In this episode of Climbing Mount CMMC, Bobby and Kaleigh discuss the critical aspects of maintaining CMMC compliance after you pass your assessment. They cover maintenance activities, evidence gathering, and scaling strategies for MSPs and organizations to stay compliant and prepared for audits.
NIST 800-171: Protecting Controlled Unclassified Information in Nonfederal Systems
Website: https://www.axiom.tech/
YouTube: https://www.youtube.com/channel/UCaJagoDasNG3MqLqw2Af_ZQ
Axiom's LinkedIn: https://www.linkedin.com/company/axiomtech/
Bobby's LinkedIn: https://www.linkedin.com/in/bobbyguerra/
Kaleigh's LinkedIn: https://www.linkedin.com/in/kaleigh-floyd-079a52190/
[00:00:01] Hello Climbers and welcome to Climbing Mount CMMC. Boxing up by 6. Good job. What is it doing? Look at that. Hello Climbers and welcome back to another episode of Climbing Mount CMMC, the podcast. My name is Kaylee Floyd and this is Bobby Guerra and we are a part of an MSP called Axiom
[00:00:29] that is CMMC Level 2 certified and we are going to be talking about maintenance today. A very, very exciting topic. Tons of people talk about it all over the globe. No, but to be serious, to be for real, a lot of people talk about assessment readiness, how to get ready for an assessment, how to pass, what to do with your C3PAO. But not a lot of people talk about, okay, what happens like after all that?
[00:00:54] Because it still keeps going and things keep happening and you have to maintain this environment that you've built, that CMMC compliance. So we're going to talk about that today and I think who better to talk about that with than somebody that had to do it not only for us, but also think about our clients' maintenance. So there's a lot of different aspects of this. So if you're an MSP that has to maintain your client's environment and your own,
[00:01:19] or you're an OSC that has to just maintain your own compliance for CMMC Level 2, this will be a great podcast episode for you. Yeah. So let's get into it, shall we? Well, I think there is an opportunity when you're doing your maintenance to think about how you can utilize that to prove that your tenant is functioning correctly or whatever your information system is. And you run into it all the time, Kaylee, where people reach out to you and they're like, I want to have my system built as fast as possible. How fast can I get?
[00:01:49] Because this organization, this prime, whoever is reaching to me and saying, hey, I need it now. How fast can I get it? Can I get it in a month or two? And the problem is your system security plan has to talk about how you're going to maintain the environment and make sure it's functioning and working the right way. So let's say that Kaylee goes through and does, let's say it's a 20-person company, and she's the person that authorizes users for access to the system.
[00:02:15] So there's some process that she has to go through to authorize them to then give them access to the system. What is that? It could be that Kaylee emails me the MSP to say, hey, add this user. And you're like, have they had their training? Have they done their background check? So there's going to have to be some type of validation and checking that's going to have to happen before you allow them authorization to the system. And that has got to be saved and tracked and kept somewhere. OK, so that's just the authorization.
[00:02:42] But yearly, right, under 312-3 has got the control review, right? So that's the CA family. And you're supposed to be reviewing those controls. So at least yearly, that process has to be examined. Is it functioning and working the right way that you'd want to do? And one of the ways you'd want to do that is to be like, is the user list in Intra or Active Directory
[00:03:05] or Okta or Amazon, does it match the list of authorized users that Kaylee thinks is allowed in the system? Because they have to be different. You can't just point towards Amazon's list or Okta or Intra and say, that's my authoritative list. No, that's the list that's already in the system. They're already in. There needs to be a list that you can compare that says, this is the authorized users. These are the users that are in the system. And then you compare them. If they match, you're good.
[00:03:32] What a lot of people don't understand is there has to be some type of maintenance and review process that has to happen for that, at least at some type of cadence or interval, at a minimum yearly for all of those that have to be reviewed and examined. So when you're thinking about those types of activities, that's where it starts to get interesting when you're like, I want to be in this set time. For us, we have certain activities that we do monthly, certain activities we do bi-yearly, some that we do annually, some that we do quarterly.
[00:03:59] And so those kind of fourth types of different things that we do, those all need to happen at least once. Typically, like most C-3PO's are like, if you're going to be doing something monthly, I want to see a few, like two to three monthly activities that proves that this has been done. If you're going to do it at some type of bi-yearly or quarterly interval, a lot of times C-3PO's will be like, okay, well, if you just at least run those once, that way I can see that you've done it. Like, for example, your tabletop exercise, right?
[00:04:29] So at least give me one exercise this year. You might have it in your plan to do it twice a year, but at least give me one. And so those are the types of things that you want to see. When you're thinking about trying to speed run a build of a tenant, you really do need to think about those types of things. Yeah. So for those of you who are not understanding, this is sort of like a one-two punch scenario where not only are you talking about maintaining it, but that maintenance is gathering evidence. And that evidence is needed for assessments.
[00:04:58] And also, I mean, it doesn't like write it down specifically, like you must need evidence for this, but your self-attestations that you do once a year. I really would hope if you're attesting correctly and saying, yes, we are still doing this, that you are still doing it and gathering the evidence for it. So not only is this needed every three years when you're doing your C-3PO assessment, but it technically is needed every year when you're self-attesting
[00:05:27] to this SPURS score of 110. You need to know that you're doing it. How do you know that you're doing it? You have the evidence that you're doing it. So I think really it applies to both of those. Yeah. Something to think about too there is, let's say we have an MSP relationship, right? So Kaylee, you have Kaylee's manufacturing, and I'm Bobby the MSP. And I'm going to help you get ready, right, Kaylee? So we create the best SSP we can do. We write how everything does.
[00:05:56] A lot of this stuff is custom and specific to how you operate. I go ahead and write a lot of stuff down about how you do it, about how you authorize users. You do background checks. You do all these different things for adding users and that you wipe devices and you're cleaning because you print CUI. And let's say you say, Bobby, I'm destroying it the right way. I'm wiping it off the thumb drives. I'm cleaning off the machines when we're done with it and we recycle them. All of those types of activities. Oh, yeah, yeah, yeah. You know, we're doing all the background checks. We're doing the training for our team.
[00:06:26] Don't worry about that, Bobby. We've got this. I'm like, okay, cool. And then you're saying, hey, Bobby, you guys got it. You're doing the patching, right? You're doing the updating of the devices. You're making sure the SEM data is being managed and monitored and examined and you're saving all that great evidence. So everybody's working as a team and it's all great, right? And you come to your assessment and you get to prove it. And then that year, you pass. Everything looks great. And then Kaylee's like, I got a lot of bids to do and I don't give a crap.
[00:06:55] And she's not validating the background checks have been done. Just the HR person says they're good and she goes ahead and saves it. She's not checking to make sure that the training's being done for their people. And she's not continually telling the MSP when people have left the company. She just puts the machines in there and then pretends like they're brand new boxes when she wants to go ahead and get them repurposed. As you start to see, it starts to devolve pretty quickly if you're not really paying attention. And within a year's time,
[00:07:24] you could then have a system that's not even close to accurate in how it's being maintained and managed. And then Dibcac DCMA reaches out to you, right? And they're like, hey, you've got a critical bid and we want to assess, we want to look at you. And they give you your 90 day notice and they show up. And they can see that, you know, it's year two. Your SSP has not been updated and you check the box saying you were. You haven't reviewed any of your stuff. They look at the RBAC database and can tell that you've adjusted it very quickly
[00:07:53] within that timeframe when Dibcac is showing up. They can see all the sins that have happened during that timeframe. And the question is, what are they going to do? What is Dibcac going to do about that? Are they going to throw their head back and laugh? Or are you going to be, you know, having something more serious happen to you? Because the whole CMMC program has been lined up to provide all the necessary evidence in the test stations. You're checking those boxes saying, I promise I'm not lying. I am doing what I say I'm going to do.
[00:08:23] And then when DCMA comes back and audits you, possibly in between your three-year assessments, that could be a real problem. So don't just fall asleep at the wheel. These maintenance activities really should be paid attention. And as an MSP, if you're not taking this seriously when you're supporting the compliance for your clients, shame on you. Like it is your response. They're paying you money to maintain that. Now, if they fall asleep on their part and they're not doing it
[00:08:52] and you're trying and you're begging them to do it, that's on them. But if they're paying you money, you better be doing what you're supposed to be doing. You're not paying them to do their job. They're paying you to do yours. So at a minimum, make sure you're doing yours. Yeah. And that brings up a good point too of, you know, you said that the MSP is supposed to, you know, potentially do some of this or maybe they're responsible. They wrote on the customer responsibility matrix, you know, during the CMMC level two
[00:09:22] assessment readiness and went through the whole C3PAO assessment with you, speaking to the controls that they do. Now, what do they do after the assessment is done? They handle those controls still, right? It's written on the customer responsibility matrix. But I, you know, I have met a few MSPs also that are like, how do we do this maintenance thing? Like, we're just trying to get them ready. You know, what do we do with that? It's not everybody has fully thought it through
[00:09:50] or has gone through that yet because this is still new. And MSPs, honestly, I mean, we just talked to Matt Travis about this, but MSPs do not have a lot of direction when it comes to this in the ecosystem, especially now. So we're trying to figure that out. It's very likely that the MSP that you're working with is trying to help guide you through. It doesn't really know what to do with the maintenance piece of it because they've never done it. Totally likely. And it doesn't mean that there are a horrible MSP, but you need to know what you're getting yourselves into. Or if you're the MSP,
[00:10:19] you need to speak to that with your client so that they know what you are and what you can do and what you can't do. Do not just finish this whole assessment and then just throw everything to your client and say, good luck. And then you leave and that's it, you know? And if you do that, like, what does the client do? Like, what does that OSC do? They're stuck trying to figure out how to do all this now by themselves. So it's huge. It's easy to be an afterthought because it's after the assessment, you know?
[00:10:49] So let's talk about that. What is your approach specifically going into, you know, we talk about our checklist, our maintenance checklist, using the assessment objective level. We look, we broke that down and saw, like, what maintenance components are needed for this? You know, so do you want to speak to that and the difficulties of, like, maybe making that and what you learned from it, positives or negatives? Yeah, so there's a smart play, in my opinion, that you do here as a maintenance service provider.
[00:11:18] Now, if you're an OSC, you may not have these capabilities or abilities to do it, but if you're an MSP, you definitely should and have these. You're going to have some type of PSA or ticketing or some type of automation system that you're going to have. You should be able to create all of these maintenance activities for your clients in advance. So you sit down, you create the list of what you're going to do monthly, what you're going to do quarterly, what you're going to do biannually and annually, right? So you write those all down, you create those tickets, then you create all the tasks
[00:11:48] that are supposed to happen in each of those activities. What type of evidence is going to be created? What additional validation? Oh, you know, also there are certain activities that are going to happen continually. For example, alerts. Alerts might come in, so create a task process that you're going to do for alerts. One of those could be, guess what? Updated. That is a requirement in one of the controls. So as you guys are doing the alert management, you can be tackling some of those controls literally as it's happening,
[00:12:17] which is a great thing, right? So those are all great evidences you can point. So there's a lot of stuff that you can do to help yourself out. Now, as an OSC, you might not have a ticketing system or something where you can do that. There's lots of things like monday.com or other types of activities or systems that can create some schedules or activities that you can do. They can do it. You can do calendar type things. You can just do an Excel spreadsheet and have those maintenance activities done. There's lots of ways that you could try to have those types of documented activity. Now, if you're using a cloud solution, obviously you don't want
[00:12:47] to save that data in there, but you can use it to help you track some of those things because if you start saving the types of data, you could be walking in some possible issues that you got to worry about, like if you're taking screenshots of stuff, like what is it? And you got to think about whether it's FedRAMP and whether it would need to be. That's a completely different conversation and it might not be. But the point is it's just something to think about when you're tracking those types of activities. You want to think about where that data is being saved and how you're managing it.
[00:13:17] And so that's the way that I would do it. Let's talk more specifics too and some examples that you feel like would be good for, I mean, like if you were starting off, you know, doing this, what you would want to hear. So for me, the first one that is probably one of the biggest challenges for a managed service provider or anyone that's having to do with this is the patching and vulnerability because they work hand in hand, right? So let's pretend that you're using just the Microsoft stack. You're not using some type of vulnerability management solution
[00:13:47] like Qualys or some other type of, you know, Nessus or some other type of scanning vulnerability system. Let's say you're just using the vanilla Defender from Microsoft. It's going to have, Defender's going to have the capability of looking all of the systems that you have in there. So let's say you have just 20 workstations that are joined the tenant. It's going to tell you, here's the vulnerabilities I see, but you could have Intune pushing the patches. Now, if you're sitting there and you're like, I'm going to have to, every vulnerability, I'm going to track it down and fix, that's not efficient
[00:14:16] because chances are the patching process could solve it automatically without any effort from you. So you've got to give the automation time for it to work. So what do you do? So you need to think about a strategy and plan that at least monthly or whatever your risk appetite is, you want to look at, okay, what isn't getting caught in the normal patching process? Is the person just not turning their computer on at all? Are they on a sabbatical
[00:14:45] for two months and you didn't know about it? And that machine is slowly falling out of compliance because those vulnerabilities are going to show up and Defender's going to tell you or whatever your scanning capabilities is going to be like, I haven't seen these machines in a while, right? So you're going to have to think about that. So at least once a month you want to be able to see what's falling off the table and how, and those are the service tickets or activities you want to then focus on to get re-in alignment. If you have 200 computers, that could be a real task because in the past,
[00:15:15] organizations that have these CMMC requirements almost are good enough was okay, but that's not how it is now. The government gets to set what those timeframes are. When you get to Rev3, they have specific timeframes that they're, and it doesn't matter what that organization feels like their risk appetite is. The government's setting those as operational defined values. So once we hit Rev3, you better start thinking about what they have defined on those timeframes. So start thinking about how you can start changing your operational processes
[00:15:44] to start be aligning with what's going to be coming down the pipe once Rev3 in a year or two starts dropping. That would be like the first monthly activity that you need to really think about. And it's going to take possibly a day or two of time depending on the size of the devices of how much activity and time you have to look at and make sure that they're being patched and updated and they're back into the acceptable timeframes. Because the way the patching works is that they typically have it defined by like critical, high, medium, and like low, right?
[00:16:12] And so they want to make sure that you're hitting your timeframes and maybe criticals have to be done within 30 days, right? And so maybe it's a Google issue or Adobe, like they want to see those critical updates are being addressed right away. And then the other ones you have some more timeframe. So that would be the first one. That's something that I just want to point out. Yes, that is going to take time. But I think another thing to point out, it's going to take knowledge. Right. Because the person
[00:16:42] that's going to do that is going to have to understand that. So it's coming from somebody who is an OSC. If you're listening to this and you're going through your level two preparation, you're going to go through your C3PAO level two assessment, who's going to do this in your organization afterwards? Who can handle this? If you don't have an MSP, let's say an RPO or a consultant of some kind is helping you get ready. Most likely, some of them do,
[00:17:11] but most likely that person is not going to do these types of activities afterwards. So who is going to be owning this? Who has that knowledge? I'm just making sure that while they're listening to you with what you're saying, that they're thinking about it from that perspective. Not everybody has an IT provider, that mom and pop shop of 10 people. I get it. You're just 10 people, but unfortunately, you still have to do this, this exact same thing. It's just not as big. You know, you're not looking at 100 computers,
[00:17:39] you're not looking at 100 users, but you're still looking at that 10, you know? So they still have to do it. So I just wanted to point that out. You're still looking at that deadline. Yeah, you're still looking at the same deadline. Of the 30, 60, 90, 120 days of timeframe. And does it matter? Hey, I'm small. I don't matter. So I should be able to accept this risk. Nope. The risk has already been factored in in the way that 800-171 was written. So it's baked in. You don't get to make that decision. The DOD does and NIST
[00:18:09] and how they wrote that. And that's just how it is. You've got to get in that boat and start rowing. So that's how that works. And the other aspect too is you might need to think about, okay, is there a product that I might need to purchase to help me make this an easier process? Maybe you don't want to use Defender. Maybe you're a service provider and you've got to think about how you're going to do this at scale, right? Maybe you want to have 20 or 30 clients. How are you going to do that scale? You're going to just hop into everybody's machine and do it through Defender for theirs individually. That's a lot of bodies
[00:18:38] you're going to have to be throwing at to be figuring out how you want to do this at some type of scale. So you just really need to start thinking about that as an MSP about how these maintenance activities as you start to have more clients can crush you. So you want to think about that. Yeah, I love it. The other thing that you want to think about is what cadence do you want to do? We typically do it on a monthly basis to make sure that the systems are reporting back to your SIM tool. So you want to make sure that your data feeds are coming back
[00:19:07] into your system again. And so at least monthly, in my opinion, you would want to be able to make sure that all of my systems are reporting. You should be able to detect or pick up that a workstation has not checked in in a month or two because that means that you're not, are they on a sabbatical or has something gone wrong with the analytics, you know, the agent that's sending it to your SIM tool? Has it checked out and you're not getting it? Was that intentional or was it by accident? You know, those are types of things. It could be,
[00:19:37] you also want to check, like, maybe you have your firewall, right, that in, because you have a physical location and that firewall is going to Sentinel or whatever your cloud-based SIM tool is. Has it checked in this month at all to send the logs? If the answer's no and it takes you four months to see that, that's a lot of data you just lost. And I'm not sure if an assessor would be cool about that. So you've got to think about those types
[00:20:06] of maintenance activities, like making sure that data is flowing into your management stuff. And then you've got to think about sanitization. What I mean by that is that some type of cadence, probably monthly, you've got to think about how you're going to get rid of your paper, thumb drives, you know, computers being wiped, stuff like that. Those are things a lot of times people don't really think about. This is not something you think of after an assessment because you notice that sometimes, you know, you're hearing these things that Bobby is saying.
[00:20:36] You have to write to these things of how you do it, what you do in the SSP. So what if you write yourselves into a very, very tight corner, very, very uncomfortable corner where you're like, yeah, so we are going to, anytime we're done using a machine, we're going to smash it with a hammer 15 times, run it over with a semi truck, throw it in a fire, do a little ritual over it, and then tuck it in the sea. And you say that you do that every time. Well,
[00:21:07] guess what? You're going to have to figure out how you do that every time. And you're probably going to have some OSHA violations, some EPA violations, there's all kinds of, yeah. Yeah, but just, you know, that's an extreme stupid example, but what I'm trying to say is do not paint yourself in a corner with the maintenance component of it. You've talked about the ODBs of, you know, there's some corners that were already painted for you, that were made for you, that you're going to have to sit in when it comes to
[00:21:36] just the Department of Defense or the Department of War made for you, but also you could very much overcorrect in certain scenarios. So be careful with that. I agree. Some other monthly activities you probably want to pay attention to, visitor logs, who's come and gone, that you're going to store it, save it, are you tracking it, do you want to see that? Some other ones that are good to track is going to be, this one is sinister, your allow listing. So you're going to have
[00:22:06] application allow listing that is going to possibly be catching stuff. And in theory, new software and other components should only add new items that you're going to have to add to your allow list. What do I mean by that? So in the CM domain, there is a requirement that says that you have to have some type of application that is policing the ability of apps to function and run unless it's on your allow list. Okay?
[00:22:35] And so the way that you create that list is, you know, it could be like ThreatLocker, for example, or the Airlock, you know, some other type of application allow listing program to do that. But monthly, you're going to have to continually check. You're like, wait a minute, Bobby, you know, that should only happen when you're going to do a change. Well, there's this little thing that we were just talking about, about maintenance and updates are going to happen and things are going to do and new DLLs are going to happen and that crap just causes chaos for those types of apps
[00:23:05] all the time. So each month, you're going to have to get in there and poke and prod and make sure that that thing's behaving the way it's supposed to so that things aren't breaking, that you're going to have to make sure the patches are behaving the way. So there's some type of maintenance process you're probably going to have to go through to double check that. It can also be a great way for you to identify apps that somehow got on there that they shouldn't have been and now you're like, okay, how did I get there? I see that my application listing blocked it. We need to have a talk, right?
[00:23:35] Yeah, spoiler alert. Technology sometimes does crazy things and stupid things or things you would not expect and so no matter if you put a rule for something or you just checked it a few days ago or, you know, why would this Windows update all of a sudden download these random things onto my device without me knowing? Well, it happens. No matter how stupid you might think it is, it still can happen and so you have
[00:24:04] to be able to pay attention to that and maintain it so what's the cadence that you're going to do? How are you going to check that? Who's going to check it? All goes back to it. So some quarterly ones to think about is public-facing activities so you're posting on social media, right? Your website, here we just won this new bid. Look at this F-35 design that we did for them. You're like, wait, what? This is a picture of all of our team next to the build design. To the build design that I have that is, you know, controlled,
[00:24:34] unclassified information. So there has to be some type of review process of when you're posting information on publicly and there has to be a review process where you at least annually, quarterly, biannually. Well, depending on the cadence, this might be something that you might want to do quarterly because you might be very, very active. Your organization may constantly be pushing. Maybe you only do it once a year because you hardly ever do any posts. Either way, you're going to have to do it at least once. You want to think about in your quarterly review your cab process, right? So your change control,
[00:25:04] you at least want to probably do that at least quarterly to be able to make sure that your cab is getting together. I want to point out this is the biggest punch in the face a lot of the time to organizations that I talk about of the change control process and how it's a song. You can't always get what you want, right? It's really unfortunate when a person in the company is used to having just beautiful
[00:25:34] admin access or some type of access where they can just do whatever they want, whenever they want, however they want. And then the change requests come in, the change approval process comes in, and you realize, hold on a second, I can't do this anymore and I have to have a board that checks out these things, that reviews them and this is, no matter how much you love your MSP, no matter how much you love your consultant, they cannot just wash this away
[00:26:03] from you. You are still the company. So you can't get away from this one. You gotta do it. Yeah. Gotta do it. And when I first started doing it like cab, I was like, I hate this. But now I've grown to appreciate it. It really helps the organization. I'm gonna cut that for Adam. He's gonna cry that you said that. But yeah, it's helpful, I feel like. Yeah. So another biannual one that would be good and you might even want to do it quarterly is just reviewing. Yeah.
[00:26:32] And some organizations would probably even do these activities monthly. Would be reviewing your hardware inventory and your authorized user list just to make sure they're accurate. You could do it not as often as quarterly. It just depends on the size of the organization, the maturity of your automation and how you do your validation. But at least you have to be thinking about it because it's gonna drift. The users that are authorized in the system versus your list, as much as you try, the human factor just freaking finds a way. Kind of like, what is it? Jurassic Park life finds a way. Like,
[00:27:02] our humanity will find a way to frick it up. We just, we do. We're just really great at screwing up systems. You know, you have that nice cabling system that you paid all this money to all the cables come from the switch and you come back in two months and that stuff looks like spaghetti. You know, just, yeah. So, you want to think about that. That's like, for me, my mom experience personally, is just no matter how many times I clean the playroom every day, the next day
[00:27:31] it's an absolute tornado. You know, I mean, I try to clean it, try to keep it clean, put away the toys. It don't matter. It doesn't matter. And I try to clean those toys, you know, because kids put stuff in their mouths. I put it back. I clean them off so that nobody gets sick. Sure enough, chucks it in their nose, throws it in their mouth. They get sick anyway. Doesn't matter. No matter how much you try. Embrace the suck. Embrace the suck.
[00:28:00] That's right. Um, rights, permissions, permissions on folders, SharePoint libraries. You're going to check those monthly, quarterly? Yes. I don't know if you're aware about SharePoint, but that junk gets messy. It can be. The permission rights of that can get so messy so fast. Um, yeah, you can't just, uh, go like, okay, I did it. I set up my SharePoint site and I walk away and then it's, that's how it is. Somebody with a click of a button
[00:28:28] could change dramatically the access to a folder, a site itself, you know, a user access. Yeah, that crap can get messy real fast. So your baselines of your systems, you want to check those, your security baselines of how you do it, your baseline build processes, you want to check those at least, uh, annually if not quarterly or biannually. That is a requirement. That's an ODB, right, for, um, Rev3 even too. I can't remember, but it's definitely something you're going to have to do at least annually.
[00:28:58] Yeah. Um, yeah. So you've got to look at those types of things. Uh, also at least annually you're going to have to look at all your policies and your procedures to make sure that you feel like they are still adequate and sufficient. Uh, your system security plan, um, at least needs to get a yearly date stamp that's like, I reviewed it, everything looks good, put your date, time, name, execute, the authorized person, then you can maybe make a tweak or two, and then if you get assessed
[00:29:27] or they look at it, you're like, oh yeah, I can see he's evolved his SSP at least yearly and looked at stuff and made some changes. Uh, and that type of stuff you want to make sure is happening. Now for large organizations, they're probably making changes constantly. We, as an organization, as an MSP, like weekly, we're changing some of the things or processes or tweaks that we're doing and how we're doing it. So it's constantly getting updated and evolved as we get to do it. It's a very challenging process for us, but every organization is different in how they do that. Um,
[00:29:57] so you got to make sure you're doing those controls and those reviews, tabletop exercises, your risk review, checking your risk register, those have to be at least done annually, your training, right? Your people that are being trained, you got to look and make sure that those are happening because if you're not doing your training, then your team's going to fall behind and that's one that's kind of quiet, like quiet quitting. Is that what, is that what they're quiet? I mean, like that, that can really get you, you know, where you're not doing your training. Well, and it's not even, it could get you on reoccurring training
[00:30:27] for the team that you have, but I'm sure you're, you're onboarding somebody, you're, you're hiring people. And so, is it getting done to the new people as well as the reoccurring, um, you know, regular, um, yearly training that you get with your staff that's already onboarded, but, but rather just the continuous onboarding. If you're onboarding, you know, five people a month, are all of those people continuously getting that training? What if somebody messes up? What if somebody misses the bow? They, you know,
[00:30:57] you send them a link, but they never do it. Like, who's keeping track of that and how is that working? Yeah, those are some good examples. Hopefully that's helpful for people. I mean, I think it was. And, and I feel like, you know, I have to say just the grand scheme of things. When you're hearing this, I'm sure as an MSP, if you're trying to do this at scale, you're already seeing, oh, do you see how hard this is? I feel like it would be wrong of me to not share. You can already start seeing this overarching thing of if you're trying to do this at scale as an MSP,
[00:31:27] how these simple, or, I mean, in my opinion, it wouldn't be simple, but these tasks that you just start to just list off and you're like, oh yeah, I got to remember to do that. Oh yeah, I got to do that. Well, if you're in charge of it for a company or multiple companies, that's multiple tasks. That's multiple things you have to do quarterly. That's multiple things you have to do biannually. You notice that it starts to add up. It starts to add up and so you just have to be prepared for that. So, you know, that's something that, Bobby, I'm sure you can speak to
[00:31:56] with having to think about not only having to do that for ourselves, but also for you and that type of cadence as well. So, yeah. That's the quiet challenge I think that MSPs face is when you start onboarding more and more of the clients. The responsibilities of those maintenance activities, if you're doing 60 to 70% of those for the client, which most MSPs, if they're really going full at it, could probably do. Like, they could absorb those responsibilities but not saying that they want to or they, but like, they're capable of doing it, right?
[00:32:27] It's within their possibility of doing. They may put a wall there and say, I'm not going to do that. I'm going to let the organization that we're supporting, they'll be responsible for that. And that's where that shared responsibility between them has to be carved out. But, that can bury you if you're not thinking about it as you're starting to scale. That's why we typically say MSPs need to try to understand what boat they're going to be in. Are we going to support a few clients? Are we going to try to build something that's going to scale and support multiple people?
[00:32:56] And both are fine, but you can't be one and the other. Like, you've got to really think about that. So, as you're coming up with your solution, if you're doing it not at scale, then maybe you could just do Defender for them and some other individual components and support them getting where they're not and you're great. And it's, you know, occasional maintenance activities you're trying to do and that'd be fine. But if you're doing 20, you're doing 30, you're going to have to think about something about how you're going to attack these
[00:33:26] because you can't just keep throwing infinite bodies at it. And that's something to think about when you're also picking MSPs. And you want to know what organization are you working with? Are they going to be just supporting a few CMMC clients or are they going to be trying to do this at scale? That's a good question if you're trying to pick one to ask. That's a great, yeah, that's a great question. I mean, yeah, are you just a one-off or is it the scalable process that they do regularly? So, yeah, I love that. Well,
[00:33:55] I hope this was beneficial to you guys. OSC is listening to this, also MSP is listening to this of just the perspective of, hey guys, this is not just the future, this is the now. You have to prepare for this. It's not pretend. It's not something that, oh yeah, we'll figure that out later. It's very real. It's a challenge and it can, it can be quite difficult for you. But if you prepare, it can be a simplistic, you know, process that your team continues to do and monitors. So,
[00:34:25] just make sure to think about this, whether you're somebody who is preparing for an assessment right now or, you know, you haven't started your journey yet, that's a great opportunity to write your SSP in such a way that you're thinking about it. So, if you have any questions or thoughts or ideas, please make sure to comment them below or message us on LinkedIn. We'd love to talk with you about it. Also, too, every Thursday we post a new video, so please make sure to tune in every Thursday for a new episode. We hope you guys
[00:34:54] enjoyed today's episode about maintenance. Remember, guys, as always, to keep on climbing. We'll see you next week. Bye.

