Webinar Transcript: CMMC – Are Your Ready?
David Hammarberg: Good afternoon, and thank you for joining us for today’s webinar titled Cybersecurity Maturity Model Certification: Are you ready?
My name is David Hammarberg, Partner at McKonly & Asbury. I’ve been with the firm a little over 26 years, and I lead up our CMMC, SOC 2, HITRUST, internal audit areas. Excited to be here with a team of lead assessors we have here at McKonly & Asbury. And I will let each one of them give a quick introduction.
Elaine, would you start us off?
Elaine Nissley: Yes. Hello, everyone. I’m Elaine Nissley. I’m a Director here in the CMMC area. I’ve been with the firm for 21 years. I have a background in IT and IT Auditing from the Internal Audit perspective, and Dave pulled me into CMMC when we were getting ready. We went through our DIBCAC assessment and passed with no problems and became certified, authorized to C3PAO, on January of 2025. So, we look forward to working with you as we go through this presentation, and certainly we welcome any questions in the chat box.
Mike Murray: I’m Mike Murray, I’m a Manager. I’ve been with the firm for 4 years. My background is in Army Human Intelligence. I changed gears to the IT world. And because of those two factors, Dave pulled me into the CMMC segments. I’m excited to be here. Thank you.
Ryan Handley: My name is Ryan Handley, Supervisor with the firm. Most of my experience comes from the federal government. My most recent position there was actually with DCMA DIBCAC itself. So, a lot of experience performing 800-171 assessments and CMMC Level 2 assessments for prospective C3PAO’s. Also, have 15 years in the Pennsylvania Air National Guard. Looking forward to answering your questions.
David Hammarberg: If you’re not familiar with us, McKonly & Asbury is an accounting and business advisory firm with offices in Camp Hill, Lancaster, Bloomsburg, and Philadelphia, Pennsylvania. We offer a wide range of services to organizations in various industries. For more information, please visit our website. If you joined us on past webinars, welcome back. If you haven’t, our monthly webinars feature various business topics to keep you updated on what’s going on around us.
Be sure to check out our website to catch past presentations as well as current information through our blog.
Our Thought Leadership Subscription, M&A Insights, has been revised to give our subscribers an opportunity to select which topics are most relevant to them. Subscribe today to stay informed.
David Hammarberg: And the Agenda. Before we jump into the agenda, I just want to kind of give a little bit of background: McKonly & Asbury, how we got to this actual title, where it came from, because it wasn’t by accident. So McKonly & Asbury became a C3PAO on January 2nd, 2025, with 34 other C3PAO’s, the first time you could be authorized to become a C3PAO, January 2nd, 2025. A C3PAO, and I know we have a wide range of individuals on this call, ranging from people who just want CPE to people who are interested in CMMC to people who, you know, are ready for an assessment. So, you know, a C3PAO stands for CMMC Third-Party Assessment Organization. For those of you who are wondering what that stood for.
We began, like I said, last January of 2025. And it was a quick learning curve. And I would say we’re still learning. We’re 13 months into the assessments. But we quickly realized that OSC’s, Organization Seeking Assessment, OSA, I should say. They also go by OSC, which is Organizations Seeking Certification, regardless of what term you use.
Those organizations were coming to us unprepared. We were not finding organizations that came to us that really had the ability to pass the assessment. Cyber-AB, which again, is the accreditation body of CMMC, allows us to do mock assessments. And one of the things that we were really pushing, back then and currently, is doing mock assessments before there’s those, full blown assessments, allows us to see eye-to-eye with the organization seeking assessment.
And it allows us to go through and make sure that, you know, are they trending Met, are they trending Not Met, with all of the 110 controls, the 320 objectives. A lot of C3PAO’s do mock assessments. We do a mock assessment that’s really expanded. It’s probably 4-to-6 weeks. We go through their, like I said, all 320 objectives.
One of the key notes with doing this kind of work is you cannot consult and do the assessment for the same client. So, a lot of C3PAO’s out there will do consulting to prepare, but they will also do the assessment. We’ve been doing assessments for SOC 2 HITRUST, etc., since the early 2000’s, 800-53, And it really… assessments is what we do.
So, at McKonly & Asbury, we don’t do any consulting, we just do the assessment. Part of that mock assessment, according to Cyber-AB, it is not a consulting. It’s going through and saying we can say, is it Met, is it Not Met, and the reason why it’s Not Met. One of the big differences for us is we go through, and we might assess something ten times until it’s trending Met.
So again, that’s a 4-to-6-week process. We go through, and early on going back to, you know, where I started this: what’s the background, where did this come from, is organizations were just not getting it. They weren’t understanding what we needed to start the mock assessment or start the assessment, basically the same thing. So, we came up with this package of key documents that really is expanding.
I think we added something two weeks ago. You know, it’s stuff that we need for the organization to come to that mock assessment or assessment prepared. And even in the mock assessment, you know, a lot of organizations out there, in the beginning, treated that as a gap analysis. It’s not. You should be coming to this mock assessment, thinking you’re 100% there.
David Hammarberg: And then we’re going to go through it. And I think, you know, of all the clients we’ve done, we’ve had one client where we’re like, you know, they really didn’t need a mock assessment. For the rest of them, this thing is very valuable, so that, you know, there’s no guarantee you’re going to have a successful assessment after you go through a mock assessment, but there’s, you know, it’s likely that it will help get you through that in a positive result. So, to jump into the agenda, you can read it here. These are some of the items that we need in order to start. And we’ll go through these and identify them through the slides. So, I’m not going to read them out loud.
David Hammarberg: And as we go through, there’s a lot of acronyms when you get into the government: DoD, DoW, Department of War, Department of Defense. You’re going to have more and more acronyms. So, we’re going to try to say the acronym and, as well as, let you know what that is. As we go through, like Elaine said earlier, please put questions in the chat. Love to answer those to keep, you know, keep dialog going. And we’ll move on.
David Hammarberg: We have a polling question. I’ll read this. If you have any questions for us during today’s presentation, please submit them through the built-in question function in the webinar control panel, and we’ll do our best to answer them during or after the webinar. For those of you that are looking to obtain CPE credit for today’s webinar, please keep in mind that there will be four polling questions throughout today’s presentation and you must answer all four of those questions to get your certificate via email within a month after the webinar.
David Hammarberg: In order for attendees to be eligible, you must answer via the polling submission. We will not accept late responses. So, it’s a fairly, difficult question for you. Do you wish to receive CPE for attending today’s webinar? That was a little bit of a joke. But if you can go ahead and hit yes or no, there. We’re supposed to give you a little bit of silence, so everyone has time to answer. So, I will, have a brief, 30-second silence here for everyone to answer.
David Hammarberg: All right, that was a quick 30 seconds, but it looks like we’ve got, most people are here for CPE. And I would imagine those 13 people that are not here for CPE, are here because they’re looking for an assessment, or preparing or looking to, you know, again, the reason why they’re getting assessment, is so that they can bid on DoW contracts, Department of War contracts.
You know, the contract says, hey, you can’t bid on this unless you are at a Level 2 certification. So, we will keep going.
Mike Murray: I am going to discuss two of the foundational documents for determining the scope of your environment. Without getting the scope nailed down, you really can’t build those key documents. Both of these, CMMC Scoping Guide Level 2 and the CMMC Assessment Guide Level 2, can be found freely on the DoW CIO’s website. If you receive copies of the slides, they’re linked directly in there as well.
I’m not going to read these documents to you, but I am going to go over each of them at a bit of a higher level and highlight some of the more impactful points. The Scoping Guide is primarily useful for helping you determine the asset types and your environments and what you are supposed to do with those assets in terms of documentation and what kinds of testing, and basically testing and assessment you can expect, during your Level 2 assessment for those asset types.
We’re going to get into those a little bit later on. There is further discussion on the asset types to help dispel as much of the gray area as possible. During an actual assessment, you should reach agreement with your C3PAO on the asset types in your environment by the end of phase one. So, there is room built in this to correctly identify the asset types rather than it being a Pass / Fail if you mislabel or are not sure about a particular asset in your environment. You should keep in mind that the scope should include people, technologies, and facilities.
So, it’s not just like the end points and the hardware, within your scope. For example, personnel from an MSP who provides security for in scope parts of the environment would be considered a Security Protection Asset. And you can read more about that within the guide itself. It also does contain discussion on physical and logical separation techniques, as well as, External Service Provider considerations, which, that we will get into, in greater detail later on as well.
David Hammarberg: Yeah. And I should tell you, you know, this presentation, although it’s a more high-level presentation that we give our clients, every client that signs up with us, we go through this right after they signed up for their engagement letter. So, you know, if it’s a six month out assessment, they get it right away so that they can, you know, gauge what we want and what they have.
David Hammarberg: And these guides here, again, can be found on the web. And, you know, make sure you get the right one. Level 2, September 2024. But again, scoping is so important in any assessment, whether you’re doing CMMC or any other framework. Ryan, I know we’ve gone through some nightmares together in regards to scoping. Tell me what happens when you don’t have the right scope, and you’ve tried to go through the mock assessment.
Ryan Handley: So, like Michael alluded to, it’s nearly impossible to proceed any further without having the scope nailed down. There’s so many things that come into play when we start getting down into the 320 control objectives, that you’ll basically have to re, you know, you’ll have to go back through and redo everything if that scope is not nailed down in the beginning.
A good example of that. Everything is really based around where CUI is circulating in your environment. You know that there’s ,if we discover something mid assessment, you know that, that could affect, you know, a couple hundred, possibly even all 320 control objectives. So again, there’s a lot of wasted time if we don’t have a clear picture of your scope, before we proceed with actually looking at the objectives.
David Hammarberg: Yeah, that’s so important because in the past we spent so much extra time restarting mock assessments because now all of a sudden, we realize, hey, the scope isn’t that enclave, it’s more of an enterprise, etc. So, very important that if you’re doing this yourself, you get it right. Or if you’re working with someone else to help you with this, that you get that right and, you know, you don’t move ahead until you realize what that scope is, where your CUI is located, what data you’re protecting.
Mike Murray: So, forward, I have a couple more thoughts about the assessment guide as well, Dave.
David Hammarberg: No problem, sorry about that.
Mike Murray: Yep, no worries. So, the assessment guide is kind of a peek behind the curtain, how an assessment is going to be performed.
It will help set expectations right off the bat and really should be required reading prior to undergoing Level 2 assessment. The CMMC assessment methodology is explained here at a fairly higher level, with the three assessment methods being interviewing, examination and testing. So, for example, in our assessments, interviews and testing are closely tied together.
While we interview key personnel who have responsibility for a given control, we may ask for a screen share or live demonstration of how an objective is met, and at that point will gather screenshots as evidence. The guide also discusses how assessment findings are reached and delivered. Each of the 320 objectives will have one of three possible findings, that being Met, Not Met, or Not Applicable.
Finally, the guide does provide good discussion for each of the 110 controls and includes example scenarios and potential assessment considerations for each objective. While it may not be like a good end to end read, if you have questions about particular controls or objectives, you know, what they mean, how to meet them, it is a really good reference to keep on hand.
David Hammarberg: Thanks, and if you can’t find those guides, let us know. We can send you a link.
Mike Murray: So again, these are the key documents that are foundational to an assessment. In most cases, there are additional supporting documents as well. But in that first delivery of an assessment package, we would expect, at a minimum, these documents. And again, the key here is that all of these documents should work together rather than necessarily being standalone.
And what I mean by that is, what you have listed on the Categorized Asset List, should be represented on the Network Diagram. The CUI Flow Diagram should be a reflection of what is documented in the System Security Plan, and in some cases, the Shared Responsibility Matrix. So, we rely on all of these to paint a much clearer picture of the environment.
David Hammarberg: Mike, how often do these documents change going through the mock assessment?
Mike Murray: We expect that during the mock assessments, because of the fact we’ll go back and reassess objectives, again and again, we expect several versions of the SSP, several versions of the Network Diagrams. So that can change anywhere from 5 to 15. You know, there’s really no upper limit that we’ve seen yet.
David Hammarberg: And again, we can’t consult on this. So, we’re saying Met, Not Met, and why it’s Not Met. So really the OSC, Organization Seeking Certification, really needs to take that information, go back to their MSP, RPO, and go back and figure out what they have to do and come back to us. So, is that correct?
Mike Murray: Yes. So, when we give, when we deliver, a Not Met for an objective, you never have to wonder exactly why we thought that it was Not Met. Well, we can’t tell you how to fix it. We’ll tell you what is not working. And we’ll tell you in enough detail that, you know, you should be able to take that information, go back, and try again.
David Hammarberg: Right.
David Hammarberg: All right. Polling question number two. What is the status of your preparation for a CMMC Level 2 C3PAO Certification Assessment?
David Hammarberg: And this will probably be all over the place. And I will be silent for another 30 – 45 seconds.
All right. Not needed by my organization. So, either people are needing CPE, or they just want to broaden their education on what’s out there. And then we have 11% Ready to engage a C3PAO. So, we have a good demographic here. You know, and just going back to, Mike’s last slide there, you know, a lot of organizations, documentation is the hardest thing.
David Hammarberg: You know, we find a lot of organizations that, from a technical standpoint, they’re, pretty good. But from a documentation standpoint, they’re not. And I think there’s got to be a balance there. You know, you don’t want too much, and you don’t want too little, so that’s a challenge.
Mike Murray: Yeah. I would add to that. And what we have seen in a number of cases since you mentioned it, in the SSP, if you tell us three different ways, you’re meeting an objective, when only one of those is required, well, then we’re going to chase down the evidence for those three objectives. When you could of stopped at one.
David Hammarberg: Yeah. The challenge is that, you know, sometimes for us, it will be like, hey, why are you asking this?
David Hammarberg: I’m like, I’m asking it because that’s what’s in your SSP. And I have to test everything that you’re putting in your SSP. So, you know, you want to think those things through clearly and put information there to meet the objective. And that’s sometimes the challenge. Ryan.
Ryan Handley: All right. So, this is the first of the key documents that we’re going to go over.
This is the System Security Plan. Most of the things that you’ll see in this slide that we address as a requirement, are actually required within the 800-171 in 3.12.4. So, there’s a bunch of objectives that cover what’s actually required to be in your SSP per the CMMC Level 2 rules.
The first of which, we’d like to see that your SSP addresses at the 320 objective level and not the 110 requirement level. For each objective, kind of alluding to what Mike and Dave just talked about, we need a concise but detailed description of how you believe you’re meeting each control.
We would advise you not to overdo it. As Mike said, if there’s three different ways when you would have been good with one, we, you know, we would advise you to stick with the simplest approach possible. But we also need a good amount of detail in there because you have to remember, as assessors, we don’t, you know, we’re not your employees, but we’re not familiar with your environment.
This is your, the SSP is basically your chance to explain this to somebody who’s never seen your environment before, and how you’re meeting each of those 320 objectives. The next thing we look for is just an overview and description. We also look for applicable roles and responsibilities. There are several objectives throughout the assessment where we’ll actually, you know, things like Least Privilege, Separation of Duties. It helps us to make those determinations up front when we have those roles and responsibilities listed in the SSP.
David Hammarberg: And Ryan, we go through when we do this presentation for new clients, we go through, and we show them an example of an SSP. But there’s no standard out there. It’s just, you know, it’s standard in what we expect in there. But format wise, I guess I should say, there’s no standard.
Ryan Handley: Yeah. That’s correct. I mean, there’s plenty of GRC tools out there that can generate an SSP for you. We also see clients that kind of do this manually by hand with a Word document. So again, as long as the information’s in there, we don’t care what the format is, just as long as we can figure out what’s going on within a relatively short amount of time.
Mike Murray: Network diagrams. The first bullet point there says that all assets in the categorized asset list should be present on this diagram. There are exceptions to that. So, like I said earlier, your asset types includes people, technologies, and facilities. So, for example, we don’t, if you have 45 employees, you know, we don’t expect to see the employees on the Network Diagram, but what this refers to are all of the other, like the technologies and the facilities, we would want to see on a Network Diagram. This is what is visually going to represent your scope the best. I often talk about Network Diagram and the CUI Flow Diagram in conjunction because there’s no rule that says they have to be two separate diagrams. If your environment is simple enough and small enough, you can have a Network Diagram that shows the flow of CUI.
But in the more complex environments and enterprises, we would want to see the overall Network Diagram.
The CUI Flow Diagram, specifically, is where we’re going to see what CUI touches. From the moment it is received from, if you have a prime or directly from the government, we want to see where it comes from, where it traverses the environment, where it is stored, and where it exits. And in some rare cases, where it is created as well.
So, you can have, let’s say, if you have 10 endpoints in your scope, and they are all CUI assets, and they are all identical in terms of configuration, security, all of that, you can just have a representative sample of one of those endpoints in the CUI Flow Diagram for simplicity. While, you know, all ten of those would be represented in the Network Diagram.
David Hammarberg: You know, we seem to get Network Diagrams fine, but the CUI Flow Diagram, and just this, how the CUI flows through the organization, just seems to be a stumbling block for individuals. I mean, this is open to all three of you guys, you know, why do you think that is?
Mike Murray: A couple cases that I’ve seen, I think just the term itself, can trip people up because we’ve received flow charts, which are quite a bit different, for a lot of environments than what a CUI Flow Diagram would be. So, it’s like a written chart of the entire process, which can be useful, but is not really what the CUI Flow Diagram was intended to be.
David Hammarberg: Ryan or Elaine, anything to add there?
Elaine Nissley: Okay. I’ll say that, really, the CMMC assessment is mainly an assessment of the technical environment and the storage transmission of CUI.
So, what you can show the flow of CUI through people’s hands, but that really doesn’t explain to an assessor what CUI assets it’s hitting and being stored on, processed on, and transmitted. And that’s, the assessor needs to know, the association between the assets and the CUI, which is, and most people do flows associating CUI with the people that it’s associated with.
David Hammarberg: Ryan?
Ryan Handley: So, I’d say another issue that contributes to this is understanding what CUI actually is. So, we’ve had several clients where, even the customer, the government that they’re interacting with, the contracting officers aren’t even, they don’t even have a full understanding of what CUI is as it pertains to the contract when they generate specific types of information and things of that nature.
Right. So, I think that’s another big contributing factor that, all the players don’t even have a full understanding of what CUI is. And then you have overlap of information types like ITAR, that could be CUI, but aren’t. It’s not always CUI. So, a good way to get around this is, you know, build your information system with the intent that if you’re holding anything that would be CUI, this is where we’re going to put it, because the contracting officer may not always have that answer for you.
David Hammarberg: It doesn’t seem like in the past, CUI has been labeled very well, meaning it could be missing. It could not be missing. I think that plays into a role of what is CUI. And then, you know, some IT people don’t know exactly what CUI is and where it’s located. Really understanding your environment and where that CUI is. The other thing that, you know, and you guys can talk about this as well, is on the manufacturing side, you know, is it CUI when the item is produced, is it CUI, you know, diagrams, etc.
David Hammarberg: And it just seems like there’s really no clarity there from when we talk to those manufacturers. Yeah. Go ahead, Mike.
Mike Murray: Real quick on this, I didn’t touch on for the Network Diagram. Another thing that is highly useful to assessors, on the Network Diagram and CUI Flow Diagram, is something that’s actually really simple and that is designating the connection type. So, for example, if you have a CUI connection, making that connection red versus, you know, the other types, and that helps us visually track where that CUI flows, as well as Security Protection Data.
Mike Murray: So that is data that is, you know, log data, data that flows to your SIM, or endpoint detection and response. That is a way to kind of elevate the network and CUI Flow Diagrams.
David Hammarberg: And we’ll get into what kind of different assets. But you hit it there. I mean, we are going to test different assets differently.
When it comes down to whether it’s SPA asset, CUI asset, etc., so that information is really important. And when you said red Mike, what were you saying? What were you referring to there as labeling it red?
Mike Murray: So that just for an example, you could label it any color you like, but just being able to visually distinguish a CUI connection from other connection types in your environment.
Mike Murray: So, we touched on this, a little bit earlier, but the first thing that you will see in the scoping guides is a table which lists out the different CMMC asset types. In your categorized asset lists, any asset in scope should be labeled with one of these five asset types. The scoping guides, it lays out, what the requirement is for the OOSA, in other words, how you treat it, how you document it, and it also gives the assessment requirements. The assets, obviously, that are scrutinized the most are at the top. The CUI assets, they are subject to all 320 objectives. Security Protection Assets, again, think in terms of facilities, technology, and people. Those should be listed out. Now, there’s cases that we’ve run into where an OSC is kind of wondering which way to go with a particular asset, a firewall, for example.
Technically, CUI does flow to that asset, but its primary function is as a Security Protection Asset. So, if you think in terms of what is this asset’s primary function, that can help find agreement with your C3PAO. CRMA, these have also caused a little bit of heartburn. These are assets that can, but are not intended to process, store, or transmit CUI.
So, if you think in terms of, you have a flat network, you have four endpoints on a single shared network. Let’s say two of those are meant to handle CUI, but the other two are not. So, they can access it technically, but either by policy or some other security function, they are not supposed to. CRMAs, those in a way, I don’t want to say get off the hook, because they don’t get off the hook. But if they’re sufficiently documented in the SSP, and that means that your internal security policies address it and you’ve secured it as best as you can, and it’s fairly bulletproof in the SSP, then we’re not going to assess it against CMMC security requirements.
Specialized assets are in a similar boat. These are assets that you’ll find a lot in manufacturing environments, such as CNC machines or PLCs. These are devices that just by their inherent design or some other limitation, cannot be fully secured to the 320 objectives. There is a caveat to that in that they have to fall into one of five categories.
And that is they are an IoT, Internet of Things device, Industrial Internet of Things device, Operational Technology, or Government Furnished Equipment. Also, you know, if you have restricted information systems and test equipment, those can all be classified as Specialized Assets. As long as they are documented in the Asset Inventory and sufficiently documented in the SSP, meaning that, you’re showing how you are securing them to the best of your ability, then they will not be assessed against CMMC security requirements.
David Hammarberg: The two most frequent ones we see, I think are, you know, GFE, Government Furnished Equipment, or some kind of manufacturing machinery from a Specialized Asset standpoint, you agree?
Mike Murray: Yeah. Yeah, I definitely agree with that. We also get questions on Out-of-Scope Assets, and, you know, do we want to see these or not?
If they’re Out-of-Scope, then, you know, why are we documenting them? If you have Out-of-Scope Assets, they are Out-of-Scope if they are physically or logically separated from the scoped environment. The only times in my experience that we’ve really looked at Out-of-Scope Assets is if it helps define the external boundary of the environment, meaning, okay, the boundary goes up to this point.
Mike Murray: Anything outside of that is an Out-of-Scope Asset. So, if you have an enterprise of, let’s say a thousand machines, but you carve out an enclave of five, which handles CUI, with everything else Out-of-Scope, you don’t, we wouldn’t want to look at the rest of the 995 assets.
David Hammarberg: Right. And this asset list should match, you know, we should be able to dial this right into the Network Diagram. Correct?
Mike Murray: Yes. So, if we see these Security Protection Assets, labeled in the SSP, and we see it in the Categorized Asset List, we should be able to look at the CUI Flow Diagram or the Network Diagram and see that specific asset.
David Hammarberg: Right. And we get, I think we run into this a lot more than we probably should as we get these lists, whether it’s in Excel or out of the GRC platform of, you know, the asset, what it is, you know, more information about what the asset is.
But we don’t get the classification. And a lot of times I feel like we have to go back to the OSC and be like, we can’t work with this until it’s an actual asset list that is categorized correctly.
Mike Murray: Yeah, that is correct. A lot of times we will see an internal labeling system for that company, which even if it is extremely close to an Asset Category for CMMC, we still have to see it fall into one of these five specific categories to be able to work with it.
Elaine Nissley: Okay. Next, we’re going to talk about Cloud Service Providers. And one of the gray areas where there’s usually a lot of discussion is, I have, I’m using an outside organization. Are they in scope as an External Service Provider. So, the first question you need to ask is does that external provider process, store, or transmit CUI, Controlled Unclassified Information, or SPD, Security Protection Data.
If they do not process or store CUI or SPD, they’re not an External Service Provider, and they’re not in scope. If they are an External Service Provider, then the next question you ask is, are they a Cloud Service Provider, or are they a non-cloud service provider. And there’s clear guidance from NIST 800-145 that tells you the characteristics of a Cloud Service Provider.
They must provide on-demand self-service, which means that the consumer, the customer, can provision computing capabilities such as server time and network usage. There’s broad network access, which means you can access them through a thin or thick client, such as mobile phones, tablets, laptops, workstations, etcetera. They do role resource pooling. And this is one of the big ones.
A lot of your cloud, most of your cloud service providers, are what they call multi-tenant. So, you’re actually sharing the same space, same resources in the cloud. And that opens up a lot of risk. Rapid elasticity is another item to consider. Are they elastically provisioned and released automatically? So again, resources are given to you during your peak times and taken away during your lower peak times.
And again, this is sharing of resources which opens up a lot of security risk areas. And then a measured service. Do the cloud, does the cloud system automatically control and optimize your resources? And again, to do that optimization, they share resources and provide you just the resources you need. So, if you, have the CUI that’s stored in the cloud, then they are then identified as a Cloud Service Provider.
So, if it’s a Cloud Service Provider, that’s handling CUI, they must be FedRAMP moderate or authorized or equivalent. And so, they must have undergone a review by a Third-Party Assessor Organization. And they must achieve compliance with FedRAMP requirements. And if they’re only handling Security Protection Data. So, you are using an MSP to collect your audit logs and do the analysis through the SIM.
And the only thing they have is the Security Protection Data, then they do not need to be FedRAMP moderate. But they are included in scope, and they will be assessed regarding any area within your SSP. You should be identifying part of the way that you meet that assessment requirement is by using this particular service, that’s external to the organization, and then they become in scope for those assessment objectives.
If it’s a Non-Cloud Service Provider that’s handling CUI, then it’s included in the OSC scope for all 320 assessment objectives. So again, when you’re working with External Service Providers, what we’ve seen most clients do is they limit their access and do not allow them to access CUI, if that’s possible, because again, it reduces their involvement in the scope.
Elaine Nissley: Non-Cloud Service Providers, with handling Security Protection Data only, should be included in the scope, but only again for those assessment objectives related to the services that they provide.
Mike Murray: Elaine, is there still a requirement if OSC uses a Cloud Service Provider that is FedRAMP equivalent? Do they still have to perform a Body of Evidence review as part of the assessment?
Elaine Nissley: Yes. If it’s equivalent, there’s a memorandum dated December 23rd that lists the requirements that the provider must have passed and must provide you evidence that they passed a Third-Party Assessor Organization assessment of their environment and are FedRAMP compliant. They must also provide you a Body of Evidence that supports that assessment.
Elaine Nissley: So again, if you’re interested in that memorandum that has all the details regarding to equivalency, we could add that when we put out these slides as well.
David Hammarberg: Thank you, Elaine. Ryan. Keep going, Elaine. Sorry.
Elaine Nissley: Okay. The only other thing I wanted to point out here is that within the final rule 32CFR, there is a table that clearly lays out for you how to make a determination between a Cloud Service Provider and a Not a Cloud Service Provider.
Elaine Nissley: And determine whether or not your ESP is in scope. So, the language within the final rule is very clear on the definitions.
David Hammarberg: Thank you, Elaine.
Ryan, no pressure on this. And, but we need to finish up in about a minute per slide for your last six slides.
Ryan Handley: Okay, I can do that. All right. So, the next piece here, would be the Shared Responsibility Matrix.
Ryan Handley: If you’re using a, you know, well known Cloud Service Provider, like, you know, Microsoft or, you know, Amazon AWS, Google Workspace, things of that nature, they’ll know exactly what you’re talking about, and they’ll provide you with an SRM. When we wrote this slide, we were, this is pertaining to, if you’re using an MSP, or something of that nature, basically what we’encountered is, there’s been scenarios where the OSC, and the MSP are fully in a line on who’s doing what or who’s responsible for what, as it pertains to the objectives.
Ryan Handley: So, another thing we asked for is an SRM between you and your MSP, or anybody who’s not providing one to you already. So, we have a good understanding as assessors, who is responsible for what, when we’re going through the objectives.
Elaine Nissley: And MSP is Managed Service Provider.
David Hammarberg: Polling Question 3. What is your understanding of the CMMC Level 2 C3PAO Assessors requirements for the key documents? Everyone can select that. Then we’ll be quiet for 30 seconds. And I guess, Ryan, you’re down to five minutes.
All right. Very similar to, the last poll. I would assume the 12%. I think the last one was 11%. We have key documents, so it’s probably the same individuals that are, from the last poll. So very good. Ryan, take it away.
Ryan Handley: All right. So, this stage begins, when you’ve contracted with us and you’re actually beginning to start a mock assessment or a certification assessment, depending on, you know, which path you use.
Ryan Handley: These are some of the things that we, we like to think about when we talk about an Initial Evidence Package. It should include a complete listing of every artifact, every applicable policy procedure, anything and that anything you can use as evidence, during an assessment. We ask that those be provided to us well before the assessment begins.
Ryan Handley: Reason being, we need several days to look over those things, identify gaps. And the sooner that we’re able to identify those gaps, that gives you more time during the assessment to clean them up and get a better overall result. Next slide.
Elaine Nissley: I want to mention here too what a lot of people don’t realize is the CMMC requirements are evidence based. We need to gather and maintain evidence that supports our results from the assessment.
Ryan Handley: All right. So, we’ll go down into some 800-171A (Alpha) terminology. So, I bring this up because this is a common trend throughout the 800-171, it requires organizations to define certain standards. And then usually the follow-on objective to, that is, you show us where you’re actually implementing or enforcing that standard. Right.
Ryan Handley: So that’s a common trend throughout. So again, previous slide, if it uses the term, you know, specify or define, we’re looking forward to actually be written in a policy. There’s no way around it. It has to be documented somewhere. If it’s using terms like determine if, or, you know, identify, then we’re actually looking for an implementation.
Ryan Handley: We’re looking for artifacts or, you know, a live demonstration of what your implementation actually is. Next slide. I think we can go to the next one as well. So, here’s just a quick example of what I just discussed here. Again, you can see a screenshot of an example policy here. This particular objectives, it specifically states that, retention requirements for audit logs must be defined.
Ryan Handley: So, when we look for this, as you know, assessors, like we can’t, we can’t satisfy this by an interview, you know, if we come in and ask you what, you know, what’s your retention requirement? And you say, you know, well, it’s usually sometimes it’s three years, sometimes it’s two, you know, we can’t accept an interview, you know, to mark this Met. It actually has to be written down in your policy, your SSP, anywhere you know, where it’s actually strictly documented.
Ryan Handley: Next slide. Again, here’s the follow-on objective, to the definition of the retention period. In this case, we’re looking at AlienVault. And then this specific example, AlienVault retains the logs indefinitely until the license expires. So that was proof of implementation that these logs are being, you know, kept for at least one year.
Ryan Handley: So mainly the point we’re trying to drive home here is, if it says defined, it must be defined when it’s looking for, you know, evidence of that. You know, you can provide screenshots, you know, interviews for clarification, and any other type of artifact, that just lets an assessor know, hey, this is what’s being done as defined.
David Hammarberg: Polling Question #4. Are you interested in engaging the services of a C3PAO? You’ll notice as we went through this presentation is, you know, you can hear there’s a good bit of auditor’s judgment in Title 32. Some organizations don’t like that fact. They like black and white. But our organization has always, did assessments.
David Hammarberg: We’ve always had that sort of auditor’s judgment built in. So, we enjoy the way it is written and some of it could be a little bit more clearer, but, excited to do every assessment and see how organizations meet those requirements. Again, I’ll give a little bit of silence so you can answer the poll.
David Hammarberg: All right. It’s very similar. I think we had 11, 12 and 8% for the last one. And the top one is the highest one. So good deal.
David Hammarberg: And I think we’ve basically answered all the questions, throughout the period. So that’s, kind of nice. If anyone wants to pop something. I know we’re about out of time. But I think we did answer all of the, recipients’ or the participants’ questions, so that was nice. Some contact information for the individuals on the call.
David Hammarberg: Feel free to contact any of them. I’d love to hear from you. I’ll leave this up for a second.
Elaine Nissley: And there’s just one additional question came in here: If my organization has an SSP based on NIST 800-53, do we need a new one for CMMC or we can incorporate both?
David Hammarberg: Great question, Elaine. And you want to take that one. And then you know, Ryan or Mike can add in.
Elaine Nissley: I’ll let the lead assessors tell me what they’re going to accept.
Mike Murray: Good. Yeah. The short answer is yes. We would want to see something that is specifically aligned with 800-171. At least I would, if the information is there that meets, 800-171 requirements, then it can be salvaged. You know, not saying that you have to throw it out and start again, but we would want to see specifically how that relates to 800-171 objectives. Ryan?
Ryan Handley: Yeah. So, another thing, generally with, you know, leading up to CMMC Level 2 or CMMC 2.0 going live, you had to have an SSP that was tied in with your SPRS score. And that was always based off the 800-171. So, before CMMC Level 2, even became, or I’m sorry, CMMC 2.0 became live, it was still a requirement to have an SSP, that was geared towards 800-171.
David Hammarberg: Thank you very much. And I think that ends the questions. Upcoming Events. Thank you for joining us for today’s webinar. If you have any further questions regarding today’s presentation, please feel free to reach out. Our team would be happy to assist. A recording of today’s presentation will be posted on our website and social media sites in a few days.
David Hammarberg: And for those of you who have requested CPE and answer the polling questions, those certificates will be sent out within the next month. Upcoming Events. April 30th Webinar. Registration is open for our next webinar on April 30th, where our SOC team will discuss the increase in demand for SOC 2 and the changes it has caused within the industry, along with key differentiators to be aware of when finding or retaining a vendor.
Thanks again for joining us and enjoy the rest of your day.