C3PAO Tips

At Peak InfoSec, we often see clients make basic mistakes during a CMMC Level 2 Certification Assessment.

We created these C3PAO Tips to help companies understand potential mistakes they are making and how to avoid them.

C3PAO Tip #9 - Unauthorized Changes

During your Mock or Certification Assessment, make sure you follow ALL of your procedures. During two recent CMMC Level 2 Mock Assessments, we had the IT staff make changes to their system during interviews and tests.

"Uh, do you have an approved change request for what your just did?," we asked. Sheepishly, the staff person answered "No".

Well, the problem with the Security Requirement we were on was fixed, but 3.4.3 just became "Not Met" for making an unapproved change.

Thankfully, this was a Mock Assessment in both cases.

BOTTOM LINE: DO NOT make unauthorized changes during your Mock & Certification Assessments. In reality, Assessors are likely to ask to validate Change Processes were followed during your assessment window.

You can catch up on other C3PAO Tips at https://vimeo.com/showcase/11818247.
 
To schedule a CMMC Level 2 Certification Assessment, reach out to us at [email protected] or visit https://lnkd.in/e8sM_2Z3
 
Explore our latest insights on CMMC and more—check out our homepage here: https://peakinfosec.com. Don't miss episodes of 'As the CMMC Churns' for in-depth discussions at https://lnkd.in/eVGYGs3g.
 
===============================================
Peak InfoSec Homepage: https://peakinfosec.com
As the CMMC Churns Episodes: https://peakinfosec.com/as-the-cmmc-churns/
Contact Peak InfoSec for Support: https://peakinfosec.com/contact/
Email: [email protected]
YouTube: https://www.youtube.com/@as_the_cmmc_churns
===============================================

C3PAO Tip #8: 3.13.13 and the Browser

Requirement 3.13.13 is "Control and monitor the use of mobile code." Mobile code includes Java, ActiveX, Flash, and, under NIST PS 800-171 Rev 3, HTML5.

So the ubiquitous browser is in scope. This is commonly overlooked by organizations in preparing for their assessment. Please explain how you control and monitor the use of mobile code through your browsers. 

You can catch up on other C3PAO Tips at https://vimeo.com/showcase/11818247.
 
To schedule a CMMC Level 2 Certification Assessment, reach out to us at [email protected] or visit https://lnkd.in/e8sM_2Z3
 
Explore our latest insights on CMMC and more—check out our homepage here: https://peakinfosec.com. Don't miss episodes of 'As the CMMC Churns' for in-depth discussions at https://lnkd.in/eVGYGs3g.
 
===============================================
Peak InfoSec Homepage: https://peakinfosec.com
As the CMMC Churns Episodes: https://peakinfosec.com/as-the-cmmc-churns/
Contact Peak InfoSec for Support: https://peakinfosec.com/contact/
Email: [email protected]
YouTube: https://www.youtube.com/@as_the_cmmc_churns
===============================================
#cuicon #cmmc #cmmc2 #32cfrpart2002 #32cfrpart170 #cui #fci #cmmcab #thecyberab #nist800171 #defenseindustry #defensecontractors #defensecontracting #manufacturing #manufacturingindustry #dib #satellite #satellitecommunications #satellitesystems #GovCon #governmentcontracting #contractors

C3PAO Tip #6: Conduct a Mock Assessment

Undergoing a CMMC Level 2 Certification Assessment can be a risky proposition. If your organization fails, you can end up with unintended consequences (e.g., a DIBCAC Non-Voluntary audit) and potential lost revenue.

We encourage all of our potential CMMC Level 2 Certification Assessment clients to conduct a Mock Assessment. A Mock Assessment by a C3PAO is "off-the-books" and reduces the risk of your C3POA identifying a critical finding prior to beginning your formal certification assessment.

Additionally, conducting a Mock Assessment is considered an ISO best practice

You can catch up on other C3PAO Tips at https://lnkd.in/eEFCB8UW.

To schedule a CMMC Level 2 Certification Assessment, reach out to us at [email protected] or visit https://lnkd.in/e8sM_2Z3

Explore our latest insights on CMMC and more—check out our homepage here: https://peakinfosec.com. Don't miss episodes of 'As the CMMC Churns' for in-depth discussions at https://lnkd.in/eVGYGs3g.

C3PAO Tip #7: 3.7.2 and READ the Discussion

3.7.2 is one of the most commonly misinterpreted Security Requirements we run into. Why?

People don't read the Discussion closely. The word "not" in the first sentence shifts this from you managing internal maintenance work to managing 3rd party vendors and their maintenance activities.

Bottom-line in this is don't rust your memory. Always work form the NIST SP 800-171 and -171A as your source documents and read the content.

You can catch up on other C3PAO Tips at https://vimeo.com/showcase/11818247.

To schedule a CMMC Level 2 Certification Assessment, reach out to us at [email protected] or visit https://lnkd.in/e8sM_2Z3

Explore our latest insights on CMMC and more—check out our homepage here: https://peakinfosec.com. Don't miss episodes of 'As the CMMC Churns' for in-depth discussions at https://lnkd.in/eVGYGs3g.
===============================================
Peak InfoSec Homepage: https://peakinfosec.com
As the CMMC Churns Episodes: https://peakinfosec.com/as-the-cmmc-churns/
Contact Peak InfoSec for Support: https://peakinfosec.com/contact/
Email: [email protected]
YouTube: https://www.youtube.com/@as_the_cmmc_churns
===============================================

C3PAO Tip #5 | 3.1.1 is about "the how"

For 3.1.1, we commonly get the list of authorized accounts and devices as the only proof. "Great", we will generally say and then follow up with a question, "How were the people authorized?" And then, "How about these service accounts?" And then, ...

See, 3.1.1 is all about the process an OSC has to authorize and then appropriately limit access. The account & devices lists are the output.

So, when addressing 3.1.1 with your C3PAO, be ready to explain "the how."

You can catch up on other C3PAO Tips at https://lnkd.in/eEFCB8UW.

To schedule a CMMC Level 2 Certification Assessment, reach out to us at [email protected] or visit https://lnkd.in/e8sM_2Z3

Explore our latest insights on CMMC and more—check out our homepage here: https://peakinfosec.com. Don't miss episodes of 'As the CMMC Churns' for in-depth discussions at https://lnkd.in/eVGYGs3g.

===============================================
Peak InfoSec Homepage: https://peakinfosec.com
As the CMMC Churns Episodes: https://lnkd.in/eVGYGs3g
Contact Peak InfoSec for Support: https://lnkd.in/e8sM_2Z3
Email: [email protected]
YouTube: https://lnkd.in/egsMHdNd
===============================================

C3PAO Tip #4: "Shut Up Fool"

CMMC Level 2 Certification Assessments are stressful events. One of the hidden issues organizations have during an issue is continuing to talk when we are done as Assessors.

Certification Assessments create silence while we write up our notes before moving on. Silence makes people uncomfortable and they need to fill it in. MISTAKE.

Now the anxious interviewee(s) have let fear take over and bad things happen at this point. Worse are the anxious interviewee(s) who need to demonstrate how smart they are because they dig into other areas.

We now have to stop, listen, and new questions just opened up....

During there periods of silence, you need to do two things:
1. Listen to Mr. T's advice and shut up. Seriously!
2. Use the quiet to prep for the next security requirement.

Mentally, by doing this, your organization will move from reactive and fear based responses to a proactive mode

You can catch up on other C3PAO Tips at https://vimeo.com/showcase/11818247.

To schedule a CMMC Level 2 Certification Assessment, reach out to us at [email protected] or visit https://lnkd.in/e8sM_2Z3

Explore our latest insights on CMMC and more—check out our homepage here: https://peakinfosec.com. Don't miss episodes of 'As the CMMC Churns' for in-depth discussions at https://lnkd.in/eVGYGs3g.

===============================================
Peak InfoSec Homepage: https://peakinfosec.com
As the CMMC Churns Episodes: https://peakinfosec.com/as-the-cmmc-churns/
Contact Peak InfoSec for Support: https://peakinfosec.com/contact/
Email: [email protected]
YouTube: https://www.youtube.com/@as_the_cmmc_churns
===============================================

C3PAO Tip #3; The Two Fundamental Failure Reasons

The two basic reasons why an organization fails at their Certification Assessment are:
#1: They didn't use NIST SP 800-171A to determine the conformity of a security requirement.
#2: They don't evaluate all of the 320 Assessment Objectives against all in scope components.
To schedule a CMMC Level 2 Certication Assessment, reach out to us at [email protected] or visit https://lnkd.in/e8sM_2Z3
Explore our latest insights on CMMC and more—check out our homepage here: https://peakinfosec.com. Don't miss episodes of 'As the CMMC Churns' for in-depth discussions:
https://lnkd.in/eVGYGs3g
===============================================
Peak InfoSec Homepage: https://peakinfosec.com
As the CMMC Churns Episodes: https://peakinfosec.com/as-the-cmmc-churns/
Contact Peak InfoSec for Support: https://peakinfosec.com/contact/
Email: [email protected]
===============================================
#cuicon #cmmc #cmmc2 #32cfrpart2002 #32cfrpart170 #infosec #informationsecurity #compliance #cybersecurity #cui #fci #cmmcab #thecyberab #nist800171 #defenseindustry #defensecontractors #defensecontracting #grc #manufacturing #dfars #manufacturingindustry #dib #satellite #satellitecommunications #satellitesystems #managedserviceprovider #msp #managedsecurityservices #mssp #DoD #GovCon #governmentcontracting #SmallBusiness #contracts #contractors

C3PAO Tip #2: "System"

A VERY common mistake when reading NIST SP 800-171 and NIST SP 800-171A is to equate the word "System" with an IT System.

The word "System" in NIST SP 800-171 has its origins in Systems Engineering (c.f.,
https://lnkd.in/eGtjrduP) and encompasses the People, Processes, Facilities, & Technologies.

So, don't limit yourself by only thinking of IT Systems when trying to "Control the flow of CUI."

To schedule a CMMC Level 2 Certication Assessment, reach out to us at [email protected] or visit https://lnkd.in/e8sM_2Z3

Explore our latest insights on CMMC and more—check out our homepage here: https://peakinfosec.com. Don't miss episodes of 'As the CMMC Churns' for in-depth discussions:
https://lnkd.in/eVGYGs3g

===============================================
Peak InfoSec Homepage: https://peakinfosec.com
As the CMMC Churns Episodes: https://lnkd.in/eVGYGs3g
Contact Peak InfoSec for Support: https://lnkd.in/e8sM_2Z3
Email: [email protected]
===============================================

C3PAO Tip #1: Scoping Method

Proper scoping is done when an organization starts at:
1. The Information Layer,
2. Then to the People,
3. Then to the Processes they follow,
4. Then to any Facilities they use,
5. And then, finally, technologies.

In our experience Peak InfoSec , when organization try to scope from the "bottom up," they miss things that are in scope and then fail to apply protections. This is a scoping failure.

Protect yourself and your organization by starting your scoping efforts from the top.

To schedule a CMMC Level 2 Certication Assessment, reach out to us at [email protected] or visit https://lnkd.in/e8sM_2Z3

Explore our latest insights on CMMC and more—check out our homepage here: https://peakinfosec.com. Don't miss episodes of 'As the CMMC Churns' for in-depth discussions:
https://lnkd.in/eVGYGs3g

===============================================
Peak InfoSec Homepage: https://peakinfosec.com
As the CMMC Churns Episodes: https://lnkd.in/eVGYGs3g
Contact Peak InfoSec for Support: https://lnkd.in/e8sM_2Z3
Email: [email protected]
===============================================

Name
What is your Job Title?
Is there a service we offer you would like more information about? (optional)