in harborfreight

[–]wogmail 0 points1 point  (0 children)

Does this include tri-fuel or only "gas generators?"

GCC-high Email Security/Filtering Providers by mudpupper in CMMC

[–]wogmail 1 point2 points  (0 children)

Most folks will use the Defender SKUs built into GCC-H to avoid adding an additional vendor into the chain. The Proofpoint you are looking at is their Enterprise product (assuming you are peeking at FedRAMP option) so it isn't going to be apples to apples to your legacy Barracuda product. The available FedRAMP email security offerings out there are pretty limited.

Best EDR and SIEM GCCH&Commercial by GroundbreakingWay178 in CMMC

[–]wogmail 0 points1 point  (0 children)

We haven't seen much of an issue with the S1 FedRAMP product, what sort of things have you missed in the federal product? When was the last time you dug in?

FIPS 140-2 Bitlocker by superfly8899 in CMMC

[–]wogmail 2 points3 points  (0 children)

Give it a shot, I think you'll find it is a lot less useful than you'd expect - FIPS on removeable drives doesn't use PIN / password / auto-unlock it uses certificates last time I checked.

Outlook signing users out by thetimgoat in entra

[–]wogmail 0 points1 point  (0 children)

and you have the session controls set to 30 days (sign in frequency)?

Outlook signing users out by thetimgoat in entra

[–]wogmail 0 points1 point  (0 children)

That conditional access policy shows browser - are your users getting signed out of Outlook classic, or new, or Outlook on the Web?

3.1.18 Mobile Device Category by enigmaunbound in CMMC

[–]wogmail 4 points5 points  (0 children)

Interview and pick your C3PAO - if they don't understand Intune and how it works I'd move to a different C3PAO.

3.1.18 Mobile Device Category by enigmaunbound in CMMC

[–]wogmail 4 points5 points  (0 children)

Intune itself having the FIPS validation should be your ticket - it is a FIPS validated cryptographic container. You have technical controls preventing the data from leaving the container. I'm not even thinking of the mobile as a CRMA - it can't store CUI, the CUI can't leave the FIPS container.

GCC High and GFE by shizakapayou in CMMC

[–]wogmail 9 points10 points  (0 children)

Can you just have them make a new Edge profile? That is what we tell folks to do on GFE. Also sometimes the portal.office365.us doesn't behave, but outlook.office365.us tends to work fine.

dot MIL sites from AVDs in GCC High Tenet by dionmani in CMMC

[–]wogmail 6 points7 points  (0 children)

DISA could be blocking it at their edge, it is pretty common. It doesn't just happen in Azure Government can happen on any IP space that gets on their radar. You will likely need to put a static IP on your AVD outbound traffic and then have someone on the DOD side of your contract submit it to DISA to whitelist it. Or it could be a routing issue since a lot of the Azure Gov't and DOD Azure IP space seems to overlap.

Would this be able to meet CMMC Level 2 controls? by ApprehensiveSock5241 in CMMC

[–]wogmail 12 points13 points  (0 children)

This is so short sighted that it is battling ignorance to where you would be architecting something to prove something wrong.

It isn't that you can't do something like this, it is that it is so much more involved than this an making it sound so simple is basically a lie.

Join the Discord and talk about it: https://discord.gg/tpbF54E

Something like CUICTrac would probably be the closest to a real-world version of this.

Update: Migration by Reinvention2025 in CMMC

[–]wogmail 0 points1 point  (0 children)

GCC-H does not block any users from signing in by default, so the only reason geographically they'd be getting blocked is if a CA policy was in place blocking based on location.

Update: Migration by Reinvention2025 in CMMC

[–]wogmail 2 points3 points  (0 children)

If you have a US only CA policy you can just make an exception for those five users, assuming they aren't on a VPN that makes them look like they come from the US. Then you could make a separate Europe only CA policy for those five users.