Tag: cmmc

Home / cmmc
Ports, Protocols, Programs Functions, and Services
Post

CMMC Practice 3.4.7 – Ports, Protocols, Programs Functions, and Services

TL;DR: Simplifying Essential Features for Compliance The Goal: Restrict and disable nonessential programs, ports, protocols, functions, and services to reduce your system’s attack surface and improve security. Challenges: Documentation—not implementation—is where most companies fall short. You must define “essential” clearly and apply it consistently. What to Do: • Inventory: Identify everything running on your systems....

The CMMC Rule and Plans of Action & Milestones (POA&M)
Post

The CMMC Rule and Plans of Action & Milestones (POA&M)

One of the things that I wanted to see in the CMMC Rule was more clarity on utilizing Plans of Action and Milestones (POA&M) for companies that do not fully meet all 110 requirements during their assessment. I’m continuing to dive into the CMMC rule…it’s freaking long. Here is what it says about POA&Ms, the...

Post

The CMMC Rule is FINAL!

Woooohoooo, the long awaited CMMC Rule will be published on the Federal Register on October 15, 2024. The Wrightbrained team has spent some time looking at the document. Clarifications are a big theme. Everyone in the CMMC ecosystem had a lot of questions and there were several that stood out as the most common. I...

FIPS 140-2 and CMMC Compliance
Post

FIPS 140-2 and CMMC Compliance

What is FIPS 140-2? Federal Information Processing Standards Publication 140-2 is a standard for the cryptographic modules used in software and hardware to protect sensitive data. The key difference between FIPS-validated modules and others is the rigorous testing and verification process they undergo. This process can take years, ensuring these modules meet strict security protocols....

Post

The CrowdStrike Outage: Risk Assessments & Single Points of Failure

On July 19, 2024, what should have been a routine update meant to improve CrowdStrike’s Falcon Sensor software ended up causing chaos. Instead of enhancing the endpoint detection and response system, the update resulted in Windows computers crashing spectacularly, displaying the dreaded “Blue Screen of Death.” This caused disruptions across the globe and across industries...

VerySecure UAV’s On-Site CMMC Assessment – Physical Security & related domains
Post

VerySecure UAV’s On-Site CMMC Assessment – Physical Security & related domains

Disclaimer: This story is entirely fictional. Any resemblance to actual persons, living or dead, or actual events, or actual companies is purely coincidental and unintended. The characters, companies, and events portrayed are purely a work of fiction. Jil Wright, a Certified CMMC Assessor, has provided this narrative to offer organizations seeking certification an example of what...

CMMC Assessment – SI Domain – MakeBelieve Manufacturing
Post

CMMC Assessment – SI Domain – MakeBelieve Manufacturing

Disclaimer: This story is entirely fictional. Any resemblance to actual persons, living or dead, or actual events, or actual companies is purely coincidental and unintended. The characters, companies, and events portrayed are purely a work of fiction. Jil Wright, a Certified CMMC Assessor, has provided this narrative to offer organizations seeking certification an example of what...

Configuration Management Gears
Post

Baseline Configurations: The First Step in Configuration Management

The Configuration Management (CM) domain in NIST SP 800-171 requires organizations to create and maintain baseline configurations and inventories for all their systems that includes hardware, software, firmware, and documentation.  Think of baseline configurations like a snapshot, capturing the ideal system setup. Documenting a system’s desired state and practicing effective configuration and change management are crucial...

Multi-factor Authentication (MFA) and How to Thwart Bypass Attacks
Post

Multi-factor Authentication (MFA) and How to Thwart Bypass Attacks

Multi-Factor Authentication (MFA) significantly strengthens security for businesses and individuals by adding extra layers of verification before granting access to accounts or devices. Instead of relying on just one factor like a password, MFA requires two or more factors. This makes it much harder for attackers to gain unauthorized access. Research suggests that implementing MFA...