Taking CMMC Seriously - What Is The Cost Of Compliance?

JSchaus & Associates
JSchaus & AssociatesFED Govt Contracts Consulting + 1 - 2 0 2 - 3 6 5 - 0 5 9 8 à JSchaus & Associates
Taking CMMC Seriously:
What is the Cost of
Compliance?
September, 19, 2023
Welcome!
Bill Wootton
Chief Revenue Officer
C3 Integrated Solutions
bwootton@C3isit.com
© 2023 C3 Integrated Solutions. All Rights Reserved.
3
Today’s Topics
▸Overview: Major Components of the Cost of CMMC
▸Building a Strategy
▸Deployment
▸Management and Monitoring
▸Compliance
▸Data Enclaves: Options and Impact
▸Three Types of Companies
Building a Strategy
© 2023 C3 Integrated Solutions. All Rights Reserved.
5
Building Your CMMC Strategy
Understanding
your business
Setting the
system
boundary
Determining the
organizational
impact
Determining
the expertise
you need
© 2023 C3 Integrated Solutions. All Rights Reserved.
6
Understanding Your Business
External Factors Internal Factors
▸ Your Customers…
▸ Which agencies do you work with?
▸ Your Partners…
▸ Who are your primes and subs?
▸ What are THEIR requirements to continue
working with them?
▸ Your Contracts…
▸ What clauses are already in your contracts?
▸ Your Future…
▸ Where will your business be in 2-3 years?
▸ Your Data…
▸ Do you have CUI?
▸ Do you have export-controlled data?
▸ Can you segment it from the rest of the
organization?
▸ Your People…
▸ Who directly interacts with CUI
▸ Who indirectly interacts with CUI?
▸ Your Systems…
▸ Which systems store, process, or transit
data?
The better you know your business, the less you will need a consultant to answer these questions.
© 2023 C3 Integrated Solutions. All Rights Reserved.
7
Company Examples: All 100-Person Firms
Research Firm
• Almost all commercial work
• Single DoD contract
• Team segmented from rest
of the firm
Manufacturing Firm
• Approximately 90% DoD
work
• Highly customized parts for
aircraft
• Large amounts of export-
controlled data
Professional Services
• Many distributed contracts
• Team members rotate
between DoD and civilian work
regularly
• Centralized admin supports all
contracts
Current systems are not compliant. No preexisting certifications (e.g. ISO
9001)
© 2023 C3 Integrated Solutions. All Rights Reserved.
8
Employee Access to CUI (100-person
Company)
????????
90 People 10 people
90 People
10 people
Commercial
Within CUI Boundary
Company 1 – Research
Firm
Company 3 – Professional Services Firm
Company 2 – Manufacturing Firm
© 2023 C3 Integrated Solutions. All Rights Reserved.
9
Determining System Boundaries: Enclave or
All-In?
ENCLAVE
Separate environment isolated
from the corporate environment
ALL-IN
Full configuration of corporate
environment to meet CMMC
requirements
Pros
▸ Reduced investment and scope
▸ Smaller attack surface
▸ More controlled system
boundary
▸ Limited (if any) data migration
Cons
▸ Swivel-seat user impact
▸ Illusion of cost savings
▸ Dual administration
▸ Unintended spillage
Pros
▸ Single, consolidated
environment
▸ Eliminates all technical debt
(fresh start)
Cons
▸ Data migration
▸ User impact
▸ Higher deployment costs
▸ Everyone is “locked down”
▸ Non-approved applications
© 2023 C3 Integrated Solutions. All Rights Reserved.
10
Enclave or All-In?
????????
90 People 10 people
90 People
10 people
Commercial
Within CUI Boundary
Company 1 – Research
Firm
Company 3 – Professional
Services
Company 2 - Manufacturing
Enclave
????
All-in
© 2023 C3 Integrated Solutions. All Rights Reserved.
11
Cost Drivers in Building a Strategy
Drivers Costs
▸ Knowledge of business
▸ Knowledge of data
▸ Current situation
▸ Technical debt
▸ Documentation
▸ Previous investment
▸ Internal resources
▸ Expertise/knowledge
▸ Availability
▸ Direct costs
▸ Outside consultant
▸ Internal effort
▸ Indirect costs
▸ Organization impact beyond IT
⁃ Business process changes
⁃ Segmenting and isolating data in an
enclave
▸ Impact of Strategy
⁃ Determines cost of the rest of the
process
▸ Confidence
▸ Risk of pursuing the wrong approach
Strategy costs are
not directly related to
the size of the
company. In most
cases, the scope of
effort drives the cost
profile.
Deployment
© 2023 C3 Integrated Solutions. All Rights Reserved.
13
Setting the System Boundary
System Boundary System Selection
• Communications
• E-mail
• Unified communications
• Collaboration
• Documents
• Other data
• CRM
• Financial
• Operational technology
• Access
• Virtual desktop
• Physical devices
• Mobile devices
• Cloud v. on-premises
• FedRAMP
• Export control
• US data residency
• US persons
Minimizing the
system boundary
reduces the services
that need to be fully
compliant
© 2023 C3 Integrated Solutions. All Rights Reserved.
14
Technology Costs
▸System selection
criteria
▸Accreditations
▸Attestations
▸Export control
▸GovCloud is
typically at least
30% higher
Commercial GCC GCC High
Data Centers Worldwide US Only US only
Accreditation FedRAMP
Moderate*
FedRAMP
Moderate
FedRAMP High
DFARS 7012 No Yes Yes
ITAR/EAR No No Yes
CUI/CDI No Maybe Yes
Customer
Support
Worldwide/Commercial
Personnel
Directory/Nt
k Azure Commercial Azure Gov
M365 G5
($/yr) $684 $684 $1120
Source: Understanding Compliance Between Microsoft 365 Commercial, GCC, GCC-High and DoD Offerings - Microsoft Community Hub
Microsoft 365 Example
Critical to choose the right systems that are accredited and can attest to requirements
© 2023 C3 Integrated Solutions. All Rights Reserved.
15
Deployment Costs
▸Provisioning
▸Establish the tenant
▸Configure
▸Should align to NIST SP 800-171
▸Data migration
▸Proportional to the size of the company
▸Microsoft 365 examples
⁃ Mailboxes
⁃ Teams and SharePoint
• Complexity – Workflows, etc.
Management and
Monitoring
© 2023 C3 Integrated Solutions. All Rights Reserved.
17
Management
Standard Services Compliant Services
▸ System administration
▸ Operational monitoring
▸ Patch management
▸ Support Desk
▸ Moves, adds, changes
▸ Documentation
▸ SLA
▸ SRM
▸ Standardized
procedures
▸ Configuration updates
▸ System reviews
▸ Support for GRC tool
▸ Assessment support
▸ U.S. based
If your corporate IT or
current MSP provider
cannot support
requirements (i.e. US
person only support),
an MSP specializing in
the DIB should be
considered.
© 2023 C3 Integrated Solutions. All Rights Reserved.
18
Monitoring – What to look for
▸ Automation
▸ Export control
▸ 24x7
▸ Documentation
▸SLA
▸SRM
▸IR Plan
▸ Assessment support
▸ Incident response
▸ Certifications
▸SOC-2
▸ Vulnerability scanning
Costs vary widely
depending on the
level of services and
the sophistication of
the solution.
Compliance
© 2023 C3 Integrated Solutions. All Rights Reserved.
20
Cost of Managing Compliance
Initial Costs Ongoing Costs
▸ Pre-assessment review
▸ Documentation
development
▸ System Security Plan (SSP)
▸ Policies
▸ Procedures
▸ Incident response plan
▸ Initial assessment
▸ Gap analysis
▸ POAM development
▸ Initial table-top
▸ Documentation
▸ Management and upkeep
▸ Integration with services?
▸ Assessment support
▸ Annual validations
▸ Table-top
▸ GRC tool
▸ Licensing
▸ Information upkeep
▸ Ad hoc consulting
Compliance costs have a
minimum threshold where
certain activities (i.e.
assessment) are required
regardless of company
size.
Back to Our Examples…
Numbers provided are for illustration purposes only.
© 2023 C3 Integrated Solutions. All Rights Reserved.
22
Cost Profile
Considerations
▸ Commercial v. GCCH M365
▸ IT support costs
▸ Monitoring costs
▸ Users swivel seat
▸ Double count users across both
environments
Not considered
▸ Additional applications
▸ Intangibles
▸User frustration
▸Overhead and administration of multiple
environments
Corporate Government
Microsoft
365
Commercial M365 G5
$57/month
GCC High M365
G5
$1120/year
IT Support
Internal
$150 month
equivalent
Outsourced
$200/month
Monitoring
Commercial Grade
$26/endpoint
Compliant
$35/endpoint
Strategy, deployment and cost of compliance
assumed comparable across examples unless noted.
© 2023 C3 Integrated Solutions. All Rights Reserved.
23
Pre-CMMC Annual IT Budget
▸M365 Commercial
▸G5 license
▸100 users
▸IT Support
▸$150/user cost of operation
▸May be internal or external
▸Monitoring
▸“Commercial grade”
▸$26/endpoint
▸Assume 100 endpoints
▸Annual budget: $279,600
$68,400
$180,00
0
$31,200
$-
$50,000
$100,000
$150,000
$200,000
$250,000
$300,000
Corporate
M365 IT Support Monitoring
© 2023 C3 Integrated Solutions. All Rights Reserved.
24
Company 1: Research Firm
▸GCC High enclave
▸10 users, M365 G5
▸Azure Virtual Desktop
▸User access
▸No additional applications
▸$2000/month usage
▸IT Support
▸$200/user, External vendor
▸Monitoring
▸$35/endpoint (virtual)
▸Total Budget: $343,700
$279,60
0
$64,100
$-
$50,000
$100,000
$150,000
$200,000
$250,000
$300,000
$350,000
$400,000
Annual Budget
Corporate Enclave
© 2023 C3 Integrated Solutions. All Rights Reserved.
25
Company 2: Manufacturing Firm
▸All-In
▸Microsoft 365 GCC High
▸100 users
▸Azure Virtual Desktop
▸Not required
▸Endpoints converted
▸IT Support
▸$200/user
▸External vendor
▸Monitoring
▸$35/endpoint (virtual)
▸Migration costs not considered
▸Total Budget: $401,000
$119,00
0
$240,00
0
$42,000
$-
$50,000
$100,000
$150,000
$200,000
$250,000
$300,000
$350,000
$400,000
$450,000
All-In
M365 IT Support Monitoring
© 2023 C3 Integrated Solutions. All Rights Reserved.
26
Company 3: Professional Services
▸ All-in or Enclave?
▸ Likely the most expensive from a
strategy development perspective
▸ Escalating commitment as users
are added
▸ Increased risk of unintended
spillage
▸ Increased user frustration and
confusion
▸ Break even to go all-in just under
30 users
* Does not consider other applications
nor strain of managing multiple
environments for both IT and users
$-
$100,000
$200,000
$300,000
$400,000
$500,000
$600,000
$700,000
$800,000
0 10 20 30 40 50 60 70 80 90 100
Commerical GCCH Enclave All-In
© 2023 C3 Integrated Solutions. All Rights Reserved.
27
About C3 Integrated Solutions
Technology
Experience
11 years Microsoft partner
6+ years experience in GCC
High
Multiple Gold competencies
Co-Sell Authorized
Client Experience
450+ Microsoft 365 clients
200+ GCC High clients
Deep NIST, DFARS, ITAR
experience
Industry Leader
First to offer GCC High
backup and hosted voice
CMMC Registered
Practitioner Organization
Two successful C3PAO
clients
Wrap-up and Questions
Get Started
Build the barriers that
protect your business,
not disrupt it.
Our mission is to protect sensitive data and prevent breaches by providing world-class
cybersecurity and compliance services to businesses of all sizes.
visit
c3isit.com
1 sur 29

Recommandé

OPTIMIZING PIPELINES WITH MACHINE LEARNING DECISION SUPPORT par
OPTIMIZING PIPELINES WITH MACHINE LEARNING DECISION SUPPORTOPTIMIZING PIPELINES WITH MACHINE LEARNING DECISION SUPPORT
OPTIMIZING PIPELINES WITH MACHINE LEARNING DECISION SUPPORTwle-ss
20 vues29 diapositives
Cloud ROI and Implementation - A TechBlocks Solutions Guide par
Cloud ROI and Implementation - A TechBlocks Solutions GuideCloud ROI and Implementation - A TechBlocks Solutions Guide
Cloud ROI and Implementation - A TechBlocks Solutions GuideTechBlocks
367 vues12 diapositives
ITAM Tools Day, November 2015 - Concorde par
ITAM Tools Day, November 2015 - ConcordeITAM Tools Day, November 2015 - Concorde
ITAM Tools Day, November 2015 - ConcordeMartin Thompson
443 vues14 diapositives
The CMDB/CMS in the Digital Age: A Bedrock for IT Transformation par
The CMDB/CMS in the Digital Age: A Bedrock for IT TransformationThe CMDB/CMS in the Digital Age: A Bedrock for IT Transformation
The CMDB/CMS in the Digital Age: A Bedrock for IT TransformationEnterprise Management Associates
489 vues46 diapositives
Best Practices for Embedding Analytics by GoodData Product Leader par
Best Practices for Embedding Analytics by GoodData Product LeaderBest Practices for Embedding Analytics by GoodData Product Leader
Best Practices for Embedding Analytics by GoodData Product LeaderProduct School
134 vues25 diapositives
PCM Vision 2019 Keynote: Elliot Baretz par
PCM Vision 2019 Keynote: Elliot BaretzPCM Vision 2019 Keynote: Elliot Baretz
PCM Vision 2019 Keynote: Elliot BaretzPCM
592 vues21 diapositives

Contenu connexe

Similaire à Taking CMMC Seriously - What Is The Cost Of Compliance?

How to Calculate ROI for Network Management & Monitoring par
How to Calculate ROI for Network Management & MonitoringHow to Calculate ROI for Network Management & Monitoring
How to Calculate ROI for Network Management & MonitoringSolarWinds
5.6K vues23 diapositives
Microsoft licensing analysis - an introduction par
Microsoft licensing analysis - an introductionMicrosoft licensing analysis - an introduction
Microsoft licensing analysis - an introductionNiels Jørgen Hansen
1.2K vues38 diapositives
CRMIT Solutions - An Overview par
CRMIT Solutions - An OverviewCRMIT Solutions - An Overview
CRMIT Solutions - An OverviewCRMIT
951 vues17 diapositives
AssetsHub Pitch Deck par
AssetsHub Pitch DeckAssetsHub Pitch Deck
AssetsHub Pitch DeckAssetsHub
25 vues15 diapositives
financial_close_and_disclosure_management_on_cloud par
financial_close_and_disclosure_management_on_cloudfinancial_close_and_disclosure_management_on_cloud
financial_close_and_disclosure_management_on_cloudCharles Wilson
378 vues18 diapositives
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ... par
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...ThousandEyes
87 vues25 diapositives

Similaire à Taking CMMC Seriously - What Is The Cost Of Compliance? (20)

How to Calculate ROI for Network Management & Monitoring par SolarWinds
How to Calculate ROI for Network Management & MonitoringHow to Calculate ROI for Network Management & Monitoring
How to Calculate ROI for Network Management & Monitoring
SolarWinds5.6K vues
CRMIT Solutions - An Overview par CRMIT
CRMIT Solutions - An OverviewCRMIT Solutions - An Overview
CRMIT Solutions - An Overview
CRMIT951 vues
AssetsHub Pitch Deck par AssetsHub
AssetsHub Pitch DeckAssetsHub Pitch Deck
AssetsHub Pitch Deck
AssetsHub25 vues
financial_close_and_disclosure_management_on_cloud par Charles Wilson
financial_close_and_disclosure_management_on_cloudfinancial_close_and_disclosure_management_on_cloud
financial_close_and_disclosure_management_on_cloud
Charles Wilson378 vues
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ... par ThousandEyes
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...
ThousandEyes87 vues
VMSDeploymentGuide_Extract1a par Tom - Creed
VMSDeploymentGuide_Extract1aVMSDeploymentGuide_Extract1a
VMSDeploymentGuide_Extract1a
Tom - Creed51 vues
Under cloud cover: How leaders are accelerating competitive differentiation par Susanne Hupfer, Ph.D.
Under cloud cover: How leaders are accelerating competitive differentiationUnder cloud cover: How leaders are accelerating competitive differentiation
Under cloud cover: How leaders are accelerating competitive differentiation
Migrating apps-to-the-cloud-final par eng999
Migrating apps-to-the-cloud-finalMigrating apps-to-the-cloud-final
Migrating apps-to-the-cloud-final
eng999289 vues
How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2... par Ignyte Assurance Platform
How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2...How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2...
How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2...
MongoDB World 2019: Data Digital Decoupling par MongoDB
MongoDB World 2019: Data Digital DecouplingMongoDB World 2019: Data Digital Decoupling
MongoDB World 2019: Data Digital Decoupling
MongoDB602 vues
Preview novarica1908 eb-core-business_case par ~Eric Principe
Preview novarica1908 eb-core-business_casePreview novarica1908 eb-core-business_case
Preview novarica1908 eb-core-business_case
~Eric Principe25 vues
The Advantages and Pitfalls of Data Centre Consolidation par DAYWATCHER.COM
The Advantages and Pitfalls of Data Centre ConsolidationThe Advantages and Pitfalls of Data Centre Consolidation
The Advantages and Pitfalls of Data Centre Consolidation
DAYWATCHER.COM550 vues
Planning for Cloud Profitability From Day One: MSP VAR Companies and Cloud Co... par ProfitBricks
Planning for Cloud Profitability From Day One: MSP VAR Companies and Cloud Co...Planning for Cloud Profitability From Day One: MSP VAR Companies and Cloud Co...
Planning for Cloud Profitability From Day One: MSP VAR Companies and Cloud Co...
ProfitBricks960 vues

Plus de JSchaus & Associates

Sponsored Content: Finding Federal Contract Opportunities (Part 1) par
Sponsored Content: Finding Federal Contract Opportunities (Part 1)Sponsored Content: Finding Federal Contract Opportunities (Part 1)
Sponsored Content: Finding Federal Contract Opportunities (Part 1)JSchaus & Associates
33 vues21 diapositives
Top 40 Federal Contractors - PROFILE #40 - GSK par
Top 40 Federal Contractors - PROFILE #40 - GSKTop 40 Federal Contractors - PROFILE #40 - GSK
Top 40 Federal Contractors - PROFILE #40 - GSKJSchaus & Associates
19 vues81 diapositives
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps Construction par
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps ConstructionTop 40 Federal Contractors - PROFILE #39 - Hensel Phelps Construction
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps ConstructionJSchaus & Associates
18 vues77 diapositives
Top 40 Federal Contractors - PROFILE #38 - Dell par
Top 40 Federal Contractors - PROFILE #38 - DellTop 40 Federal Contractors - PROFILE #38 - Dell
Top 40 Federal Contractors - PROFILE #38 - DellJSchaus & Associates
14 vues75 diapositives
Top 40 Federal Contractors - PROFILE #37 - CACI par
Top 40 Federal Contractors - PROFILE #37 - CACITop 40 Federal Contractors - PROFILE #37 - CACI
Top 40 Federal Contractors - PROFILE #37 - CACIJSchaus & Associates
43 vues76 diapositives
GSA_FedMine_JSchaus_10192023.pptx par
GSA_FedMine_JSchaus_10192023.pptxGSA_FedMine_JSchaus_10192023.pptx
GSA_FedMine_JSchaus_10192023.pptxJSchaus & Associates
17 vues46 diapositives

Plus de JSchaus & Associates(20)

Sponsored Content: Finding Federal Contract Opportunities (Part 1) par JSchaus & Associates
Sponsored Content: Finding Federal Contract Opportunities (Part 1)Sponsored Content: Finding Federal Contract Opportunities (Part 1)
Sponsored Content: Finding Federal Contract Opportunities (Part 1)
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps Construction par JSchaus & Associates
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps ConstructionTop 40 Federal Contractors - PROFILE #39 - Hensel Phelps Construction
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps Construction
Top 40 Federal Contractors - PROFILE #34 - Steel and Shipbuilding Company par JSchaus & Associates
Top 40 Federal Contractors - PROFILE #34 - Steel and Shipbuilding CompanyTop 40 Federal Contractors - PROFILE #34 - Steel and Shipbuilding Company
Top 40 Federal Contractors - PROFILE #34 - Steel and Shipbuilding Company
Top 40 Federal Contractors - PROFILE #29 - National Security par JSchaus & Associates
Top 40 Federal Contractors - PROFILE #29 - National SecurityTop 40 Federal Contractors - PROFILE #29 - National Security
Top 40 Federal Contractors - PROFILE #29 - National Security

Dernier

How can the social and solidarity economy help refugees along their journey? par
How can the social and solidarity economy help refugees along their journey?How can the social and solidarity economy help refugees along their journey?
How can the social and solidarity economy help refugees along their journey?OECD CFE
63 vues7 diapositives
NGO awareness programs par
NGO awareness programsNGO awareness programs
NGO awareness programsSERUDS INDIA
8 vues1 diapositive
2023-11-17-building_inspector_posting (1).pdf par
2023-11-17-building_inspector_posting (1).pdf2023-11-17-building_inspector_posting (1).pdf
2023-11-17-building_inspector_posting (1).pdfNorthwestBOCA
54 vues6 diapositives
Moving up into upper secondary by Hannah Kitchen - OECD Education Webinar 23N... par
Moving up into upper secondary by Hannah Kitchen - OECD Education Webinar 23N...Moving up into upper secondary by Hannah Kitchen - OECD Education Webinar 23N...
Moving up into upper secondary by Hannah Kitchen - OECD Education Webinar 23N...EduSkills OECD
81 vues16 diapositives
Taking care of the elders par
Taking care of the eldersTaking care of the elders
Taking care of the eldersSERUDS INDIA
6 vues6 diapositives
Dr Jean Paul Latyr FAYE - 2023 ReSAKSS Conference.pptx par
Dr Jean Paul Latyr FAYE - 2023 ReSAKSS Conference.pptxDr Jean Paul Latyr FAYE - 2023 ReSAKSS Conference.pptx
Dr Jean Paul Latyr FAYE - 2023 ReSAKSS Conference.pptxAKADEMIYA2063
6 vues24 diapositives

Dernier(20)

How can the social and solidarity economy help refugees along their journey? par OECD CFE
How can the social and solidarity economy help refugees along their journey?How can the social and solidarity economy help refugees along their journey?
How can the social and solidarity economy help refugees along their journey?
OECD CFE63 vues
2023-11-17-building_inspector_posting (1).pdf par NorthwestBOCA
2023-11-17-building_inspector_posting (1).pdf2023-11-17-building_inspector_posting (1).pdf
2023-11-17-building_inspector_posting (1).pdf
NorthwestBOCA54 vues
Moving up into upper secondary by Hannah Kitchen - OECD Education Webinar 23N... par EduSkills OECD
Moving up into upper secondary by Hannah Kitchen - OECD Education Webinar 23N...Moving up into upper secondary by Hannah Kitchen - OECD Education Webinar 23N...
Moving up into upper secondary by Hannah Kitchen - OECD Education Webinar 23N...
EduSkills OECD81 vues
Dr Jean Paul Latyr FAYE - 2023 ReSAKSS Conference.pptx par AKADEMIYA2063
Dr Jean Paul Latyr FAYE - 2023 ReSAKSS Conference.pptxDr Jean Paul Latyr FAYE - 2023 ReSAKSS Conference.pptx
Dr Jean Paul Latyr FAYE - 2023 ReSAKSS Conference.pptx
AKADEMIYA20636 vues
Sponsor for Child Bright Future par SERUDS INDIA
Sponsor for Child Bright FutureSponsor for Child Bright Future
Sponsor for Child Bright Future
SERUDS INDIA10 vues
2023 Veterans Day Exhibit.pptx par lday4
2023 Veterans Day Exhibit.pptx2023 Veterans Day Exhibit.pptx
2023 Veterans Day Exhibit.pptx
lday448 vues
Dr. Ousmane Badiane - 2023 ReSAKSS Conference.pptx par AKADEMIYA2063
Dr. Ousmane Badiane - 2023 ReSAKSS Conference.pptxDr. Ousmane Badiane - 2023 ReSAKSS Conference.pptx
Dr. Ousmane Badiane - 2023 ReSAKSS Conference.pptx
AKADEMIYA20636 vues
Permit & Zoning Tech 2023 1116.pdf par NorthwestBOCA
Permit & Zoning Tech 2023 1116.pdfPermit & Zoning Tech 2023 1116.pdf
Permit & Zoning Tech 2023 1116.pdf
NorthwestBOCA54 vues
2023 First Tee - Greater Richmond Holiday Gift Guide par bill151498
2023 First Tee - Greater Richmond Holiday Gift Guide2023 First Tee - Greater Richmond Holiday Gift Guide
2023 First Tee - Greater Richmond Holiday Gift Guide
bill15149880 vues
Support a Child Bright Future kurnool par SERUDS INDIA
Support a Child Bright Future kurnoolSupport a Child Bright Future kurnool
Support a Child Bright Future kurnool
SERUDS INDIA8 vues
Dr Getaw Tadesse - 2023 ReSAKSS Conference .pptx par AKADEMIYA2063
Dr Getaw Tadesse - 2023 ReSAKSS Conference .pptxDr Getaw Tadesse - 2023 ReSAKSS Conference .pptx
Dr Getaw Tadesse - 2023 ReSAKSS Conference .pptx
AKADEMIYA20638 vues
Creation of Policy, Ordinance, Minutes of Meeting and Activity Design for San... par AlvaroTojongDioquino
Creation of Policy, Ordinance, Minutes of Meeting and Activity Design for San...Creation of Policy, Ordinance, Minutes of Meeting and Activity Design for San...
Creation of Policy, Ordinance, Minutes of Meeting and Activity Design for San...

Taking CMMC Seriously - What Is The Cost Of Compliance?

  • 1. Taking CMMC Seriously: What is the Cost of Compliance? September, 19, 2023
  • 2. Welcome! Bill Wootton Chief Revenue Officer C3 Integrated Solutions bwootton@C3isit.com
  • 3. © 2023 C3 Integrated Solutions. All Rights Reserved. 3 Today’s Topics ▸Overview: Major Components of the Cost of CMMC ▸Building a Strategy ▸Deployment ▸Management and Monitoring ▸Compliance ▸Data Enclaves: Options and Impact ▸Three Types of Companies
  • 5. © 2023 C3 Integrated Solutions. All Rights Reserved. 5 Building Your CMMC Strategy Understanding your business Setting the system boundary Determining the organizational impact Determining the expertise you need
  • 6. © 2023 C3 Integrated Solutions. All Rights Reserved. 6 Understanding Your Business External Factors Internal Factors ▸ Your Customers… ▸ Which agencies do you work with? ▸ Your Partners… ▸ Who are your primes and subs? ▸ What are THEIR requirements to continue working with them? ▸ Your Contracts… ▸ What clauses are already in your contracts? ▸ Your Future… ▸ Where will your business be in 2-3 years? ▸ Your Data… ▸ Do you have CUI? ▸ Do you have export-controlled data? ▸ Can you segment it from the rest of the organization? ▸ Your People… ▸ Who directly interacts with CUI ▸ Who indirectly interacts with CUI? ▸ Your Systems… ▸ Which systems store, process, or transit data? The better you know your business, the less you will need a consultant to answer these questions.
  • 7. © 2023 C3 Integrated Solutions. All Rights Reserved. 7 Company Examples: All 100-Person Firms Research Firm • Almost all commercial work • Single DoD contract • Team segmented from rest of the firm Manufacturing Firm • Approximately 90% DoD work • Highly customized parts for aircraft • Large amounts of export- controlled data Professional Services • Many distributed contracts • Team members rotate between DoD and civilian work regularly • Centralized admin supports all contracts Current systems are not compliant. No preexisting certifications (e.g. ISO 9001)
  • 8. © 2023 C3 Integrated Solutions. All Rights Reserved. 8 Employee Access to CUI (100-person Company) ???????? 90 People 10 people 90 People 10 people Commercial Within CUI Boundary Company 1 – Research Firm Company 3 – Professional Services Firm Company 2 – Manufacturing Firm
  • 9. © 2023 C3 Integrated Solutions. All Rights Reserved. 9 Determining System Boundaries: Enclave or All-In? ENCLAVE Separate environment isolated from the corporate environment ALL-IN Full configuration of corporate environment to meet CMMC requirements Pros ▸ Reduced investment and scope ▸ Smaller attack surface ▸ More controlled system boundary ▸ Limited (if any) data migration Cons ▸ Swivel-seat user impact ▸ Illusion of cost savings ▸ Dual administration ▸ Unintended spillage Pros ▸ Single, consolidated environment ▸ Eliminates all technical debt (fresh start) Cons ▸ Data migration ▸ User impact ▸ Higher deployment costs ▸ Everyone is “locked down” ▸ Non-approved applications
  • 10. © 2023 C3 Integrated Solutions. All Rights Reserved. 10 Enclave or All-In? ???????? 90 People 10 people 90 People 10 people Commercial Within CUI Boundary Company 1 – Research Firm Company 3 – Professional Services Company 2 - Manufacturing Enclave ???? All-in
  • 11. © 2023 C3 Integrated Solutions. All Rights Reserved. 11 Cost Drivers in Building a Strategy Drivers Costs ▸ Knowledge of business ▸ Knowledge of data ▸ Current situation ▸ Technical debt ▸ Documentation ▸ Previous investment ▸ Internal resources ▸ Expertise/knowledge ▸ Availability ▸ Direct costs ▸ Outside consultant ▸ Internal effort ▸ Indirect costs ▸ Organization impact beyond IT ⁃ Business process changes ⁃ Segmenting and isolating data in an enclave ▸ Impact of Strategy ⁃ Determines cost of the rest of the process ▸ Confidence ▸ Risk of pursuing the wrong approach Strategy costs are not directly related to the size of the company. In most cases, the scope of effort drives the cost profile.
  • 13. © 2023 C3 Integrated Solutions. All Rights Reserved. 13 Setting the System Boundary System Boundary System Selection • Communications • E-mail • Unified communications • Collaboration • Documents • Other data • CRM • Financial • Operational technology • Access • Virtual desktop • Physical devices • Mobile devices • Cloud v. on-premises • FedRAMP • Export control • US data residency • US persons Minimizing the system boundary reduces the services that need to be fully compliant
  • 14. © 2023 C3 Integrated Solutions. All Rights Reserved. 14 Technology Costs ▸System selection criteria ▸Accreditations ▸Attestations ▸Export control ▸GovCloud is typically at least 30% higher Commercial GCC GCC High Data Centers Worldwide US Only US only Accreditation FedRAMP Moderate* FedRAMP Moderate FedRAMP High DFARS 7012 No Yes Yes ITAR/EAR No No Yes CUI/CDI No Maybe Yes Customer Support Worldwide/Commercial Personnel Directory/Nt k Azure Commercial Azure Gov M365 G5 ($/yr) $684 $684 $1120 Source: Understanding Compliance Between Microsoft 365 Commercial, GCC, GCC-High and DoD Offerings - Microsoft Community Hub Microsoft 365 Example Critical to choose the right systems that are accredited and can attest to requirements
  • 15. © 2023 C3 Integrated Solutions. All Rights Reserved. 15 Deployment Costs ▸Provisioning ▸Establish the tenant ▸Configure ▸Should align to NIST SP 800-171 ▸Data migration ▸Proportional to the size of the company ▸Microsoft 365 examples ⁃ Mailboxes ⁃ Teams and SharePoint • Complexity – Workflows, etc.
  • 17. © 2023 C3 Integrated Solutions. All Rights Reserved. 17 Management Standard Services Compliant Services ▸ System administration ▸ Operational monitoring ▸ Patch management ▸ Support Desk ▸ Moves, adds, changes ▸ Documentation ▸ SLA ▸ SRM ▸ Standardized procedures ▸ Configuration updates ▸ System reviews ▸ Support for GRC tool ▸ Assessment support ▸ U.S. based If your corporate IT or current MSP provider cannot support requirements (i.e. US person only support), an MSP specializing in the DIB should be considered.
  • 18. © 2023 C3 Integrated Solutions. All Rights Reserved. 18 Monitoring – What to look for ▸ Automation ▸ Export control ▸ 24x7 ▸ Documentation ▸SLA ▸SRM ▸IR Plan ▸ Assessment support ▸ Incident response ▸ Certifications ▸SOC-2 ▸ Vulnerability scanning Costs vary widely depending on the level of services and the sophistication of the solution.
  • 20. © 2023 C3 Integrated Solutions. All Rights Reserved. 20 Cost of Managing Compliance Initial Costs Ongoing Costs ▸ Pre-assessment review ▸ Documentation development ▸ System Security Plan (SSP) ▸ Policies ▸ Procedures ▸ Incident response plan ▸ Initial assessment ▸ Gap analysis ▸ POAM development ▸ Initial table-top ▸ Documentation ▸ Management and upkeep ▸ Integration with services? ▸ Assessment support ▸ Annual validations ▸ Table-top ▸ GRC tool ▸ Licensing ▸ Information upkeep ▸ Ad hoc consulting Compliance costs have a minimum threshold where certain activities (i.e. assessment) are required regardless of company size.
  • 21. Back to Our Examples… Numbers provided are for illustration purposes only.
  • 22. © 2023 C3 Integrated Solutions. All Rights Reserved. 22 Cost Profile Considerations ▸ Commercial v. GCCH M365 ▸ IT support costs ▸ Monitoring costs ▸ Users swivel seat ▸ Double count users across both environments Not considered ▸ Additional applications ▸ Intangibles ▸User frustration ▸Overhead and administration of multiple environments Corporate Government Microsoft 365 Commercial M365 G5 $57/month GCC High M365 G5 $1120/year IT Support Internal $150 month equivalent Outsourced $200/month Monitoring Commercial Grade $26/endpoint Compliant $35/endpoint Strategy, deployment and cost of compliance assumed comparable across examples unless noted.
  • 23. © 2023 C3 Integrated Solutions. All Rights Reserved. 23 Pre-CMMC Annual IT Budget ▸M365 Commercial ▸G5 license ▸100 users ▸IT Support ▸$150/user cost of operation ▸May be internal or external ▸Monitoring ▸“Commercial grade” ▸$26/endpoint ▸Assume 100 endpoints ▸Annual budget: $279,600 $68,400 $180,00 0 $31,200 $- $50,000 $100,000 $150,000 $200,000 $250,000 $300,000 Corporate M365 IT Support Monitoring
  • 24. © 2023 C3 Integrated Solutions. All Rights Reserved. 24 Company 1: Research Firm ▸GCC High enclave ▸10 users, M365 G5 ▸Azure Virtual Desktop ▸User access ▸No additional applications ▸$2000/month usage ▸IT Support ▸$200/user, External vendor ▸Monitoring ▸$35/endpoint (virtual) ▸Total Budget: $343,700 $279,60 0 $64,100 $- $50,000 $100,000 $150,000 $200,000 $250,000 $300,000 $350,000 $400,000 Annual Budget Corporate Enclave
  • 25. © 2023 C3 Integrated Solutions. All Rights Reserved. 25 Company 2: Manufacturing Firm ▸All-In ▸Microsoft 365 GCC High ▸100 users ▸Azure Virtual Desktop ▸Not required ▸Endpoints converted ▸IT Support ▸$200/user ▸External vendor ▸Monitoring ▸$35/endpoint (virtual) ▸Migration costs not considered ▸Total Budget: $401,000 $119,00 0 $240,00 0 $42,000 $- $50,000 $100,000 $150,000 $200,000 $250,000 $300,000 $350,000 $400,000 $450,000 All-In M365 IT Support Monitoring
  • 26. © 2023 C3 Integrated Solutions. All Rights Reserved. 26 Company 3: Professional Services ▸ All-in or Enclave? ▸ Likely the most expensive from a strategy development perspective ▸ Escalating commitment as users are added ▸ Increased risk of unintended spillage ▸ Increased user frustration and confusion ▸ Break even to go all-in just under 30 users * Does not consider other applications nor strain of managing multiple environments for both IT and users $- $100,000 $200,000 $300,000 $400,000 $500,000 $600,000 $700,000 $800,000 0 10 20 30 40 50 60 70 80 90 100 Commerical GCCH Enclave All-In
  • 27. © 2023 C3 Integrated Solutions. All Rights Reserved. 27 About C3 Integrated Solutions Technology Experience 11 years Microsoft partner 6+ years experience in GCC High Multiple Gold competencies Co-Sell Authorized Client Experience 450+ Microsoft 365 clients 200+ GCC High clients Deep NIST, DFARS, ITAR experience Industry Leader First to offer GCC High backup and hosted voice CMMC Registered Practitioner Organization Two successful C3PAO clients
  • 29. Get Started Build the barriers that protect your business, not disrupt it. Our mission is to protect sensitive data and prevent breaches by providing world-class cybersecurity and compliance services to businesses of all sizes. visit c3isit.com