Cyber-Circuits-Essential-CMMC-QA.pdf

PDF 150 KB Posted

Attached to
DEHUMIDIFIER Federal contract opportunity
Solicitation number
SPMYM221Q0376
Issued by
Defense Logistics Agency Land and Maritime

View the file

Other files for this federal contract opportunity

Other files attached to DEHUMIDIFIER, newest first.
File Type Posted
21-Q-0376U0002.pdf PDF
NIST SP 800-171 Frequently Asked Questions.pdf PDF
NIST SP 800-171 Assessment Methodology Version 1.2.1_24 June 2020.pdf PDF
21-Q-0376U0001.pdf PDF
21-Q-0376.pdf PDF
CDRLS.pdf PDF
SOW.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Is Project Spectrum a vendor that provides cybersecurity services to Department of Defense (DoD) supply chain vendors?

Project Spectrum is a nonprofit effort funded by the DoD Office of Small Business Programs to help educate the Defense Industrial Base (DIB) on compliance. We are vendor-neutral and are here to assist you with your cybersecurity and compliance needs.

Which resources does Project Spectrum provide contractors to assist with interpreting the NIST SP 800-171 and CMMC requirements?

We provide tailored answers to questions on our community forum. We are also compiling reviews of compliant products and developing a CMMC implementation course that covers each practice to help you understand the compliance requirements.

Where can we discuss whether our solution to a control is adequate?

Visit the Project Spectrum community forum, consult a Registered Provider Organization (RPO; when available), and conduct online research. For example, when looking for encryption with CMMC/NIST SP 800-171, you will need a FIPS-compliant provider. Project Spectrum also recommends seeking FedRAMP Moderate+ providers, which can often work for CMMC/NIST SP 800-171 compliance.

When are we required to upload our NIST SP 800-171 self-assessment to the Supplier Performance Risk System (SPRS)?

The new Defense Federal Acquisition Regulation Supplement (DFARS) interim rule explaining how to upload the basic assessment into the Supplier Performance Risk System (SPRS) has an associated date of December 1, 2020.

Is there a sample assessment available to allow contractors to review their systems before submitting on the Supplier Performance Risk System (SPRS)?

Yes, please register for a free account at projectspectrum.io and complete the NIST SP 800-171 cyber readiness check. Your score will be available when you submit the assessment. You can continue to self-assess as you make adjustments.

projectspectrum.io https://community.projectspectrum.io/ https://projectspectrum.io/#!/reviews https://community.projectspectrum.io/ https://projectspectrum.io/#!/register projectspectrum.io

How do I provide my system security plan (SSP) while reporting my self-assessment score in the Supplier Performance Risk System (SPRS)?

Please review Annex B of the NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1, June 24, 2020 for information required to enter your results from a Basic NIST SP 800-171 DoD Assessment into SPRS. Per the guidance, requirements include assessment date, assessment score, assessment scope, and plan of action completion date. There is no prescribed format or specified level of detail for system security plans.

However, organizations ensure that the required information in [SP 800-171 Requirement] 3.12.4 is conveyed in those plans.

Does being CMMC certified make you NIST SP 800-171 compliant?

CMMC Level 3 requirements encompass the full NIST SP 800-171 requirements. If you earn CMMC Level 3 certification, you should also be NIST SP 800-171 compliant;

however, the NIST and CMMC audit and compliance authorities are currently separate.

How do the scores for NIST SP 800-171 and CMMC Levels 1 and 2 equate?

CMMC is its own standard that incorporates elements of NIST SP 800-171 with additional federal requirements and industry best practices. Project Spectrum recommends treating CMMC and NIST SP 800-171 as separate standards. Self-assessment tools for one may not match the other.

If you are CMMC Level 1 certified, do you need to comply with 17 practices or the 110 NIST SP 800-171 controls?

You would need just the 17 practices. The lower requirement is because you are not handling CUI.

When will there be harmonization of CMMC Levels 4 and 5 with the a la carte selection of requirements defined in NIST SP 800-172?

There is currently no clear answer. Feel free to ask about this on the Project Spectrum community forum, and we will share any updates we have.

When will the Department of Defense (DoD) post what auditors expect for CMMC Levels 1 and 3?

The official assessment guide is in draft form. A final version is slated to be released before the end of 2020.

Will the CMMC update affect Surface Deployment and Distribution Command (SDDC) business and General Services Administration (GSA) business?

It depends on the contracts and their requirements. GSA in the recent STARS III contract used CMMC wording, but the organization has not signed on to using CMMC.

Project Spectrum recommends that you speak with your contract manager(s) or POCs.

https://www.acq.osd.mil/dpap/pdi/cyber/docs/NIST%20SP%20800-171%20Assessment%20Methodology%20Version%201.2.1%20%206.24.2020.pdf https://www.acq.osd.mil/dpap/pdi/cyber/docs/NIST%20SP%20800-171%20Assessment%20Methodology%20Version%201.2.1%20%206.24.2020.pdf https://community.projectspectrum.io/

Does the Defense Federal Acquisition Regulation Supplement (DFARS) 252.204- 7012 definition of Controlled Technical Information mean that any document not marked with Distribution Statement A (i.e., releasable to the public) in accordance with DoD Instruction (DoDI) 5230.24 must be maintained on an information system capable of providing adequate security, which includes the implementation of NIST SP 800-171?

The DFARS clause and DoDI are addressed in the CUI Registry under the category Controlled Technical Information. In addition to being compliant with the aforementioned, the broader issue of CMMC compliance addresses the ambiguity around the term "adequate security," because many industry best practices are included in the CMMC. This design was specifically to minimize the guesswork in security. By focusing on CMMC implementation, you are essentially providing adequate security.

Can you give real-world examples of Federal Contract Information (FCI)?

On a penetration testing contract, commercial off-the-shelf and applications used by government clients can be FCI.

Where can we find examples of Federal Contract Information (FCI) that may need CMMC Level 1?

Look for what the DoD contracts require. Authorized holders determine what is and isn’t FCI/CUI/Classified. Authorized holder is an individual, agency, organization, or group of users that is permitted to designate or handle CUI, in accordance with 32 CFR Part 2002. From CFR Part 2002, "Designating agencies must mark CUI at the time they designate the information as CUI."

The applications one organization uses might be FCI, while those same applications used by another organization may be classified.

Can Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) be comingled on the same network?

Yes, but only on a network at the appropriate level. If your organization handles CUI at CMMC Level 3, you can store non-CUI FCI on your network because you are meeting higher compliance requirements than CMMC Level 1. You can work a CMMC Level 1 contract on a CMMC Level 5 certified network. However, not the opposite.

How can we determine if contractor-generated information is Controlled Unclassified Information (CUI)?

The DoD determines whether data is or contains CUI.

Is the end customer part number considered Controlled Unclassified Information (CUI), e.g., 68A12345-1 or 74A98765-2?

This depends on the customer, the specific part, and the CUI category. For example, Naval Nuclear Propulsion Information has relatively stricter safeguarding and dissemination controls than CUI categories that include only basic. The Project Spectrum CUI for Contractors course explains how to use the CUI Registry to research specific categories and their associated markings.

We believe a few Controlled Unclassified Information (CUI) practices are not applicable to our organization. How do we mark a practice N/A?

Typically, something becomes N/A if the threat vector is eliminated. For example, do you not use Wi-Fi (802.11) at your organization, you do not need to prove compliance with WPA2 encryption? State how you eliminated the threat vector and why it is not applicable.

When can we expect certified third-party assessor organization (C3PAO) training and accreditation to begin?

C3PAO applications are being processed, so there should be an update soon. One hundred provisional assessors have been trained and will be certified to perform assessments until the formal training through licensed training providers (LTPs) is expected to begin in 1Q21.

What does it cost to attend the public CMMC Accreditation Body (CMMC-AB) certified professional class, which is required for the CMMC-AB certified professional journey track?

The cost of the training will be determined by licensed training providers (LTPs) on the open market.

How can we join cohort programs for CMMC trainers/assessors?

Students were selected randomly from a large pool of qualified applicants. There are no more slots open for this training.

Can properly certified individuals support both registered provider organizations (RPOs) and certified third-party assessor organizations (C3PAOs)? Can you explain the conflicts of interest between the RPO, C3PAO, and any other company certifications?

Individuals can offer any support they are qualified to provide. The CMMC-AB will enforce only the following points:

• A CMMC-AB certified assessor (CA) must lead an assessment for score of an organization seeking certification (OSC).

• The CA must be hired (either through W2 or 1099) by a C3PAO when performing said assessments.

• If a CA or C3PAO has consulted or supported an OSC in preparing for an assessment, that same individual or company (or the same individual through a different company) cannot also perform the formal assessment for the same

OSC.

How will companies with 100% remote employees be assessed?

The CMMC-AB is exploring virtual assessment methods and will announce them after finalizing the assessment methodology.

How will small businesses that comprise one person working from home be assessed?

They will be assessed the same as organizations with a more traditional office/industrial setting at the appropriate CMMC level; however, remember that compliance means threat vectors have been eliminated or mitigated to an acceptable baseline by the compliance organization.

Take the physical protection requirements as an example. If you handle Federal Contract Information (FCI) and print FCI data, where are you storing it? How are you disposing of it? Do you have a home office with a lockable drawer? Do you have a roster of people who have keys to that office and drawer? Do you ever physically meet people in your home? If so, you will need a visitor sign in/sign out to log visitors.

The smaller the organization, the easier the controls are to implement. A single person with several machines could outsource some of his requirements with SaaS solutions and cloud storage solutions. Keep in mind that during the COVID-19 pandemic, this is a major issue for organizations with remote employees. Remote work requires additional mitigations, such as virtual private networks (VPNs) and ensuring WPA3 encryption for those using their home Wi-Fi network.

How does COVID-19 affect the required controls as employees work remotely and access company data via internet service providers (ISPs)?

Remote work has opened threat vectors requiring mitigations to remain compliant.

Some of them include ensuring employees are using VPNs to keep them on the compliant company network instead of their own, ensuring they are either using WPA2 encryption on their home Wi-Fi or requiring them to plug in, ensuring FIPS-compliant full disk encryption (FDE) device solutions to mitigate physical security being decentralized, and using cloud solutions to keep CUI/FCI off employees’ home networks.

When using cloud providers, are we expected to use a FedRAMP-certified provider?

Although not required, FedRAMP Moderate solutions are a good baseline for solutions compatible with CMMC. Solutions that are NIST SP 800-171 compliant can work.

Remember that many solutions can work but not out-of-the-box, meaning you will have to configure them. Many vendor solutions are pre-set with most of those configurations, so you can use a non-FedRAMP provider. In both cases, you will need to explain why the solution is compliant.

Are there commercial off-the-shelf (COTS) services such as Amazon Web Services (AWS) or Azure that are providing the lion's share of the hardware/software needed for CMMC?

Public cloud service providers offer compliance guidance to complement their services. While AWS, Azure, Microsoft, and Google provide blueprints to obtain NIST SP 800-171 compliance (nearly CMMC Level 3), cloud subscribers are still responsible for ensuring their exact cloud architecture is specifically covered by their cloud service provider. In some instances, the subscriber is still responsible for achieving compliance.

If a cloud system is CMMC-certified at Level 3, is each virtual enclave in the cloud certified, or does each enclave require a separate certification?

You can certify whole networks or enclaves. You don't need to certify enclaves separately; you just need to show in the same assessment that they are compliant if you want them certified.

A situation in which a system or application receives protection from controls (or portions of controls) that are developed, implemented, assessed, authorized, and monitored by entities other than those responsible for the system or application;

entities either internal or external to the organization where the system or application resides.

https://docs.microsoft.com/en-us/microsoft-365/compliance/offering-nist-sp-800-171?view=o365-worldwide%20%20https://aws.amazon.com/blogs/security/need-nist-compliance-in-the-aws-cloud-aws-compliance-has-you-covered-nist-800-171/ https://cloud.google.com/security/compliance/nist800-171

With a fixed fee contract, how can we recover costs associated with CMMC Level 3 compliance?

Compliance is part of the cost of doing business. Calculate your return on investment (ROI) for cybersecurity and determine if it is economical.

How do you recommend companies with just one or two employees handle CMMC and NIST SP 800-171 compliance?

That depends on your organization's needs. The smaller the organization, the easier compliance typically is to achieve. To continue working remotely, you need a compliant cloud/email solution and must find COTS solutions for everything from FDE to multifactor authentication (MFA). Project Spectrum has a growing tool review page that can help you find compliant solutions depending on your level. You may also look at FedRAMP Moderate+ solutions, as they typically fit.

File details come from the government source that posted it. Updated .