CMMC Certification

ControlCase
ControlCaseControlCase
WEBINAR:
CMMC CERTIFICATION
YOUR IT COMPLIANCE PARTNER –
GO BEYOND THE CHECKLIST
Download CMMC Compliance Checklist
CMMC Compliance Blog
Schedule CMMC Compliance Discussion
ControlCase Introduction
What is CMMC?
Who does CMMC apply to?
What is the CMMC accreditation body (CMMC-AB)?
What is a CMMC Third-Party Organization (C3PAO)?
What does CMMC mean for cybersecurity?
What are the CMMC certification levels?
How often is CMMC needed?
CMMC and NIST
What is the CMMC Assessment process?
Why ControlCase?
Agenda
© 2021 ControlCase. All Rights Reserved. 2
1
2
3
4
5
6
7
8
9
10
11
CONTROLCASE INTRODUCTION
1
© 2021 ControlCase. All Rights Reserved. 3
ControlCase Snapshot
© 2021 ControlCase. All Rights Reserved. 4
CERTIFICATION AND CONTINUOUS COMPLIANCE SERVICES
Go beyond the auditor’s checklist to:
Dramatically cut the time, cost and burden from becoming certified and maintaining IT compliance.
• Demonstrate compliance more efficiently
and cost effectively (cost certainty)
• Improve efficiencies
⁃ Do more with less resources and gain
compliance peace of mind
• Free up your internal resources to focus
on their priorities
• Offload much of the compliance burden to
a trusted compliance partner
1,000+ 275+
10,000+
CLIENTS IT SECURITY
CERTIFICATIONS
SECURITY
EXPERTS
Solution
© 2021 ControlCase. All Rights Reserved. 5
Certification and Continuous Compliance Services
“I’ve worked on both sides of
auditing. I have not seen any other
firm deliver the same product and
service with the same value. No
other firm provides that continuous
improvement and the level of detail
and responsiveness.
— Security and Compliance Manager,
Data Center
Certification Services
© 2021 ControlCase. All Rights Reserved. 6
One Audit™
Assess Once. Comply to Many. “You have 27 seconds to make a first
impression. And after our initial
meeting, it became clear that they
were more interested in helping
our business and building a
relationship, not just getting the
business.
— Sr. Director, Information Risk & Compliance,
Leading Government Contractor
CMMC RPO ISO 27001
& 27002
SOC 1,2,3 & SOC
for Cybersecurity
HITRUST CSF
HIPAA PCI DSS GDPR NIST 800-53
PCI PIN PCI PA-DSS FedRAMP PCI 3DS
WHAT IS CMMC?
2
© 2021 ControlCase. All Rights Reserved. 7
Cybersecurity Maturity Model Certification (CMMC)
CMMC is a unifying standard for the
implementation of cybersecurity across
the Defense Industrial Base (DIB).
Released by the US Department of
Defense (DoD) and became effective
November 30th, 2020.
CMMC aims to standardize and improve
cybersecurity practices within the
Defense Department and Defense
Industrial Base (DIB) ecosystem.
CMMC ensures that DIB companies
implement appropriate cybersecurity
practices and processes to protect
Federal Contract Information (FCI) and
Controlled Unclassified Information
(CUI) within their unclassified networks.
What is CMMC?
© 2021 ControlCase. All Rights Reserved. 8
CUI refers to sensitive information that laws, Federal regulations, or Government-wide
policies require or permit executive branch agencies to protect.
Information the
Government creates
or possesses.
Information an entity
creates or possesses
for or on behalf of
the Government.
What is Controlled Unclassified Information (CUI)?
© 2021 ControlCase. All Rights Reserved. 9
WHO DOES CMMC APPLY TO?
3
© 2021 ControlCase. All Rights Reserved. 10
Who does CMMC apply to?
© 2021 ControlCase. All Rights Reserved. 11
Defense Industrial Base (DIB)
contractors
whose unclassified
networks possess,
store, or transmit Controlled
Unclassified Information (CUI).
Defense Industrial Base (DIB)
contractors whose unclassified
networks possess Federal
Contract Information (FCI).
WHAT IS THE CMMC
ACCREDITATION BODY (CMMC-AB)?
4
© 2021 ControlCase. All Rights Reserved. 12
What is CMMC Accreditation Body (CMMC-AB)?
© 2021 ControlCase. All Rights Reserved. 13
Independent
organization
authorized to
operationalize
CMMC in
accordance with
the US Department
of Defense
requirements.
Authorizes and
Accredits CMMC
Third Party
Assessment
Organizations
(C3PAOs).
Authorizes and
Accredits CMMC
Assessors and
Instructors
Certification
Organizations
(CAICO).
WHAT IS A CMMC THIRD-PARTY
ORGANIZATION (C3PAO)?
5
© 2021 ControlCase. All Rights Reserved. 14
What is a CMMC Third-Party Organization (C3PAO)?
© 2021 ControlCase. All Rights Reserved. 15
Conduct CMMC
assessments and issue
CMMC certificates based on
the results of the
assessments.
Accredited C3PAOs must
meet all DoD requirements
and achieve full compliance
with ISO/IEC 17020.
WHAT DOES CMMC MEAN
FOR CYBERSECURITY?
6
© 2021 ControlCase. All Rights Reserved. 16
What does CMMC mean for cybersecurity?
© 2021 ControlCase. All Rights Reserved. 17
CMMC enforces the Defense Federal Acquisition Regulation
Supplement (DFARS) and National Institute of Standards and Technology (NIST)
frameworks by requiring every contractor to be audited by an independent
third-party auditor or CMMC Third-Party Assessment Organization (C3PAO).
WHAT ARE THE CMMC
CERTIFICATION LEVELS?
7
© 2021 ControlCase. All Rights Reserved. 18
Cybersecurity Maturity Model Certification (CMMC)
There are 5 levels, each with
associated controls and processes.
The level of the CMMC certificate is
dependent upon the type and nature of
information
flowed down from your prime contractor.
The DoD will specify the required CMMC
level in Requests for Information (RFIs)
and Requests for Proposals (RFPs).
CMMC MATURITY LEVELS
© 2021 ControlCase. All Rights Reserved. 19
What are the CMMC Levels?
LEVEL 1
Basic Cyber Hygiene
LEVEL 2
Intermediate Cyber
Hygiene
LEVEL 3
Good Cyber Hygiene
LEVEL 4
Proactive
LEVEL 5
Advanced/Progressive
© 2021 ControlCase. All Rights Reserved. 20
Processes: Performed Documented Managed Reviewed Optimizing
Equivalent to all practices in
Federal Acquisition
Regulation (FAR) 48 CFR
52.204-21
17 Practices 130 Practices
• Comply with the FAR
• Encompasses all
practices from NIST SP
800-171 r1
• Includes an additional
20 practices to support
good cyber hygiene
72 Practices 156 Practices 171 Practices
• Comply with the FAR
• Includes a subset of 48
practices from the NIST
SP 800-171 r1
• Includes an additional 7
practices to support
intermediate cyber
hygiene
• Comply with the FAR
• Encompasses all
practices from NIST SP
800-171 r1
• Includes a subset of 11
practices from NIST SP
800-171B
• Includes an additional
15 practices to
demonstrate a
proactive cybersecurity
program
• Comply with the FAR
• Encompasses all
practices from NIST SP
800-171 r1
• Includes a subset of 15
practices from NIST SP
800-171B
• Includes an additional
11 practices to
demonstrate an
advanced cybersecurity
program
HOW OFTEN IS CMMC NEEDED?
8
© 2021 ControlCase. All Rights Reserved. 21
How often is CMMC needed?
© 2021 ControlCase. All Rights Reserved. 22
A CMMC certificate is valid for
3 years
CMMC AND NIST
9
© 2021 ControlCase. All Rights Reserved. 23
CMMC and NIST
© 2021 ControlCase. All Rights Reserved. 24
CMMC Level 3 includes the 110 security requirements specified in NIST SP 800-171.
The CMMC Model also incorporates additional practices and processes from other standards;
• NIST SP 800-53
• Aerospace Industries Association (AIA)
• National Aerospace Standard (NAS) 9933 “Critical Security Controls for Effective Capability in
Cyber Defense”, and
• Computer Emergency Response Team (CERT)
• Resilience Management Model (RMM)
NIST 800-171 Control Domains
110 security requirements broken down into 14 control families taken from FIPS 200 and NIST 800-53:
:
© 2020 ControlCase. All Rights Reserved. 25
Access Control Identification & Authentication Physical Protection Security Assessment
Audit & Accountability Incident Response Personnel Security
System & Communications
Protection
Awareness & Training Maintenance
Risk
Assessment
Systems & Information Integrity
Configuration Management Media Protection
WHAT IS THE CMMC
ASSESSMENT PROCESS
10
© 2021 ControlCase. All Rights Reserved. 26
ControlCase CMMC Consulting Process
© 2021 ControlCase. All Rights Reserved. 27
Remediate
Design Assess
ControlCase is an Approved CMMC Registered
Provider Organization (RPO)
COMPLETED BY C3PAO
1
CMMC CONSULTING ASSESSMENT
2
PHASE 1
Identify the applicable
CMMC
PHASE 2
CMMC Gap Assessment
DELIVERABLES
CMMC Gap Assessment
Report
ControlCase Methodology for CMMC Consulting
© 2021 ControlCase. All Rights Reserved. 28
1 2 3
WHY CONTROLCASE?
11
© 2021 ControlCase. All Rights Reserved. 29
One Audit™
© 2021 ControlCase. All Rights Reserved. 30
CMMC RPO CCPA SOC 1,2,3 & SOC
for Cybersecurity
ISO 27001
& 27002
HIPAA FedRAMP
NIST CSF PCI PIN PCI PA-DSS CSA STAR Microsoft SSPA
Assess Once. Comply to Many.
PCI DSS
ControlCase Compliance Hub
© 2021 ControlCase. All Rights Reserved. 31
Automated
Compliance
Engine
(ACE)
• Collect evidence such
as configurations
remotely.
ControlCase
Data Discovery
(CDD)
• Scan end user
workstations for PII.
Vulnerability
Assessment &
Penetration Testing
(VAPT)
• Perform remote
vulnerability scans and
penetration tests.
Automated Log
Analysis
(LOGS)
• Review log settings
and identify missing
logs remotely.
Continuous Compliance Services
ControlCase Addresses Common non-compliant situations that may leave you vulnerable:
© 2021 ControlCase. All Rights Reserved. 32
In-scope assets
not reporting logs
In-scope assets missed
from vulnerability scans
Critical, overlooked
vulnerabilities due to volume
Risky firewall rule sets
go undetected
Non-compliant user access
scenarios not flagged
FEATURE: Package 1 - With Cybersecurity Services* Package 2 - Without Cybersecurity Services*
Quarterly Review of 15 to 25 Compliance Questions ✓ ✓
Quarterly Review of Scope ✓ ✓
Collecting & Analyzing Data through connectors from client systems — ✓
Vulnerability Assessment ✓ —
Penetration Testing ✓ —
Sensitive Data Discovery ✓ —
Firewall Ruleset Review ✓ —
Security Awareness Training ✓ —
Logging & Automated Alerting ✓ —
* Hybrid package can be selected.
Summary – Why ControlCase
© 2021 ControlCase. All Rights Reserved. 33
“They provide excellent service,
expertise and technology. And,
the visibility into my compliance
throughout the year and during
the audit process provide a lot
of value to us.
— Dir. of Compliance,
SaaS company
THANK YOU FOR THE OPPORTUNITY
TO CONTRIBUTE TO YOUR IT
COMPLIANCE PROGRAM.
www.controlcase.com
contact@controlcase.com
Download CMMC Compliance Checklist
CMMC Compliance Blog
Schedule CMMC Compliance Discussion
1 sur 34

Recommandé

CMMC 2.0 Explained: Impact for SMBs par
CMMC 2.0 Explained:  Impact for SMBsCMMC 2.0 Explained:  Impact for SMBs
CMMC 2.0 Explained: Impact for SMBsIgnyte Assurance Platform
261 vues24 diapositives
SOC2 Intro and Mindfulness par
SOC2 Intro and MindfulnessSOC2 Intro and Mindfulness
SOC2 Intro and MindfulnessEmilyGladstoneCole
96 vues24 diapositives
Auditing SOX ITGC Compliance par
Auditing SOX ITGC ComplianceAuditing SOX ITGC Compliance
Auditing SOX ITGC Complianceseanpizzy
484 vues21 diapositives
SOC 2 and You par
SOC 2 and YouSOC 2 and You
SOC 2 and YouSchellman & Company
3.8K vues42 diapositives
IT General Controls par
IT General ControlsIT General Controls
IT General ControlsCicero Ray Rufino
3.1K vues14 diapositives
IT System & Security Audit par
IT System & Security AuditIT System & Security Audit
IT System & Security AuditMufaddal Nullwala
1.8K vues29 diapositives

Contenu connexe

Tendances

ISO 27001 How to use the ISMS Implementation Toolkit.pdf par
ISO 27001 How to use the ISMS Implementation Toolkit.pdfISO 27001 How to use the ISMS Implementation Toolkit.pdf
ISO 27001 How to use the ISMS Implementation Toolkit.pdfAndrey Prozorov, CISM, CIPP/E, CDPSE. LA 27001
224 vues60 diapositives
Iso 27001 in images - sample slides from different levels of training, e.g. F... par
Iso 27001 in images - sample slides from different levels of training, e.g. F...Iso 27001 in images - sample slides from different levels of training, e.g. F...
Iso 27001 in images - sample slides from different levels of training, e.g. F...Stratos Lazaridis
333 vues32 diapositives
Overview of ISO 27001 ISMS par
Overview of ISO 27001 ISMSOverview of ISO 27001 ISMS
Overview of ISO 27001 ISMSAkhil Garg
1.5K vues33 diapositives
Information Systems Audit & CISA Prep 2010 par
Information Systems Audit & CISA Prep 2010Information Systems Audit & CISA Prep 2010
Information Systems Audit & CISA Prep 2010Donald E. Hester
2.9K vues98 diapositives
Webinar - CMMC Certification.pptx par
Webinar - CMMC Certification.pptxWebinar - CMMC Certification.pptx
Webinar - CMMC Certification.pptxControlCase
632 vues36 diapositives
CSA STAR Program par
CSA STAR ProgramCSA STAR Program
CSA STAR ProgramSchellman & Company
1.4K vues32 diapositives

Tendances(20)

Iso 27001 in images - sample slides from different levels of training, e.g. F... par Stratos Lazaridis
Iso 27001 in images - sample slides from different levels of training, e.g. F...Iso 27001 in images - sample slides from different levels of training, e.g. F...
Iso 27001 in images - sample slides from different levels of training, e.g. F...
Overview of ISO 27001 ISMS par Akhil Garg
Overview of ISO 27001 ISMSOverview of ISO 27001 ISMS
Overview of ISO 27001 ISMS
Akhil Garg1.5K vues
Information Systems Audit & CISA Prep 2010 par Donald E. Hester
Information Systems Audit & CISA Prep 2010Information Systems Audit & CISA Prep 2010
Information Systems Audit & CISA Prep 2010
Donald E. Hester2.9K vues
Webinar - CMMC Certification.pptx par ControlCase
Webinar - CMMC Certification.pptxWebinar - CMMC Certification.pptx
Webinar - CMMC Certification.pptx
ControlCase632 vues
Audit Sample Report par Randy James
Audit Sample ReportAudit Sample Report
Audit Sample Report
Randy James8.2K vues
2022-Q2-Webinar-ISO_Spanish_Final.pdf par ControlCase
2022-Q2-Webinar-ISO_Spanish_Final.pdf2022-Q2-Webinar-ISO_Spanish_Final.pdf
2022-Q2-Webinar-ISO_Spanish_Final.pdf
ControlCase388 vues
ITGC audit of ERPs par Jayesh Daga
ITGC audit of ERPsITGC audit of ERPs
ITGC audit of ERPs
Jayesh Daga1.6K vues
Top management role to implement ISO 27001 par PECB
Top management role to implement ISO 27001Top management role to implement ISO 27001
Top management role to implement ISO 27001
PECB 4.4K vues
PCI DSS Compliance Checklist par ControlCase
PCI DSS Compliance ChecklistPCI DSS Compliance Checklist
PCI DSS Compliance Checklist
ControlCase1.2K vues
Project plan for ISO 27001 par technakama
Project plan for ISO 27001Project plan for ISO 27001
Project plan for ISO 27001
technakama4.5K vues
Basics in IT Audit and Application Control Testing par Dinesh O Bareja
Basics in IT Audit and Application Control Testing Basics in IT Audit and Application Control Testing
Basics in IT Audit and Application Control Testing
Dinesh O Bareja4.5K vues
It audit methodologies par Salih Islam
It audit methodologiesIt audit methodologies
It audit methodologies
Salih Islam4.4K vues
IT Audit methodologies par genetics
IT Audit methodologiesIT Audit methodologies
IT Audit methodologies
genetics6.6K vues

Similaire à CMMC Certification

DFARS CMMC SPRS NIST 800-171 Explainer.pdf par
DFARS CMMC SPRS NIST 800-171 Explainer.pdfDFARS CMMC SPRS NIST 800-171 Explainer.pdf
DFARS CMMC SPRS NIST 800-171 Explainer.pdfControlCase
72 vues29 diapositives
How I Woke Up from the CMMC Compliance Nightmare par
How I Woke Up from the CMMC Compliance NightmareHow I Woke Up from the CMMC Compliance Nightmare
How I Woke Up from the CMMC Compliance NightmareIgnyte Assurance Platform
232 vues27 diapositives
MCGlobalTech CMMC Managed Compliance Service par
MCGlobalTech CMMC Managed Compliance ServiceMCGlobalTech CMMC Managed Compliance Service
MCGlobalTech CMMC Managed Compliance ServiceWilliam McBorrough
672 vues29 diapositives
CMMC DFARS/NIST SP 800-171 par
CMMC DFARS/NIST SP 800-171 CMMC DFARS/NIST SP 800-171
CMMC DFARS/NIST SP 800-171 Ignyte Assurance Platform
203 vues17 diapositives
A Clear Path to NIST & CMMC Compliance - 2023 Cleveland Security Summit.pdf par
A Clear Path to NIST & CMMC Compliance - 2023 Cleveland Security Summit.pdfA Clear Path to NIST & CMMC Compliance - 2023 Cleveland Security Summit.pdf
A Clear Path to NIST & CMMC Compliance - 2023 Cleveland Security Summit.pdfJack Nichelson
21 vues24 diapositives
Cybersecurity Maturity Model Certification par
Cybersecurity Maturity Model CertificationCybersecurity Maturity Model Certification
Cybersecurity Maturity Model CertificationMurray Security Services
247 vues20 diapositives

Similaire à CMMC Certification(20)

DFARS CMMC SPRS NIST 800-171 Explainer.pdf par ControlCase
DFARS CMMC SPRS NIST 800-171 Explainer.pdfDFARS CMMC SPRS NIST 800-171 Explainer.pdf
DFARS CMMC SPRS NIST 800-171 Explainer.pdf
ControlCase72 vues
A Clear Path to NIST & CMMC Compliance - 2023 Cleveland Security Summit.pdf par Jack Nichelson
A Clear Path to NIST & CMMC Compliance - 2023 Cleveland Security Summit.pdfA Clear Path to NIST & CMMC Compliance - 2023 Cleveland Security Summit.pdf
A Clear Path to NIST & CMMC Compliance - 2023 Cleveland Security Summit.pdf
Jack Nichelson21 vues
Cybersecurity Maturity Model Certification (CMMC) par Robert E Jones
Cybersecurity Maturity Model Certification (CMMC)Cybersecurity Maturity Model Certification (CMMC)
Cybersecurity Maturity Model Certification (CMMC)
Robert E Jones250 vues
PCI DSS Compliance in the Cloud par ControlCase
PCI DSS Compliance in the CloudPCI DSS Compliance in the Cloud
PCI DSS Compliance in the Cloud
ControlCase565 vues
A Clear Path to NIST & CMMC Compliance_ISSA.pptx par Jack Nichelson
A Clear Path to NIST & CMMC Compliance_ISSA.pptxA Clear Path to NIST & CMMC Compliance_ISSA.pptx
A Clear Path to NIST & CMMC Compliance_ISSA.pptx
Jack Nichelson325 vues
OneAudit™ - Assess Once, Certify to Many par ControlCase
OneAudit™ - Assess Once, Certify to ManyOneAudit™ - Assess Once, Certify to Many
OneAudit™ - Assess Once, Certify to Many
ControlCase704 vues
Webinar: Critical Steps For NIST Compliance par Withum
Webinar: Critical Steps For NIST ComplianceWebinar: Critical Steps For NIST Compliance
Webinar: Critical Steps For NIST Compliance
Withum211 vues
Leveraging compliance to raise the bar on security par Mike Lemire
Leveraging compliance to raise the bar on securityLeveraging compliance to raise the bar on security
Leveraging compliance to raise the bar on security
Mike Lemire531 vues
Managing Multiple Assessments Using Zero Trust Principles par ControlCase
Managing Multiple Assessments Using Zero Trust PrinciplesManaging Multiple Assessments Using Zero Trust Principles
Managing Multiple Assessments Using Zero Trust Principles
ControlCase260 vues
EPISODE 1 | Security Wars: A New Goal: CMMC Compliance & Department of Defens... par Rea & Associates
EPISODE 1 | Security Wars: A New Goal: CMMC Compliance & Department of Defens...EPISODE 1 | Security Wars: A New Goal: CMMC Compliance & Department of Defens...
EPISODE 1 | Security Wars: A New Goal: CMMC Compliance & Department of Defens...
Performing One Audit Using Zero Trust Principles par ControlCase
Performing One Audit Using Zero Trust PrinciplesPerforming One Audit Using Zero Trust Principles
Performing One Audit Using Zero Trust Principles
ControlCase375 vues
FedRAMP Certification & FedRAMP Marketplace par ControlCase
FedRAMP Certification & FedRAMP MarketplaceFedRAMP Certification & FedRAMP Marketplace
FedRAMP Certification & FedRAMP Marketplace
ControlCase1.1K vues

Plus de ControlCase

PCI DSS v4 - ControlCase Update Webinar Final.pdf par
PCI DSS v4 - ControlCase Update Webinar Final.pdfPCI DSS v4 - ControlCase Update Webinar Final.pdf
PCI DSS v4 - ControlCase Update Webinar Final.pdfControlCase
608 vues31 diapositives
ISO 27001 2002 Update Webinar.pdf par
ISO 27001 2002 Update Webinar.pdfISO 27001 2002 Update Webinar.pdf
ISO 27001 2002 Update Webinar.pdfControlCase
1.6K vues31 diapositives
Integrated Compliance Webinar.pptx par
Integrated Compliance Webinar.pptxIntegrated Compliance Webinar.pptx
Integrated Compliance Webinar.pptxControlCase
621 vues30 diapositives
French PCI DSS v4.0 Webinaire.pdf par
French PCI DSS v4.0 Webinaire.pdfFrench PCI DSS v4.0 Webinaire.pdf
French PCI DSS v4.0 Webinaire.pdfControlCase
341 vues35 diapositives
Webinar-MSP+ Cyber Insurance Fina.pptx par
Webinar-MSP+  Cyber Insurance Fina.pptxWebinar-MSP+  Cyber Insurance Fina.pptx
Webinar-MSP+ Cyber Insurance Fina.pptxControlCase
69 vues26 diapositives
2022-Q3-Webinar-PPT-DataProtectionByDesign.pdf par
2022-Q3-Webinar-PPT-DataProtectionByDesign.pdf2022-Q3-Webinar-PPT-DataProtectionByDesign.pdf
2022-Q3-Webinar-PPT-DataProtectionByDesign.pdfControlCase
811 vues27 diapositives

Plus de ControlCase(20)

PCI DSS v4 - ControlCase Update Webinar Final.pdf par ControlCase
PCI DSS v4 - ControlCase Update Webinar Final.pdfPCI DSS v4 - ControlCase Update Webinar Final.pdf
PCI DSS v4 - ControlCase Update Webinar Final.pdf
ControlCase608 vues
ISO 27001 2002 Update Webinar.pdf par ControlCase
ISO 27001 2002 Update Webinar.pdfISO 27001 2002 Update Webinar.pdf
ISO 27001 2002 Update Webinar.pdf
ControlCase1.6K vues
Integrated Compliance Webinar.pptx par ControlCase
Integrated Compliance Webinar.pptxIntegrated Compliance Webinar.pptx
Integrated Compliance Webinar.pptx
ControlCase621 vues
French PCI DSS v4.0 Webinaire.pdf par ControlCase
French PCI DSS v4.0 Webinaire.pdfFrench PCI DSS v4.0 Webinaire.pdf
French PCI DSS v4.0 Webinaire.pdf
ControlCase341 vues
Webinar-MSP+ Cyber Insurance Fina.pptx par ControlCase
Webinar-MSP+  Cyber Insurance Fina.pptxWebinar-MSP+  Cyber Insurance Fina.pptx
Webinar-MSP+ Cyber Insurance Fina.pptx
ControlCase69 vues
2022-Q3-Webinar-PPT-DataProtectionByDesign.pdf par ControlCase
2022-Q3-Webinar-PPT-DataProtectionByDesign.pdf2022-Q3-Webinar-PPT-DataProtectionByDesign.pdf
2022-Q3-Webinar-PPT-DataProtectionByDesign.pdf
ControlCase811 vues
Webinar-Spanish-PCI DSS-4.0.pdf par ControlCase
Webinar-Spanish-PCI DSS-4.0.pdfWebinar-Spanish-PCI DSS-4.0.pdf
Webinar-Spanish-PCI DSS-4.0.pdf
ControlCase596 vues
2022 Webinar - ISO 27001 Certification.pdf par ControlCase
2022 Webinar - ISO 27001 Certification.pdf2022 Webinar - ISO 27001 Certification.pdf
2022 Webinar - ISO 27001 Certification.pdf
ControlCase1.2K vues
HITRUST Certification par ControlCase
HITRUST CertificationHITRUST Certification
HITRUST Certification
ControlCase902 vues
Continuous Compliance Monitoring par ControlCase
Continuous Compliance MonitoringContinuous Compliance Monitoring
Continuous Compliance Monitoring
ControlCase815 vues
Vendor Management for PCI DSS, HIPAA, and FFIEC par ControlCase
Vendor Management for PCI DSS, HIPAA, and FFIECVendor Management for PCI DSS, HIPAA, and FFIEC
Vendor Management for PCI DSS, HIPAA, and FFIEC
ControlCase361 vues
Performing PCI DSS Assessments Using Zero Trust Principles par ControlCase
Performing PCI DSS Assessments Using Zero Trust PrinciplesPerforming PCI DSS Assessments Using Zero Trust Principles
Performing PCI DSS Assessments Using Zero Trust Principles
ControlCase348 vues
PCI DSS Business as Usual par ControlCase
PCI DSS Business as UsualPCI DSS Business as Usual
PCI DSS Business as Usual
ControlCase366 vues
Continuous Compliance Monitoring par ControlCase
Continuous Compliance MonitoringContinuous Compliance Monitoring
Continuous Compliance Monitoring
ControlCase405 vues
Healthcare Compliance: HIPAA and HITRUST par ControlCase
Healthcare Compliance: HIPAA and HITRUSTHealthcare Compliance: HIPAA and HITRUST
Healthcare Compliance: HIPAA and HITRUST
ControlCase487 vues
Integrated Compliance – Collect Evidence Once, Certify to Many par ControlCase
Integrated Compliance – Collect Evidence Once, Certify to ManyIntegrated Compliance – Collect Evidence Once, Certify to Many
Integrated Compliance – Collect Evidence Once, Certify to Many
ControlCase327 vues
ISO 27001 In The Age Of Privacy par ControlCase
ISO 27001 In The Age Of PrivacyISO 27001 In The Age Of Privacy
ISO 27001 In The Age Of Privacy
ControlCase415 vues
PCI DSS and Other Related Updates par ControlCase
PCI DSS and Other Related UpdatesPCI DSS and Other Related Updates
PCI DSS and Other Related Updates
ControlCase161 vues
PCI DSS Business as Usual (BAU) par ControlCase
PCI DSS Business as Usual (BAU)PCI DSS Business as Usual (BAU)
PCI DSS Business as Usual (BAU)
ControlCase171 vues
Continuous Compliance Monitoring par ControlCase
Continuous Compliance MonitoringContinuous Compliance Monitoring
Continuous Compliance Monitoring
ControlCase487 vues

Dernier

MechMaf Shipping LLC par
MechMaf Shipping LLCMechMaf Shipping LLC
MechMaf Shipping LLCMechMaf Shipping LLC
58 vues288 diapositives
sample.potx par
sample.potxsample.potx
sample.potxMaryna Yurchenko
16 vues3 diapositives
davood_keshavarz_david_keshavarz_criminal_conviction_prison_sentence_judgemen... par
davood_keshavarz_david_keshavarz_criminal_conviction_prison_sentence_judgemen...davood_keshavarz_david_keshavarz_criminal_conviction_prison_sentence_judgemen...
davood_keshavarz_david_keshavarz_criminal_conviction_prison_sentence_judgemen...morshedislam3
14 vues5 diapositives
Monthly Social Media Update November 2023 copy.pptx par
Monthly Social Media Update November 2023 copy.pptxMonthly Social Media Update November 2023 copy.pptx
Monthly Social Media Update November 2023 copy.pptxAndy Lambert
19 vues49 diapositives
Basic of Air Ticketing & IATA Geography par
Basic of Air Ticketing & IATA GeographyBasic of Air Ticketing & IATA Geography
Basic of Air Ticketing & IATA GeographyMd Shaifullar Rabbi
59 vues27 diapositives
2023 Photo Contest.pptx par
2023 Photo Contest.pptx2023 Photo Contest.pptx
2023 Photo Contest.pptxculhama
30 vues185 diapositives

Dernier(20)

davood_keshavarz_david_keshavarz_criminal_conviction_prison_sentence_judgemen... par morshedislam3
davood_keshavarz_david_keshavarz_criminal_conviction_prison_sentence_judgemen...davood_keshavarz_david_keshavarz_criminal_conviction_prison_sentence_judgemen...
davood_keshavarz_david_keshavarz_criminal_conviction_prison_sentence_judgemen...
morshedislam314 vues
Monthly Social Media Update November 2023 copy.pptx par Andy Lambert
Monthly Social Media Update November 2023 copy.pptxMonthly Social Media Update November 2023 copy.pptx
Monthly Social Media Update November 2023 copy.pptx
Andy Lambert19 vues
2023 Photo Contest.pptx par culhama
2023 Photo Contest.pptx2023 Photo Contest.pptx
2023 Photo Contest.pptx
culhama30 vues
Navigating EUDR Compliance within the Coffee Industry par Peter Horsten
Navigating EUDR Compliance within the Coffee IndustryNavigating EUDR Compliance within the Coffee Industry
Navigating EUDR Compliance within the Coffee Industry
Peter Horsten43 vues
Bloomerang Thank Yous Dec 2023.pdf par Bloomerang
Bloomerang Thank Yous Dec 2023.pdfBloomerang Thank Yous Dec 2023.pdf
Bloomerang Thank Yous Dec 2023.pdf
Bloomerang106 vues
Top 10 Web Development Companies in California par TopCSSGallery
Top 10 Web Development Companies in CaliforniaTop 10 Web Development Companies in California
Top 10 Web Development Companies in California
TopCSSGallery73 vues
Presentation on proposed acquisition of leading European asset manager Aermon... par KeppelCorporation
Presentation on proposed acquisition of leading European asset manager Aermon...Presentation on proposed acquisition of leading European asset manager Aermon...
Presentation on proposed acquisition of leading European asset manager Aermon...
bookmyshow-1.pptx par 125071035
bookmyshow-1.pptxbookmyshow-1.pptx
bookmyshow-1.pptx
12507103513 vues
See the new MTN tariffs effected November 28, 2023 par Kweku Zurek
See the new MTN tariffs effected November 28, 2023See the new MTN tariffs effected November 28, 2023
See the new MTN tariffs effected November 28, 2023
Kweku Zurek29.5K vues
Assignment 4: Reporting to Management.pptx par BethanyAline
Assignment 4: Reporting to Management.pptxAssignment 4: Reporting to Management.pptx
Assignment 4: Reporting to Management.pptx
BethanyAline18 vues
PMU Launch - Guaranteed Slides par pmulaunch
PMU Launch - Guaranteed SlidesPMU Launch - Guaranteed Slides
PMU Launch - Guaranteed Slides
pmulaunch16 vues

CMMC Certification

  • 1. WEBINAR: CMMC CERTIFICATION YOUR IT COMPLIANCE PARTNER – GO BEYOND THE CHECKLIST Download CMMC Compliance Checklist CMMC Compliance Blog Schedule CMMC Compliance Discussion
  • 2. ControlCase Introduction What is CMMC? Who does CMMC apply to? What is the CMMC accreditation body (CMMC-AB)? What is a CMMC Third-Party Organization (C3PAO)? What does CMMC mean for cybersecurity? What are the CMMC certification levels? How often is CMMC needed? CMMC and NIST What is the CMMC Assessment process? Why ControlCase? Agenda © 2021 ControlCase. All Rights Reserved. 2 1 2 3 4 5 6 7 8 9 10 11
  • 3. CONTROLCASE INTRODUCTION 1 © 2021 ControlCase. All Rights Reserved. 3
  • 4. ControlCase Snapshot © 2021 ControlCase. All Rights Reserved. 4 CERTIFICATION AND CONTINUOUS COMPLIANCE SERVICES Go beyond the auditor’s checklist to: Dramatically cut the time, cost and burden from becoming certified and maintaining IT compliance. • Demonstrate compliance more efficiently and cost effectively (cost certainty) • Improve efficiencies ⁃ Do more with less resources and gain compliance peace of mind • Free up your internal resources to focus on their priorities • Offload much of the compliance burden to a trusted compliance partner 1,000+ 275+ 10,000+ CLIENTS IT SECURITY CERTIFICATIONS SECURITY EXPERTS
  • 5. Solution © 2021 ControlCase. All Rights Reserved. 5 Certification and Continuous Compliance Services “I’ve worked on both sides of auditing. I have not seen any other firm deliver the same product and service with the same value. No other firm provides that continuous improvement and the level of detail and responsiveness. — Security and Compliance Manager, Data Center
  • 6. Certification Services © 2021 ControlCase. All Rights Reserved. 6 One Audit™ Assess Once. Comply to Many. “You have 27 seconds to make a first impression. And after our initial meeting, it became clear that they were more interested in helping our business and building a relationship, not just getting the business. — Sr. Director, Information Risk & Compliance, Leading Government Contractor CMMC RPO ISO 27001 & 27002 SOC 1,2,3 & SOC for Cybersecurity HITRUST CSF HIPAA PCI DSS GDPR NIST 800-53 PCI PIN PCI PA-DSS FedRAMP PCI 3DS
  • 7. WHAT IS CMMC? 2 © 2021 ControlCase. All Rights Reserved. 7
  • 8. Cybersecurity Maturity Model Certification (CMMC) CMMC is a unifying standard for the implementation of cybersecurity across the Defense Industrial Base (DIB). Released by the US Department of Defense (DoD) and became effective November 30th, 2020. CMMC aims to standardize and improve cybersecurity practices within the Defense Department and Defense Industrial Base (DIB) ecosystem. CMMC ensures that DIB companies implement appropriate cybersecurity practices and processes to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) within their unclassified networks. What is CMMC? © 2021 ControlCase. All Rights Reserved. 8
  • 9. CUI refers to sensitive information that laws, Federal regulations, or Government-wide policies require or permit executive branch agencies to protect. Information the Government creates or possesses. Information an entity creates or possesses for or on behalf of the Government. What is Controlled Unclassified Information (CUI)? © 2021 ControlCase. All Rights Reserved. 9
  • 10. WHO DOES CMMC APPLY TO? 3 © 2021 ControlCase. All Rights Reserved. 10
  • 11. Who does CMMC apply to? © 2021 ControlCase. All Rights Reserved. 11 Defense Industrial Base (DIB) contractors whose unclassified networks possess, store, or transmit Controlled Unclassified Information (CUI). Defense Industrial Base (DIB) contractors whose unclassified networks possess Federal Contract Information (FCI).
  • 12. WHAT IS THE CMMC ACCREDITATION BODY (CMMC-AB)? 4 © 2021 ControlCase. All Rights Reserved. 12
  • 13. What is CMMC Accreditation Body (CMMC-AB)? © 2021 ControlCase. All Rights Reserved. 13 Independent organization authorized to operationalize CMMC in accordance with the US Department of Defense requirements. Authorizes and Accredits CMMC Third Party Assessment Organizations (C3PAOs). Authorizes and Accredits CMMC Assessors and Instructors Certification Organizations (CAICO).
  • 14. WHAT IS A CMMC THIRD-PARTY ORGANIZATION (C3PAO)? 5 © 2021 ControlCase. All Rights Reserved. 14
  • 15. What is a CMMC Third-Party Organization (C3PAO)? © 2021 ControlCase. All Rights Reserved. 15 Conduct CMMC assessments and issue CMMC certificates based on the results of the assessments. Accredited C3PAOs must meet all DoD requirements and achieve full compliance with ISO/IEC 17020.
  • 16. WHAT DOES CMMC MEAN FOR CYBERSECURITY? 6 © 2021 ControlCase. All Rights Reserved. 16
  • 17. What does CMMC mean for cybersecurity? © 2021 ControlCase. All Rights Reserved. 17 CMMC enforces the Defense Federal Acquisition Regulation Supplement (DFARS) and National Institute of Standards and Technology (NIST) frameworks by requiring every contractor to be audited by an independent third-party auditor or CMMC Third-Party Assessment Organization (C3PAO).
  • 18. WHAT ARE THE CMMC CERTIFICATION LEVELS? 7 © 2021 ControlCase. All Rights Reserved. 18
  • 19. Cybersecurity Maturity Model Certification (CMMC) There are 5 levels, each with associated controls and processes. The level of the CMMC certificate is dependent upon the type and nature of information flowed down from your prime contractor. The DoD will specify the required CMMC level in Requests for Information (RFIs) and Requests for Proposals (RFPs). CMMC MATURITY LEVELS © 2021 ControlCase. All Rights Reserved. 19
  • 20. What are the CMMC Levels? LEVEL 1 Basic Cyber Hygiene LEVEL 2 Intermediate Cyber Hygiene LEVEL 3 Good Cyber Hygiene LEVEL 4 Proactive LEVEL 5 Advanced/Progressive © 2021 ControlCase. All Rights Reserved. 20 Processes: Performed Documented Managed Reviewed Optimizing Equivalent to all practices in Federal Acquisition Regulation (FAR) 48 CFR 52.204-21 17 Practices 130 Practices • Comply with the FAR • Encompasses all practices from NIST SP 800-171 r1 • Includes an additional 20 practices to support good cyber hygiene 72 Practices 156 Practices 171 Practices • Comply with the FAR • Includes a subset of 48 practices from the NIST SP 800-171 r1 • Includes an additional 7 practices to support intermediate cyber hygiene • Comply with the FAR • Encompasses all practices from NIST SP 800-171 r1 • Includes a subset of 11 practices from NIST SP 800-171B • Includes an additional 15 practices to demonstrate a proactive cybersecurity program • Comply with the FAR • Encompasses all practices from NIST SP 800-171 r1 • Includes a subset of 15 practices from NIST SP 800-171B • Includes an additional 11 practices to demonstrate an advanced cybersecurity program
  • 21. HOW OFTEN IS CMMC NEEDED? 8 © 2021 ControlCase. All Rights Reserved. 21
  • 22. How often is CMMC needed? © 2021 ControlCase. All Rights Reserved. 22 A CMMC certificate is valid for 3 years
  • 23. CMMC AND NIST 9 © 2021 ControlCase. All Rights Reserved. 23
  • 24. CMMC and NIST © 2021 ControlCase. All Rights Reserved. 24 CMMC Level 3 includes the 110 security requirements specified in NIST SP 800-171. The CMMC Model also incorporates additional practices and processes from other standards; • NIST SP 800-53 • Aerospace Industries Association (AIA) • National Aerospace Standard (NAS) 9933 “Critical Security Controls for Effective Capability in Cyber Defense”, and • Computer Emergency Response Team (CERT) • Resilience Management Model (RMM)
  • 25. NIST 800-171 Control Domains 110 security requirements broken down into 14 control families taken from FIPS 200 and NIST 800-53: : © 2020 ControlCase. All Rights Reserved. 25 Access Control Identification & Authentication Physical Protection Security Assessment Audit & Accountability Incident Response Personnel Security System & Communications Protection Awareness & Training Maintenance Risk Assessment Systems & Information Integrity Configuration Management Media Protection
  • 26. WHAT IS THE CMMC ASSESSMENT PROCESS 10 © 2021 ControlCase. All Rights Reserved. 26
  • 27. ControlCase CMMC Consulting Process © 2021 ControlCase. All Rights Reserved. 27 Remediate Design Assess ControlCase is an Approved CMMC Registered Provider Organization (RPO) COMPLETED BY C3PAO 1 CMMC CONSULTING ASSESSMENT 2
  • 28. PHASE 1 Identify the applicable CMMC PHASE 2 CMMC Gap Assessment DELIVERABLES CMMC Gap Assessment Report ControlCase Methodology for CMMC Consulting © 2021 ControlCase. All Rights Reserved. 28 1 2 3
  • 29. WHY CONTROLCASE? 11 © 2021 ControlCase. All Rights Reserved. 29
  • 30. One Audit™ © 2021 ControlCase. All Rights Reserved. 30 CMMC RPO CCPA SOC 1,2,3 & SOC for Cybersecurity ISO 27001 & 27002 HIPAA FedRAMP NIST CSF PCI PIN PCI PA-DSS CSA STAR Microsoft SSPA Assess Once. Comply to Many. PCI DSS
  • 31. ControlCase Compliance Hub © 2021 ControlCase. All Rights Reserved. 31 Automated Compliance Engine (ACE) • Collect evidence such as configurations remotely. ControlCase Data Discovery (CDD) • Scan end user workstations for PII. Vulnerability Assessment & Penetration Testing (VAPT) • Perform remote vulnerability scans and penetration tests. Automated Log Analysis (LOGS) • Review log settings and identify missing logs remotely.
  • 32. Continuous Compliance Services ControlCase Addresses Common non-compliant situations that may leave you vulnerable: © 2021 ControlCase. All Rights Reserved. 32 In-scope assets not reporting logs In-scope assets missed from vulnerability scans Critical, overlooked vulnerabilities due to volume Risky firewall rule sets go undetected Non-compliant user access scenarios not flagged FEATURE: Package 1 - With Cybersecurity Services* Package 2 - Without Cybersecurity Services* Quarterly Review of 15 to 25 Compliance Questions ✓ ✓ Quarterly Review of Scope ✓ ✓ Collecting & Analyzing Data through connectors from client systems — ✓ Vulnerability Assessment ✓ — Penetration Testing ✓ — Sensitive Data Discovery ✓ — Firewall Ruleset Review ✓ — Security Awareness Training ✓ — Logging & Automated Alerting ✓ — * Hybrid package can be selected.
  • 33. Summary – Why ControlCase © 2021 ControlCase. All Rights Reserved. 33 “They provide excellent service, expertise and technology. And, the visibility into my compliance throughout the year and during the audit process provide a lot of value to us. — Dir. of Compliance, SaaS company
  • 34. THANK YOU FOR THE OPPORTUNITY TO CONTRIBUTE TO YOUR IT COMPLIANCE PROGRAM. www.controlcase.com contact@controlcase.com Download CMMC Compliance Checklist CMMC Compliance Blog Schedule CMMC Compliance Discussion

Notes de l'éditeur

  1. Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.
  2. Organizations of all sizes rely on ControlCase’s certification and continuous compliance services to dramatically cut the time, cost and burden out of IT compliance. Unlike traditional consulting firms, we bring a partnership approach versus an auditor mentality to every engagement. We go beyond the checklist and provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate and maintain compliance. Whether you're looking to satisfy regulatory requirements, meet customer demand or establish confidence with prospective customers, with ControlCase as your compliance partner, your workforce will be free to focus on their strategic priorities, and you’ll eliminate the hassle and reduce the stress associated with certification and continuous compliance.