Repository of Tools to Protect our Supply Chain
Federal Contract Information. Any information included in or created for a government contract not meant for public release.
Controlled Unclassifed Information. Information that requires safeguarding or dissemination controls required by law, regulation, or Govt-Wide Policy but not classifed and nuclear stuff
FCI can be created by you or the government as a result of a contract
FCI is not meant for public release
Controlled Unclassified Information, as can be made by or on behalf of the DOD.
There is no classification system for FCI
All information not for public release is FCI
CUI-Basic: Follow rules for protecting
CUI-Specified: Spells out rules for protection
Controlled Technical Information, General Procurement & Acquisition, and Proprietary Information, among others.
The National Archives creates CUI categories. The DoD or CMMC-AB has no say
FCI needs safeguarding
There is no classification system
The entity that creates the CUI labels CUI
Authorized holders with a lawful government purpose mark CUI using agency/component guidance.
Established by the Federal Acquisition Regulation Clause 52.204 - 21 Basic Safeguarding of Covered Contractor Information Systems.
FAR Clause 52.204-21 lays out basic safeguards for protection
Do not assume this is easy
CUI requires physical and cybersecurity safeguards
CUI gets protected by NIST 800-171 using the 171a methodology
Hard and expensive. Plan on 6 months to a year
No. It is not FCI.
Only the Government can create FCI.
Yes, when created as a part of a government contract, unless mutually agreed between IP owner and Gov’t Contracting Agency.
Contractors who only touch or create FCI will need to pass a level one maturation assessment
By 2025 all contractors will be assessed using the CMMC Level 1 methodology
Contractors who touch, create, receive, transmit or destory CUI will need to pass a level three maturation assessment
By 2025(ish) all contractors will be assessed using the CMMC Level 3 methodology
CUI is Controlled Unclassified Information, a marking similar to For Official Use Only (FOUO). CUI is required to be protected in ac-cordance with NIST SP 800-171
Controlled Unclassified Information. Contract information that needs additional safegaurding based on federal laws, classifed and nuclear stuff
CUI may have a cover sheet with a purple bor-der. It may also be marked as CUI, (U) CUI, or specified-marked, for example:CUI//SP-PII//NOFORN
The DoD or contractors like {Company} may produce CUI. {Company} will only create CUI when in support of a DoD contract it meets types defined in the NARA CUI Registry.
{Insert Company Name} proprietary data is not CUI. IP pertaining to {Insert Company Name} employees is not CUI. There are many types of sensitive data that are not CUI.
The person generating CUI is responsible for categorizing and marking the data. CUI today is often not labeled.
{Insert Company Name} computers and networks are not equipped to handle classified data. All classified data must reside in SIPRnet.
{Insert Company Name} has provided {Insert software solution} as secure place to store and process CUI. CUI cannot be stored on your laptop, cloud drives, USB sticks. or in {Company} Email. Saving yourself a draft email is not secure.
You should direct the sender to send you CUI through DoD tools such as SAFE, or through {Insert Software Solution}. CUI should not be sent to your {Company Email} at this time.
Given that most CUI is not lableled the company policy is to shred everything. Unless it carried food all paper gets shredded. Period. {Insert Software Solution} has guidance on destorying internal CUI. At no time should CUI be on any other external storage device.
Report any questions or concerns to your su-pervisor and the {IT Department}.
CUI is Controlled Unclassified Information, a marking similar to For Official Use Only (FOUO). CUI is required to be protected in ac-cordance with NIST SP 800-171
Controlled Unclassified Information. Contract information that needs additional safegaurding based on federal laws, classifed and nuclear stuff
CUI may have a cover sheet with a purple bor-der. It may also be marked as CUI, (U) CUI, or specified-marked, for example:CUI//SP-PII//NOFORN
The DoD or contractors like {Company} may produce CUI. {Company} will only create CUI when in support of a DoD contract it meets types defined in the NARA CUI Registry.
{Insert Company Name} or your company's proprietary data is not CUI. IP pertaining to {Insert Company Name} employees is not CUI. There are many types of sensitive data that are not CUI.
The person generating CUI is responsible for categorizing and marking the data. CUI today is often not labeled.
{Insert Company Name} computers and networks are not equipped to handle classified data. All classified data must reside in SIPRnet.
Discuss with your information security manager where CUI may be stored on your net- work. {Company} allows CUI only in our {Software Solution} systems. {
You may send CUI to {Company} via {Internal Apps} or DoD SAFE.
All CUI no longer in use gets destroyed. Discuss with your information security manager your policy on destroying CUI and media sanitization.
You should direct the sender to send you CUI through DoD tools such as SAFE. CUI must be encrypted in transit and when stored.
Report any questions or concerns to your su-pervisor and the {IT Department}.
If you do not have a contract from the government or a contract funded from a larger Government award you can not have FCI
If you do have federal funding you have FCI if you touch any information not meant for public release.
To meet the Safeguarding of Covered Contractor Information Systems required by FARS Clause 52.204-21. You can protect your entire network and company premise.
You may find it more affordable to sequester FCI to a specific device, like a company provided laptop and use a protected file sharing solution.
FCI is any data not meant for public release. So if you can download it from a public website, google it, or if the data is presently FOIable it is not FCI.
Much of your #cmmc level one compliance can be met with a well written access control policy. The FARS 21 Clause requires you to, " Limit information system access to authorized users, processes acting on behalf of authorized users, or devices"
These policie address your account management and describe how you identify users, and limit their authorization. You also have rules on how to add new equipment like printers.
A CMMC assessor will want to see an access control policy. They will want to talk to whoever manages the list and networks. This maybe an IT contractor. They may want to test how you add a new user or employee to the system.
A {company name}registered professional can help you write an access control policy.
Much of your CMMC Level One compliance revolves around common sense. Only let people who need to use data have access to that data. The FARS 21 Clause requires you to, " Limit information system access to the types of transactions and functions that authorized users are permitted to execute."
Basically you need to define access priviledges. How you do this should be documented in your access control policy. If you use O365 or G Suite you have this ability to define groups and roles. If you want to share data outside your organization you may want to use a secure and encrypted file service.
Again contact {company name} if you need help crafting a an access control policy that has evidene of your compliance. Check out {company name} for an encrypted file sharing solution
You will need to make decisions about personal devices. You either have to provide devices to employees like lap tops and cell phones or use mobild device management. The other solution is to allow no off site access or of the clock work. The Fars 21 clause requires you to limit,"use of external information systems"
Even if you provide devices you should use Mobile Device Management to protect FCI.
If you need employees to access FCI from home or remote you need a VPN. This is a virtual private network. You will need to document in your access control policy.
A CMMC assessor will want to see your access control policy, they will want talk your network adminstrator or IT consulantant and test your VPN
Many small businesses rely on IT firms. They often connect your network to their external systems. As the Government contractor iit is your responisbility to ensure any IT contractor protects your FCI.
Your CMMC assessor will want to see clear policies about FCI boundaries between yoru company and the IT contractor.
Many times IT contractors have full access to your network. For this reason CyberDI suggests only using vendors who hold a CMMC Level Three certificate. You could also sequester FCI in a file sharing system such as {company name} to only share FCI with authorized users.
Another common sense CMMC control. Would you let anyone just publish info on your website? The FARS 21 clause requires you to,"Control information posted or processed on publicly accessible information systems."
You have to be careful with stuff like websites and press releases when you touch FCI.
A CMMC assessor will want to see rules about who gets to publish data and information to public channels. A {Company Name} CMMC Registered Professional can help you write your Access Control policy so it contains the required observable evidence.
Controlling data means knowing who logs in when. This begins by having unique user names and passwords. You can not save money by sharing credentials when it comes to FCI. The FARS-21 clause requires you to, "Authenticate (or verify) the identities of those users, processes, or devices." before they can touch sensitive data
It is important to know the difference between authentication and authorization. Authentication follows the Popeye (or Slim Shady) rule: I Am who I says I am. Authorization is the permissions assigned to an authenticated user.
A CMMC assessor will need to verify if every user has a unique identifier for all systems that touch FCI. This can include user names and stuff do identify computers like a MAc address or internet users thorugh Internet Protocol addresses. If you use software you may need to document the API token generation used for authentication. APIs are like secret handshakes between computers. They will only talk if tokens match.
You need to document your user authentication process. Much of this just needs to refer to your software such as Microsoft or Google documentation. A {company name] Registered Professional can help.
One you know you authenticate each use you need to know when they log in and what device they are using. To cpmply with FARS 21 you need to have this information as a, " prerequisite to allowing access to organizational information system."
For many small businesses this maybe data kept by a IT consulting company. Once again we recommend using only IT consultants persuing a CMMC level Three certification
A CMMC assessor will look for a mchanism to support your authentication. It is important you use multifactor authentication and not just two factor authentication. Most modern computer systems support MFA. Ask your CMMC Level 3 Certified IT Company for help.
It is good company policy to err on the side of shred everything. If you have a locked room just for prining and storing FCI keep the shredder there.
It is good company policy to err on the side of shred everything. If you have a locked room just for prining and storing FCI keep the shredder there.
A {company name} Registered Professional can walk you through the NIST SP 800-88 guidance on destroying media.
Sounds silly but the CMMC Level one requires basic physical protections you may take for granted. The Fars 21 Basic safeguarding isn't safe if people have physical access to your site or your networks.
If you store FCI this needs to be in a place, such as a room or a locked cabinet where the public or unauthorized staff can not access.
Your physical access will require some advanced security such as electronically or visually checked badges and keycards.
A CMMC Level One Assessor will test your physical access authorizations and examine written policies.
Of course not. Just write this down in a policy as observable evidence for compliance. Keep visitor logs. There are plenty of fancy solutions but a paper sign in still works. Remember DFARS-21 requires you to, " Escort visitors and monitor visitor activity and maintain audit logs of physical access"
A CMMC assessor will look for your visitor escort policies. If you use electronic solutions they may test these.
Another common sense protection of the FARS 21 clause that requires you to, "maintain audit logs of physical access."
A CMMC assessor will look for your visitor logs. Even paper logs will do but you may want to consider a solution that captures a physical image.
If you use access cards these need to get into spaces that protect FCI these need protection too. The DFARS 21 clause states, "Limit physical access to organizational information systems, equipment, and the respective operating environments." If you do not protect the tools that allow you to do this you have no protection.
So if you use badges or even use a photcopier code for machines authorized for FCI duplication you need to protect these and desascribe how you protect these in an access policy.
If you padlock access to the yard don't do dumb stuff like write the combo on the side of the wall are on the lock.
A CMMC Assessor will want to see an inventory of your access control devices. They may check your doors. In fact you should prepare an iventory of all your electronic dveices and have it ready for an assessment.
Just like you need to lock and monitor your physical boundaries with doors and locks you also need to protect the boundaries of your networks and communication systems like email. In fact the FARS 21 clause requires you to monitor, "at the external boundaries and key internal boundaries of the information systems.""
A CMMC assessor will look for communication protection policies. You also should have a professional network expert diagram how FCI flos in your system. They will also want to know how your system is configured.
This is one of the most complicated of the Level One CMMC practices. You really should use a CyberDI Registered Professional to draw your network diagram. You can not do the monitoring on your own. {Company Nmane} recommends using a qualfied vendor a cybersecurity solution
The cybersecurity world has a phrase for when we sepersate different types of data using the Demilitarized Zone (DMZ) as a metaphor. This just means having a system to meet the FARS 21 requirement of, "implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks"
A CMMC assessor will test many systems and hardware. if you use an IT consultant make sure they are on the pathway to achieving CMMC Level Three classification. This is not a requirement, but recommended as good practice when using vendors to protect FCI.
You will have to monitor these systems. Once again CyberDI recommends using {software solution} for system monitoring.
Do not rely on humans to complete timely updates. You need to automate these systems so you can, "Identify, report, and correct information and information system flaws in a timely manner."
If a computer is not updated you can not identify flaws in a timely manner. You need to track updates and when you find flaws in your system there must be way to report these. flaws.
A CMMC assessor will want to see configuration management policies, device imaging policies, and they may test how you install and approve software You should document all of this with a {Company Name} Registered Professional.
You need protection from bad things on the web. In facts the FARS 21 clause calls for, "protection from malicious code at appropriate locations within organizational information systems."
Designate locations mean places where data enters and exits your system like email, servers, and firewalls. Most businesses can not do this on their own and use software solutions from enterprise software and third party IT consultants.
A CMMC assessor will want to test all the things. More things than we can fit here. You may want consider {company name} as a cybersecurity solution to help you out.
No point in protecting boundaries, places that should block access, test the "DMZ," or designated locations of FCI without updates. In facts the FARS 21 clause declares, "Update malicious code protection mechanisms when new releases are available."
Configuration managment is hard. You can't do it. Even if you use commercial off the shelf solutions you should use an IT professional. In terms of Obervable Evidence work with the consulant to write policies.
A CMMC assessor will test information integrity policies, want to see network diagrams, see how you monitor false positives, meaning that important deal getting lost in your spam folder. You can not do this alone.
Almost all email tools have policies and systems that have enough observable evidence to meet the FARS 21 requirement of, "Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed."
You may have the tools, but do you know where to find them. The Enterprise solutions maybe enough for compliance but do not confuse compliance with security. If you care about protecting FCI we recommend using someone such as {company name}
Cybersecurity begins and ends with access control. You must know who resides in your system and what stuff they can access. At home you keep track of who has keys, a cell phone account, and wifi password. Do the same at work with user names and passwords.
NIST SP 800-192 "Verfication and Test Methods for Access Control Policies/Moddels" defines access control polcies as:
high level requirements that specify how access is managed and who, under what circumstances, may access what information
Access policies can apply to specific users and roles, such as only giving accounting access to financials. Access control policies can also get assigned at the appliclation so you need to know a vendor's policy before buying any technology.
Access control policies establish organizational boundaries that limit information based on units, need-to-know, authority or any number of business siutations that require the legal access to information
Inside your network or data flow, how information moves across physical and digital spaces, boundaries act as places to stop access. This also means boundaries by design can break. Protecting these weaknesses through access control policy builds a foundation of cybersecurity
You may create one document where all your access control policies live but focus on doing business better first. As you craft company training and documentation consider where your accesc control policies already live.
Employee handbooks will describe if people can bring devices to work or connect work devices to home networks. They will describe rules banning the sharing of credentials. Human resource onboarding and exiting documents contain your access control policy. You need to review how accounts get made and include rules about where data gets transfered when employees leave. Your privacy policy may explain the rules abotu who can release data to the public or how guests can connect to your network. Vendor agreements need to explain how FCI or CUI gets shared, encrypted, and destroyed.
Focus first on including access control policies into company cuture. Then when creating your overall Access Control Policy document refer back to these company policies. This will allow you to handle the dynamic nature of a changing business world.
Access control policies fall into two types of buckets: discretionary polices based on on identity and non-discretionary polcies based on rules
{Company Name} uses {type of access control poicy}
The Federal Government considers DBAC, Discretionary Based Access Control, policies too weak for the contracting community. If you assign access at the user level you can not control who copies the file. Other users could also transfer ownership. Finally other users could mess with the data and change stuff like publication dates.
With NDAC, or non-discretionary access control, policies the user does not get rights over the object. The user can not change who has control of an object. This means NDAC policies rquire an Administrator to control access policies.
In mandatory access control (MAC) policies a central authority, or scrutinizer, controls access. You get to decide who gets garage door openers. If you receieve CUI, for example, you not change the CUI category nor the specified regulations that protect the CUI.
NDAC controls can use static or dynamic rules. Static policies, which do not change include multi-level security, attrribute based access control, and rule based access control.
Under Seperation of Duty, a dynamic set of rules, you do not assign enough priviledges to anyone to misue the system on the own. One child may hold the garage door opener, but only parents have keys to the car. Dynamic seperatation of duties can include two people having to have a safety deposit box keys. In terms of data two people maybe required to release data publicly or to execute commands on a system.
You can use a simple, or static, separation of duty that says no member can have two exclusive roles. So if a user gets marked as "Teacher" in a school they could not also get assigned to the "Principal" role
In terms of dynamic separation of duty policies NIST identifies four types:
These faults fall along the following lines:
Access control models present the security policies you enforce through your access control mechanisms, the procedures and controls that limi who sees what.
ACM create a visual of the theoretical limitations and boundaries of your access control policies. You will want to include and ACM in your system security plan. You also will want to work with a professional to ensure an accurate model
You can adapt the Enterprise Considerations NIST suggests as part of the system development life cycle
Establish the business use case If you want to add a new tool that requries additional access policies make sure you really need the tool or you are not paying for similar functionality somewherre else. Every new software and policy introduces new faults.
Consider the Bigger Picture. What does your larger network look like? What does the new tool do to your access control model? How do you report security for compliance? What documents have to change? What training do employees require?
Refine Business Processes. You will ignore this advice but make the required changes before signing the purchasing order or moving the pilot from staging to deployment. Demand a sandbox from vendors sequestered from your network. Storage is cheap. You have leverage. You also need to consider and integrate how roles and attributes are assigned to users and data.
Test for Interoperability. Look for third party interoperability certifications. Do not trust a logo on a website. Test the interoperability with your system.
Feasability and Usability Does the cost of the tool, both price and long term compliance, bring enough value? Doe the tool work? What happens in low signal areas? Do my threat awareness tools integrate?
Refine Access Control Model You need to map the flow of access control between your system and the new tool and understand how different user attributes match.