The 10 CMMC Questions Defense Suppliers Ask Us Most: A Self-Check for Your Compliance Program
CMMC Compliance GuideOctober 02, 2026
73
00:51:5535.68 MB

The 10 CMMC Questions Defense Suppliers Ask Us Most: A Self-Check for Your Compliance Program

Submit any questions you would like answered on the podcast! These are the 10 questions Stacey and Brooke hear more than any other from defense suppliers, and most companies get at least half of them wrong without realizing it. If you've ever wondered whether your setup would actually hold up to a close look, this episode is your self-check. In this episode: Do you actually need to worry about CMMC right now, with the certification requirement on contracts still paused?How to actually figure ...

Submit any questions you would like answered on the podcast!

These are the 10 questions Stacey and Brooke hear more than any other from defense suppliers, and most companies get at least half of them wrong without realizing it. If you've ever wondered whether your setup would actually hold up to a close look, this episode is your self-check.

In this episode:

  • Do you actually need to worry about CMMC right now, with the certification requirement on contracts still paused?
  • How to actually figure out whether you're Level 1 or Level 2 (and why you should push back on vague answers about what counts as CUI)
  • What "compliant" actually looks like day to day, not just the technical controls, but the ongoing documentation and change management behind them
  • Why "our IT provider handles all of it" is rarely true, and the specific questions to ask them (CRM/SRM, CCP, RP, CCA credentials)
  • Why companies with mature cybersecurity programs often still fail on documentation, even when their technical controls are solid
  • The biggest real-world mistakes: shared shop-floor logins that fail CUI access requirements, misunderstanding what the controls actually mean, and manually "reviewing logs" instead of using a SIEM
  • What an assessor actually checks first (hint: it's your scope definition, not your tools)
  • Why buying a compliance tool or downloading a template package doesn't mean you're done, and what you actually have to prove objective by objective
  • How to implement all of this without grinding operations to a halt
  • Where most companies actually land when they get an honest gap assessment

Welcome And What We Cover

Stacey

Hey there. Welcome to the CMMC Compliance Guide Podcast. I'm Stacy.

Brooke

And I'm Brooke.

Stacey

From Justice IT Consulting, where we help businesses like yours navigate CMMC and NIST 800 171 compliance. We're hired guns getting companies fast tracked to compliance, but today we're here to give you all the secrets for free. So if you want to tackle it yourself, you're equipped to do so. Let's dive into today's episode and keep your business on track. Today we're covering the 10 questions we hear from defense suppliers more than any other. And most companies get at least half of these wrong without realizing it. We're talking about shared shop floor logins that fail an assessment on the spot, template policies that describe a company that doesn't actually exist, and the one documentation gap that trips up more shops than any missing piece of technology ever does. If you've ever wondered whether your setup would actually hold up if someone looked closely, this episode is your self-check. So, Brooke, let's start with the question everyone asks

Do You Need CMMC Right Now

Stacey

first. Do we actually need to worry about CMMC right now?

Brooke

Well, yes. The answer is yes you do. That's a short answer. We can just leave it there, or uh we can explain it a little bit. So uh yes you do. Uh the SI the uh excuse me, the DOW, uh Department of War, uh did announce a pause for CMMC that's a pause uh on certifications being required on contracts. So they they implemented that pause, um a 60-day pause, which is uh uh essentially open-ended really. Uh they actually I guess they announced a 60-day um uh that they were gonna look into it, right? So um I wouldn't expect anything time anything anytime soon, necessarily. Uh but uh so while you might not have to get a certification uh to get a contract now, uh at at this moment right now, um uh this still means you they specifically said you have to be compliant, right? You have to be NIST 800-171 and CMMC level two compliant. Uh so you still have the compliance to meet, uh just not the certification on the contract. Uh that doesn't mean that C through PAOs are not doing assessments, they still are. In fact, we still have uh a few clients in the pipeline that have kept their uh certifications scheduled. Um and we've been through two since uh since the uh since the PAS two with clients. So um so the certifications are still going on and they still mean something because uh that certification, when you get it uh for the government or for a prime, that means your risk level instead of up here at self-attested, say, you know, yes, I did good, that uh they uh the risk level is a lot lower because a third party came in and validated that compliance, right? Uh so that's what the third that's what the uh certifications uh do for people right now. Um But yes, you do have to worry about CMMC, you have to worry about compliance, just not necessarily a certification on a contract. And one more thing, really, to to think about uh as as you move forward, right? There's I guess there's a couple things rolled into one, but uh one is that uh the there's not been any fresh rulemaking uh for CMMC, right? No more uh 32 CFRs or 48 CFRs or anything else that actually define it and put it into effect in law uh in those uh that Code of Federal Regulations. Um to if they don't do anything by 20 November 10th, 2028, this just switches back on, right? And that's not meant to be a scare tactic, it that's just what the what it does. They're gonna address it before then. Well, I would guess they're gonna guess they're gonna address it before then. Uh so what I kind of expect is for them to announce some sort of new rulemaking and uh and that at some point and that uh they're gonna start going through that process. They could they could announce that sometime la next year, uh you know, middle of next year or something, and they could do the proposed rule and get a uh do the final rule and get it in place before 2028 to do whatever it is they want to do. Uh the second part of that is that uh as they do that, they have signaled uh quite a bit that they want to um one, make things equal with the federal government, with the rest of the federal government, and uh the FARCOI rule takes into consideration NIST 8171 revision three. The Department of War for CMMC, for now, they were trying to stick to revision two uh so we can get through all this, right? And then and then bother with implementing revision three, because it is substantially different as far as the amount of work and everything you have to put in it. Uh so I would expect them to probably to work in revision three and their whatever changes they're gonna make. Don't really know, uh, but that would make sense. And uh they have there's been a few things that they've done that that made it look like they that's what they're they intend to do, right? Um they also said they want to reduce burden and everything else, but they've been giving mixed signals. They want to reduce the cost, but uh but yet they promote the you know uh brilliant at the basics, which cover things that you don't have to cover with uh CMMC right now. So yeah, you know, whatever. Uh we'll see, I guess. But uh anyway, expect some of those changes to be coming. Uh they just may not come before Christmas. So they may not announce it before Christmas. They, you know, all they have to do is say, hey, by the way, we're not gonna leave you a limbo forever. This is the path we're going down, right? Uh so they may do that at some point. They may not. I don't really don't know. They may well they may wait until after the elections. You know? That may that may be a plan. So uh but the long and the short of it is, you still have to comply with CMMC and you still uh you still have to have that compliance

Level One Versus Level Two

Brooke

in place.

Stacey

Aaron Powell Another question we hear often is how does a company actually know whether they're level one or level two?

Brooke

Aaron Powell Well, that's a good question. And generally it boils down to did your prime or did your uh did the government tell you you have to be, right? Uh level two is do you have any of those DFARS clauses on your contracts, right? Uh the DFA DFARS uh 252.204-7012, 7019, 7021, do you have any of those on your contracts, right? And that would be the first thing to look for. The next thing would be when you get whatever it might be that your business is. So if you get drawings or specs, uh something like that, and you know there's compliance there in the mix somewhere, say, hey, is this CUI? And they should answer you and say yes or no, right? And you can say, okay, well, can you market, you know, so I can have it appropriately in my systems. And by the way, don't send it by email again. So uh they should be willing to you know to market uh uh the real world is a lot of times they'll just say, you know what, we just need to be at level two, and this might be CUI. And and I get that. And a lot of people don't want to bite the hand that feeds them, they don't want to push too much. Um but the real answer is that you can push back and you can ask and you should ask because they're putting a big burden on you for you to have to comply, and you may or may not have to meet that compliance. And you the point is what part of that information is CUI? You know, you don't you don't know what you need to protect. So you end up just protecting everything, right? Uh so um so the CUI thing is uh is a big thing, and you should ask about that. Uh level one is for FCI. Uh excuse me, CUI is for level two, of course. Um if I didn't say that. So uh level one is gonna be FCI, federal contract information. And federal contract information is uh any information about that contract that is not public, right? So um I always tell folks if you have to log in to see the information that's not available without logging in, uh then that's probably gonna be FCI, right? And also level one, they you that should be part of the contract. You uh for for this contract, you have to be at level one. Uh and we're seeing more and more of that. There are more and more people contacting us for uh for level one help, right? Because uh we always as we always say, uh level one's not uh not much, but it's the it's uh level one is a lot easier than level two, but it's not nothing, right? Uh it's certainly not nothing. Uh if you've not even started down that road, there's a little bit of a bar to understanding what in the world uh level one is. A lot of people just phone that in and say, yeah, the rest of our network is level one and we have our level two enclave, right? Uh well is the rest of your uh network really level one. Do you really limit access uh to authorized devices? How do you do that, right? So uh that's one of that's one of those things that uh that catches people. So um but anyway, level one uh is there is there are things you have to do for level one. Um and it is worth reading through it and understanding what if you say yes, we're level one uh compliant, uh it's worth reading through and making sure you don't get caught with your proverbial pants down.

What Compliance Looks Like Daily

Stacey

All right, let's talk about what compliant actually means in practice. Can you walk us through what that actually looks like?

Brooke

Uh yeah, sure. I mean, we could spend hours or days on this discussing all the particulars, uh, but um it's not just about level one or level two, uh it's not just about the technical pieces. Because you can put you know an antivirus or uh you know endpoint management on in in place, you can put a sim in place, you can put a a directory structure in place, Active Directory Intra, or, you know, name your tool. Um you can put those in place and say, you know, and and other things and say, yep, we've got it. All of our technical controls are taken care of, and and we're good, except that you're not. So uh the number one thing is uh NIST 800171 and CMMC are all about ongoing management of that environment. They're not about uh putting it in place and forgetting about it. It'd be nice if it was, and it'd be nice if you could do that meaningfully, but that's I mean, we're we're a managed service provider, we're in IT, and from we've we know and understand that you can't just put something in place and say it's good and not worry about it. I mean, I'll just take backups for an example, and this is not necessarily uh anything you have to worry about. It is something you have to worry about, but not particularly for CMMC. But you know, I can't tell you the number of times we've gone into a place and they say, you know, they've called us, we need help, you know. Uh great, uh we'll see what we can do. You know, yeah, do you have a backup? Yes, I have a backup. All right, let's take a look at it. Do you realize your backup has not been uh not been working for, you know, it's been throwing errors for the past eight months? And they're like, well, no. You know, when they put it in place, it worked. Yeah. But there's some care and feeding that go into that to making sure that it works. So, you know, uh a backup that's not tested on a regular basis, you might as well just consider it no backup at all. And the same thing with all these other controls, right? Um whether it be endpoint protection or antivirus, however you want to phrase that. Uh antivirus is kind of a old school term uh these days, but uh endpoint protection, uh whether it's uh application whitelisting, whether it's uh firewall rules, whatever it is, all these things take ongoing management, you know. Um somebody can't uh you know somebody can't run Napster and they open a ticket. Is Latin is Napster still around these days?

Stacey

I'm not sure if people still use it, but still good records.

Brooke

You know, maybe uh maybe YouTube, you know, music or something. Anyway. Um somebody can't run their favorite music program and they open a ticket and say, hey, I need uh you know I need Spotify. There we go. There's one. I need Spotify to work because it doesn't work. And and so you can go to the you know the authorizing person, the who uh the approver and say, Hey, Joe Blow here wants to use Napster, or or excuse me, I said Spotify. So wants to use Spotify and and uh most likely you're gonna get a no, we're not gonna enable that. But you say they say, okay, we approve that, we're gonna let we're gonna let him have Spotify. So you go make that change. Well, part of that change is that you have to now document that, you know. Um and you have to you have to document it and and the configurations and everything else. It all has to be documented. You can't just make the change and forget about it, right? Um there's also all change management procedures that have to be followed, right? Uh so all this has to happen somehow. Somehow it needs to get documented. Um so you have to have proof of that so you can say, yeah, we we made this change, and here's here's where we documented it at. Um you know, same thing with uh, you know, antivirus or uh a bad thing that usually happens, or not a bad thing usually happens, but one of the common things that happens is uh you know somebody's testing trying to figure out why a program doesn't work, and uh so they disable the firewall uh to see if it works, and lo and behold, it works. You know, well now what you really need to do is go back and re-enable the firewall and then figure out what's blocking it, and then figure out what you have to open and then and then uh take care of that. But you still have to document that. You still have to open that one part, but a lot of times people either forget to uh forget to enable the firewall again, or if they open something, open up a port just testing, they forget to close that port, right? And it's an entryway into your network or onto the computer or whatever it may be. Uh so those things need to be uh you need to scan for those. You need to-that's ongoing management, right? And so all those need ongoing management. Uh all controls need ongoing management and ongoing monitoring. Um the um and that but as I referenced just a minute ago, documentation, everything needs to be documented. Your your um baseline security settings need to be documented, your uh allowed uh your uh authorized software, your authorized devices, your authorized users, those lists have to stay updated, and no, they can't live in Active Directory. No, they can't live in intra. That can be part of it. That's where you can start with it. It's what you can use as a source, but it can't be everything, right? And so um it has to be a list that you produce and show to the CEO or whoever is the authorizing official, this is our software law, uh software list, do you authorize it? And most likely his eyes are going to glaze over and say yes. But um so uh but you have to um you know that's a that's a joke, but so the uh so anyway, the you you have these ongoing documentation, ongoing management things you have to do. So uh the technical controls are just part of it. And those are they're an important part, of course. Uh that's why the the ongoing management monitoring and and uh documentation exist, is to prove that you're that you're still doing all those technical things.

What An IT Provider Can’t Do

Stacey

Aaron Powell So you kind of touched up on this a little bit, but a question that we get a lot is can't our IT provider just handle this all for us? What do you have to say about that?

Brooke

Well, yeah, I mean uh they can the answer is they can help out with it. They can't handle the whole thing. Um, your IT provider may be an all-in-one IT and compliance solution. Um, or they may just handle the IT, the technical part. Um there may be somebody that needs to do all the documentation, but um you know, they also can't authorize. So you you have to be part of that process uh to some degree, you know. Uh it may be just a little bit and you have the IT department do everything for you, um, you know, including the compliance piece. So that would be, you know, not just the technical controls, but that would be all the documentation, monitoring, and everything else. And again, documentation, then proving it, right? Um and that work is not free. So if uh if a uh IT provider shows you a gives you a quote and uh then you say, oh, by the way, I have to be CMMC uh compliant, and do you cover that? Oh yeah, we do compliance services included. I would step back and check and make sure, because it that is a lot of labor to uh to make sure that all the policies are updated, make sure all the cons uh the baseline configuration settings, the essential uh capabilities are listed out correctly, you know, all these things that have to be done, that's that's not a small amount of work. So somebody's got to do it. And some a lot of it is technical, so who's gonna take care of that? Are you gonna work on it with the IT folks, or are you going to uh trust them to do it? And you know, and in that case, uh if you do and they're part they're working on your compliance with you, your actual compliance, not just the security functions, then uh you know how do you know that they that they can do those functions and do them well? Uh well, are they seamlessly level two certified? Uh do they have a uh CRM in place, a customer uh responsibility matrix or a shared responsibility matrix? Preferably a shared responsibility matrix, but because of the federal government everybody calls it a CRM, so um but do you have one uh can they give you one of those and have one of those in place and tell you what they cover and what you're supposed to cover? Um those are all very important questions. Do they have a CCP on staff? Do they have any RPs on staff? You know, CCP is a CMMC certified professional, RP is a registered uh practitioner, and really what I'll tell you is uh the registered practitioner, RP uh designation, it's good to get, but that's like a foot in the No, it's not a foot in the door. That's more like a big toe in the door. So or in the in the pool or however you want to phrase it. Uh so that's just a big toe you're dipping in. Uh when you s go for uh CCP, that's a lot more serious and you you start to really understand uh the controls. CCA, you really, really, really start to understand them. Where you really get the understanding is going through those assessments. And so uh you understand uh what the assessor is looking for, how they view these, you know, all that kind of fun stuff. Because again, I've said this a lot to an IT guy, define might mean one thing, and it might mean uh something else, a lot more inclusive to a uh or extensive to an assessor. Uh identify, you know, list, those things uh you know, mean something different. And again, I'll go back to your authorized user list cannot live inside your Active Directory. It can't be just Active Directory. Do you have an authorized user list? Yeah, it's all the people that are in Active Directory. No, it's not. Well it may be, but you know, it's uh you have to have something that says these are the authorized users, and then you look at Active Directory and you go, oh, yeah, they match. Or all these people are in here. Uh here's some people that are just uh not in the system, but they're um authorized for physical access only, right? Because that's included, right? You have to think about that. We put those, if it makes sense, a lot of times it does for small businesses, we put those on the same list, so we don't have 25 different lists, right? We have one list, it includes authorized users in the system, authorized processes, which are generally user accounts, uh, or they could be um enterprise applications in like intra, uh intra-ID. Uh, you know, we include physical access in that. Do they have physical access or not? Do they have admin access or not? Uh what role are they? We try to put all that in one spreadsheet, and that way it's right there. We can refer to it all right there, and we don't have to jump around between spreadsheets trying to figure all that out. So in any case, you have to be able to have that list that is authorized and then look and compare it. So your IT provider, they can certainly handle a lot of this for you, but not all of it. Um and they can handle the uh a lot of the compliance part for you, uh, but they have to know what they're doing. You can't just hire somebody that says, yeah, we we help you with compliance work, we do HIPAA, PCI, ISO, you know, all these different ones. And you know, when and yeah, we do CMMC too. Do they really or are they just saying, yes, uh, we can give you an A V that is is good? You know? They have to understand CMMC and the controls and what's required in there.

Why Documentation Becomes The Gap

Stacey

Aaron Ross Powell So for those companies that have been doing IT security for a while, how close are they actually to being compliant?

Brooke

You know, those companies that have been really really focusing on cybersecurity and really trying to implement uh all the best things they can, uh they've got a lot of really they probably have a lot of really good things under their belt and and have a good foundation. Uh and even even if they have done a good job documenting things, uh it may not be the right kind of documentation for CMMC and uh NIST 800 171, and it may not be um enough of it, right? So uh you need to look and see, you know, is it adequate and is it s sufficient, you know. So d is it the right kind of documentation that they that you need to cover the control. And I would say that documentation needs to address the controls and the assessment objectives. If that documentation doesn't, and if assessments ever start back up, you know, an assessor comes to look at it, they'll be going, uh all right, well tell me tell me where this is at. I don't understand where you know this is located at in your policy, or I don't understand where this is located at in your procedure, you know, and and um it's kind of all over the place. So it really needs to uh map directly to CMMC uh level one or two and um and be explicit about that. Issues come in when you have to uh it complicates things when you uh have different uh frameworks you have to comply with, but you can still make it work. You can uh you can do the walk between the two, or between the two or three or four, however many however many you need to make uh meet. Um and there's GRC tools to help you do that. There's all sorts of stuff. But to answer your question, uh if you've been serious in cybersecurity and implementing things, making sure you're secure, uh you've probably got a lot of tools, uh a lot of good tools, a lot of good things in place. Maybe even some documentation, but documentation is usually the weak point. Um sometimes those tools don't meet the requirements to. Uh we uh I think we might uh um said something about a minute ago, but if it's a security protection asset, uh something that is providing security for uh a CUI, uh some CUI, um then like a antivirus or endpoint uh protection. Uh if it's cloud managed, you really need to have a CRM. Or if it's externally managed from you, you really need to have a CRM for that, a customer responsibility matrix. Again, to show what you're responsible for and what they're responsible for. Uh if you can't get that for that tool, you're in a lot tougher position for it to uh for it to pass an assessment for sure. Um but you should know and you should understand exactly what they do and exactly what you're supposed

The Biggest Mistakes We See

Brooke

to do.

Stacey

Aaron Powell So a big question um that we have here is what are the biggest mistakes you actually see companies make when it comes to all of this?

Brooke

Aaron Powell That's hard. There's there's a lot of these things that are very common. Uh you know, we deal a lot with uh manufacturing, right? And and construction. Those are those are a a large percent of our of our clients, especially CMMC clients. Uh so one of the one of the things we see typically is a shared account, right? Um shop or shop floor or something like that. Uh all the guys on the shop, they don't really need a computer, but they need to be able to go um, you know, pull up a part and do something with, you know, uh get some specs off it or whatever. So they all just have a shared shop account that they log in with and and access that CUI data. Well, that's a no-go because shared accounts don't uh don't identify an individual person. And so for CUI access, uh you have to have uh you have to identify a particular person, right? So um it has to be Jane Doe, it has to be Joe Blow, it has to be, you know, whoever it is, they have to be named and they have to log in to see that CUI. You can have a shared account, it just can't access CUI. So if it's uh for for clocking in, you know, uh for clocking in when you start making a product now, and when you stop now, you know, uh those sound effects were a we're supposed to be a a clock in and clock out or a stop the clock, stop the start the clock. So in any case, uh you know, uh it can be something like that. But if it if it's to that account is to access that CUI information, it has to be an individual account, not a shared account. Um one of the other things, a common thing we see is is just completely misunderstanding what the controls are about. You know? Um which is understandable again, if you're not really in tune in in compliance and and uh really if you're in tune in compliance, you're really into it then some of the stuff you get, right? But if you're an IT guy and you look at these controls, uh they mean something else to you than they do to somebody else that's used to reading the bureaucratic crap that they put in there, right? Um so uh you know, but once you understand it, once you understand what define means, once you understand what, you know, list or authorize means then um really means to an assessor, right? And so uh and it means in these contexts, then then you start to get it. And you it make that it makes a lot more sense. Uh and really for the NIST 800 171, you can go back and look at the NIST 853 that it's based on, and then there's other documents you can go back and look on and see, uh, you know, uh research those related uh documents to see what that really means. And it usually helps, although that's a lot of reading, I can tell you that. So uh again, a good GRC tool will you know list out what it's uh where the where that comes from, you know, and and um so you can kind of follow that and read up on it that way. Uh you can also, you know, take some training, uh attend events, uh attend the Cyber A B Town Halls, uh you know, all sorts of fun stuff to to get to get some understanding, which I encourage. But it does take some understanding. Uh, you know, one of the other things that uh people t I we we see a lot, um and really in the IT world, you know it's not possible, but uh but people do it in uh do it anyway or say they do it anyway, is reviewing logs. Uh yeah, I look at the logs, I look at them all the time, you know. Okay, you know, what do you look for? Are you a trained security professional? You know, how do you look for things that are uh obf obfuscated, you know? Um and just a real quick story on that to uh to pound this point home that reviewing the logs manually is not a way to to accomplish this. And and the way to accomplish it is through the use of a a SIM, a security information and event manager or monitor, or however you want whatever that is. Uh so you use that tool and it helps uh go through all those uh alerts, all those logs, and sends you alerts and say, hey, this is something you need to look into. There were, you know, 20 failures to log in and then a successful one right after that. So is that an issue? Do you need to look at it? Could be an issue. Could be that Sally is just brain dead and can't remember her password. And maybe brain dead from pulling it all nighter. That's all I mean by that. So um but uh to uh explain uh to give you an anecdote about why reviewing logs manually is is not good. We uh I go to all sorts of conferences, right? And so one of the ones I went to, uh it was Ridea Boom. It's if if you want to, if you're a security, if you're a IT or security person and you want to go to a good conference, Ridea Boom has always been good. They're pretty vendor agnostic. Um they have a lot of vendors there, of course, but you know, uh anyway, it's a it's a pretty good event. Um and they have some on the pre-day stuff, they have some things you can take advantage of. Uh you know, different vendors offer different classes. Ostensibly, yes, they're to sell you the product. But um they uh I don't know what they do at Ridea Boom or they mandate that they have to actually be educational, you know, or whatever. But the ones we've taken uh I've taken part in have been very educational. And one of them was a day in the life of a sock analyst, right? I've been in IT for a couple years now. We'll just say that. So I've been in IT since 1998, which is not forever, but it's it's a few years now. Um so uh and I've I've really leaned into cybersecurity, although I'm not a cybersecurity professional. I don't have a CISSP or anything like that, certification or anything like that. But I've always, you know, when I go to look to problems, I you know, I pour through the logs, uh, you know, all that kind of fun stuff, right? So just like a good IT guy should. Uh so but uh so I consider myself pretty good. I understand cybersecurity, I understand what's not, what doesn't, you know, what's not right, and all that kind of fun stuff. And so I go to this class, and it's uh I think it's most of the day. They split us up in teams. And uh our little team, um they give you a a a uh uh you know an event to go through and figure out what's going on. And uh so you're reading through it, I think you read through it, or maybe they put it up on the screen. I can't remember, but anyway. Yeah, some sort of practice scenario, and you go through it and you try to identify those things that are important to identify to trace trake this, trace this down, right? And so uh we did we did good. We got second place out of all the teams in the room, it's a pretty big room, so quite a few teams or three-person teams or four-person teams. And uh we got second place. Man, I thought I felt really good about that, you know. Um this is awesome. This is great. My clients are in great great hands, right? And uh so then they say, they're explaining it. Congratulations, these teams, one, two, and three, and you know, Young did great. But just so you know, this particular incident was so easy, we never see it in the wild.

Stacey

So that's really humbling.

Brooke

So uh you know, then my uh ego crashed. And I remembered why we hire, you know, uh why we have actual security professionals doing what a security professional should do. And then we have a sim that goes through that and makes alerts. We have a SOC team that looks through that and checks on those alerts and then lets us know if we need to look into it, and then helps us investigate it if we need to, you know, all that kind of fun stuff. The point is, uh you cannot do this man, you cannot look through logs manually and actually be secure and actually do a good job of it. There are tens of thousands of log entries that you would have to make sense of in very quick fashion, especially now with AI, those attacks are getting uh the quality of the attacks are getting better, the quantity of the attacks are getting better. So uh, you know, reviewing the logs manually is just not a good deal. So that we see that a lot though. You know, you have to do log review. Oh, I review those manually. You know, technically, you can do that. Here's some things that you have to be aware of that have to have an ought happen have to happen automatically, but you know, technically you can review them like that, but it's not secure. It won't it it's not gonna work, you know. So we tell people that. Another common problem is, you know, um not starting not starting at the beginning, right? If you don't start at the beginning, then you don't your your system doesn't take a lot of things, your design doesn't take a lot of things into account, right? And by starting at the beginning, I mean look at uh you know, figure out what kind of CU why you think you have CUI, uh what CUI is it, you know, are there any dissemination restrictions? And then what all systems does it touch? Where what is the flow of that CUI through my systems, you know? Uh what computers does it touch, what applications does it touch? What uh what other systems does it touch? What cloud systems does it touch, you know? Uh where does it go in, where does it flow around, and where does it go out? Uh what all does it do? And be honest with yourself, you know, if you if you take a document out of a customer portal and you put it on your server and you say, yeah, but it never touches my my laptop, it's like, well, how does it get to your server? Well, I click it and open it up and put it on my server. Okay, fine. You just processed that you just processed that CUI. Process, store, and transmit CUI. That's what has to be covered. So you got to think about that. You gotta be honest. So that's a that's a big thing, is people not taking into consideration properly, you know, what the flow of CUI is and the fact that CUI is just not just storage, it's processing and transmitting

What Assessors Check First

Brooke

too.

Stacey

Aaron Powell So you had mentioned a little earlier how as a technical person you may think of um certain terminology with CMMC to be one thing, but an assessor might want something completely different.

Brooke

Absolutely.

Stacey

So when an assessor actually walks into your environment, what are they actually looking for first?

Brooke

Well, they're looking first of all, they're looking to see that you have defined the scope well. And that's what we just talked about, right? Is you have to understand what CUI you have, where it comes from, what system it goes through, uh and and so where does that data flow? So what does what does that data flow mean that's in scope? And you have to define that scope well, and you have to say these are CUI assets, these are SPA assets, SP is uh security protection assets, SP assets. Um you have to these are out of scope, these are uh specialized assets, whatever it may be, you have to define that and you have to list that out, right? That's the first thing that they're gonna be looking for. The second thing is, you know, is there enough documentation? You know, uh you know, is your SSP two pages long? I should hope not, for 110 controls. Uh but you know, I guess real more realistically, is your SSP 15 pages long or is it more like 150 pages long, right? Um you know, for what we do, we take uh now we export from our GRC tool and it makes it longer than doing it it makes it longer usually than just doing a Word document because you have a tendency to do a Word document a little different. But um, you know, our our SSP is exported from uh GRC tool, you know, I think they're running in I could be wrong, I haven't looked at the page count necessarily in a while, but I think they're running close to uh 200 pages long or something like that. Um but uh you know 150 to 300 page SSP, you know, is not a bad deal. Uh you know, you may take and refer to where your network diagram is or something like that, and not necessarily paste it all in, because you know, a little bitty paste it in network diagram in your Word document, if you've got more than about five devices, you're gonna be going, you know, hey, I I can't read that. You know? So uh it's not really gonna do any good. Um but you do have to explain your boundary. You know, you have to list your uh your control, uh how you implemented a control, sum control summary, uh and really you need to be you need to have your assessment objective statements. You need to have statements for each of the assessment objectives. So uh they want to see that you have all that, right? And they want to see that you have all your policies you need to have. They want to see that you have some procedures and plans in there. They want to see that you have um your uh the appropriate lists, at least uh uh a authorized user list, authorized device list, uh authorized software list, you know, things like that. They want to see those things, that you have those, first of all. And you know, in that SSP, um you know, when uh you know, when we very first started in this, you know, you want to you don't want to write your policies too tight. You don't want to write your SSP too tight to lock you into anything, right? You want to give yourself some latitude. And uh so you gotta and and that's fine. You can do that to some degree, but what you want to stay away from is basically restating what the control says. Yes, we have an authorized user list. Okay, great. Well, where is it? What you know, where is it located at? What's it called, you know? Uh all that kind of fun stuff. So you you've got to call those things out. You've got your SSP as your story about how you are protecting and how you're implementing all this stuff, right? So it's gotta have it's gotta have those details in it. Um the policies, you know, keep the pol keep the policies, they have to address all the controls they need to address, all the assessment objectives they need to address. They really do. And they they have to have some meat in there. But you can keep those uh a little bit more generic and say the, you know, the authorized user list will be kept in our GRC tool, or you know, something like that. And you don't have to say what pr what GRC tool it is. You don't have to, you know, that's probably a bad example, uh, but uh the point is that SSB has to really tell your story. You can't just simply restate in a different in different words what the control says, uh which is what a lot of people do. Uh you also can't take somebody's policies that you've bought and those are called templates, right? You can't take those templates or examples and then just use them as your own and replace your company name. That doesn't work unless you just happen to be an ACMA company that does whatever, right? And is exactly what they put in there. But you have to customize those things and

Why Tools And Templates Fail

Brooke

you have to make it your own.

Stacey

Aaron Powell For our recurring listeners, they may know the answer to this question, but for the new listeners out there and those that are just starting CMMC, um can a company just buy a compliance tool or download a template package and be done with CMMC?

Brooke

Aaron Powell I think I jumped ahead on the on the last answer, but uh uh so no uh I mean and be done with CMMC. No, they can't. Uh can you start there? Yeah, you can start there, absolutely. Uh actually, uh let me take that back. Um that can be part of the beginning of the journey where you actually need to start is the actual beginning, and that is making sure you define CMMC and what uh uh discover what CMM C UI.

Stacey

C UI.

Brooke

Uh figure out what CUI you do have, why you ha think you have it, and all that kind of fun stuff. Uh and then you have to uh define your scope and your flow of data, right? So you have to start there, and and it's okay to figure out, holy cow, this CUI goes through everything in our system, and I don't want to do that. It's okay to discover that and then go, we're gonna change it, and this is the way it's gonna be. Uh that's fine to do that, and that's good to do that, uh, because we go through a lot of exercises where we say, you know, it would be easier if you did this, you know, if you did an enclave, which we've talked a lot about. I don't like the word enclave. Uh but uh you know it'd be easier if you created this enclave, right? Or use this as an enclave, whatever it might be. Um you could reduce your scope here, and you know, these would be uh, you know, you could make all these things out of scope or however it may be. So um you've got to start there. And then if you want to get some templates or tools, if there's a all-in-one product that you use, um, you know, you might use their uh and they provide templates, you might use their templates uh as a way to get started, you know. Um but what I would tell you is that a lot of those templates don't trust them because a lot of them are just not good, right? A lot of them a lot of them mix up policy and plan and procedure all in one document. And while that's okay, you can do that. It just kind of clutters things up and makes your policy a lot longer than it needs to be. Uh if you keep your procedures outside of your uh outside of your policies and your plans outside of your policies, um it makes things a lot cleaner and a lot easier. So uh that's that's the kind of thing I would suggest. I would suggest um, you know, you just you just gotta go through and really customize it for your environment. Because chances are that one tool where you got those uh where you got those templates from is not the only thing you have in your environment. And generally those templates are written only with their tool in mind. So you just gotta be careful with that. So can they help? Yeah, absolutely they can help. Um is that the first thing to go do? Absolutely not. The first thing to do is get that scope right, which begins with figuring out what CUI

Proving Evidence For Each Objective

Brooke

you have.

Stacey

Aaron Powell So jumping to the topic of evidence, what does a company actually have to prove item by item?

Brooke

Well, item by item. I mean you have to go through when you work with an assessor or when you do a self-assessment really, um you have to go through and prove that you meet each and every single one of the assessment objectives. Um Do you have an authorized user list? Yes. It's over here. This is where it's at. These are all the columns and everything else it has in it. It's all current. Uh this has been authorized, blah, blah, blah. When has it been authorized? You know, all that kind of fun stuff. So uh do you limit those access to uh the organizational systems that contain CUI to those authorized users? Yes, we do. Here's the authorized users, and here's our system, and here's the users in there, specified exactly like they are in the user list, right? So uh you have to go through each and every single assessment objective. There's 110 controls, but 320 assessment objectives, and get ready for revision three when it ever comes out because it's got a lot more. Um So uh anyway, get get ready for that one. But you have to you have to prove those assessment objectives is what you had to prove. It's not necessarily just the control statement. In fact, a lot of times the assessor might read that control statement, but really the meat is in the assessment objective. So that's where they focus and that's where they want to know that you've

Reducing Disruption While Implementing

Brooke

covered everything.

Stacey

Aaron Powell So this question is probably one that business owners care the most about. How do you actually do all of this without disrupting day-to-day operations?

Brooke

Well, that's a that's a tricky question a little bit because uh it depends on um it depends on where you start out. It depends on if you're one of those companies we talked about earlier that is pretty mature in their cybersecurity implementation. Um or if you're one of those companies that, you know, has just uh buys their workstations from Amazon and and just starts them up and and uses them, you know. Um so it depends on where you start your journey at, really. Um more people are on the not so good side of that than the good side of it, um that at least that come to us for help. And maybe maybe we have a uh skewed view of it because like an insurance professional, my wife was in insurance, that's why I use this as an example. You know, uh she sees all the worst cases, you know. Uh so we see all the people that really need help, right? Um but and we get varying needs of help as well. So uh but most of the people we see uh really need some help. So um and we're happy to help, happy to do whatever. But so you know, to do this without disrupting operations, yes, you can you can do most of these things without disrupting operations or a minimal disruption. Um, you know, if if uh none of the machines are, you know, if you decide that one of the things you have to do to meet a control is to join all the machines to all the computers to intra-ID and implement some uh in-tune with some policies and some uh some uh conditional access stuff policies. So uh if you decide you need to go that route and you have computers that are just work in work groups or just a not part of any domain, not part of any cloud service or anything else, then there's gonna have to be some migration, right? And so you have to migrate or blow it away and start over or something, and anything you choose is gonna be a little bit of disruption. And you can always, IT, part of our job is trying to figure out how to implement things with the least amount of disruption, right? And so things can be a lot of stuff can be done after hours or on weekends, or you know, you can start with uh the client and work on it while they go to lunch or something and they come back. You know, there's all sorts of things that you can do uh to get that to get those computers covered, to get those uh it may be that you have a you know a Windows 2008 server, you know, which is out of compliance, out of support, right? Uh so if it's out of compliance, out of support, um then you need a server that is in support, so likely you're gonna be buying a new server, which holy cow, uh prices are crazy these days. Uh actually, we uh quoted a couple of servers recently that were not nearly as bad as I thought they were gonna be. So they still have a ship date that's crazy, but um they have been beating the ship dates. But that's another rabbit trail. We're not gonna worry about that one. Uh but you know, if you have to migrate to a new server, yeah, there's gonna be there's gonna be some impact there. You know, you can do a lot of that with as little impact as possible, and migrating a server might be zero noticeable impact, or it might be only 0.1% noticeable because you know, two users uh didn't get the drives remapped, or something like that. You know, so there, yes, you can implement a lot of this uh without any disruption, uh, but there very well may be some workflow change because you discover that, like we talked about a minute ago, when you figure out where all your CUI data flows and you don't want it to do that, so you need to change that. That's going to be some business process change, right? Uh so is that disrupting uh for people? Some people take that in stride, and some people are really set in their ways. They don't they don't take it in stride so much. Everything is a barrier. So um so yeah, you can implement this with not a lot of and it depends, like I said, it depends on where you're coming from. You could implement all these things without a ton of disruption, but there's likely going to be something.

Where Most Companies Really Land

Stacey

So kind of just rounding out the episode here, with all that was said, where do you think most companies actually land in their compliance journey?

Brooke

Aaron Powell Most companies aren't necessarily starting from zero. Um there are some companies that are, right? Even when they think they have some things in place or or they just have no clue and they know they don't have a clue because they're not IT people and they're not compliance people, and they say, I have no clue. You know, we you know, I think we're okay, but you know, where are we at? Uh you know, uh what I can say is most of the time when we go do a gaps analysis, the people are not nearly as well off as they think they are. Um but that said, uh most of them are not at zero either, right? Or I guess in this this case, zero would be minus two oh three, because that's the that's the lowest score you can get for uh uh self-assessment or for an assessment, right? Uh so most people are not there. Most people have some things done. Uh a lot of people have some really good things in place to build on. And so most people are not at zero. Uh most people are above that somewhere. Um that said, we do work with some people that have bootstrapped their company and and are small and are trying to get going, and and they pretty much are starting from zero. They have computers, so maybe they're not zero, zero, but you know, they they have computers in place and that's about it. So um but most people have uh some decent things in place to work off of, even if they do have to upgrade a server or put some new you know, network equipment in place or or something like that. And the other thing uh is that you know, the the the whole point of the matter is if you if you can get somebody, some outside uh folks to come in and uh do a gaps analysis for you to figure out where you're at, where you need to be. Um again, that uh from our experience a lot of times that's a shock to people, right? Um but the point is that from that you can develop uh you can start to develop a plan of action and milestones. You can start to develop a plan to get there. You know where you're at, you know where you need to be, you know what your gaps are, your gaps are documented, you know, and now how do we fix those, right?

Closing And How To Reach Us

Stacey

Well, thank you, Brooke, for all of your insight.

Brooke

Absolutely.

Stacey

If you have questions about what we covered, reach out to us. We're here to help fast track your compliance journey. Text, email, or call in your questions, and we'll answer them for free here on the podcast. You can find our contact info at cmc compliance guide.com. Stay tuned for our next episode. Until then, stay compliant, stay secure, and make sure to subscribe.