Is your organization struggling to understand how to approach 3.10.6, Alternate Work Sites? What is allowed and what an assessor may be looking for?
In this CMMC Churns, we dive into 3.10.6, Enforce safeguarding measures for CUI at alternate work sites.
In the requirement deep dive, we will look at the requirement, assessment objectives, the requirements relationships to other requirements, and evidentiary objects we would expect to see as assessors.
Interestingly, there are four primary use cases (working at home; in public spaces & travelling; in a hotel room; and at a client location) to that an organization can use to define its safeguarding requirements to be followed by staff when working outside of their offices.
We also look at considerations your business should ponder when developing safeguarding measures. For example & remember, Alexa & Siri are not authorized listeners to CUI conversations…
Key CMMC Organizations
- National Archives & Records Administration Controlled Unclassified Information (CUI) Homepage
- DoD CIO’s Cybersecurity Maturity Model Certification (CMMC) Home Page
- Cyber Accreditation Body (Cyber-AB)
- Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) Contractor Resource Page
- Defense Industrial Base (DIB) Cybersecurity Portal
Key Regulations
Key Acquisition References
- 48 CFR § 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems
- DFARS Clause 252.204-7008 Compliance with Safeguarding Covered Defense Information Controls.
- DFARS Clause 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
- DFARS Clause 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS Clause 252.204-7020 NIST SP 800-171 DoD Assessment Requirements.
- DFARS Clause 252.204-7021 Compliance with the Cybersecurity Maturity Model Certification Level Requirements.