DoctorMac
DoctorMac

Ryan Bonner on working with your MSP on CMMC

|
Embed
Progress spinner
DoctorMac
DoctorMac

Ryan starts off by talking about the boorowed time from 2017 and 2022 and suggests we need a shared language with MSPs. We learned about covered conbtractor system. Contractors read the reqs and say, "That is my MSP who does that."

|
Embed
Progress spinner
DoctorMac
DoctorMac

Primes also sent out a questionnaire and said get a SPRS sccore or get dropped.

|
Embed
Progress spinner
DoctorMac
DoctorMac

Do MSPs know about the 7020 clause, have time to read 171 and supporting documents

|
Embed
Progress spinner
DoctorMac
DoctorMac

We have to think about the MSP as a traditional supplier.

|
Embed
Progress spinner
DoctorMac
DoctorMac

Plan, Do, Check, and Adjust. Manufacturers work under quality assurance.

|
Embed
Progress spinner
DoctorMac
DoctorMac

They work in a closed loop system. Everything is verified. You must plan before you perform. If you look at CMMC assessment guides almost all practices start with a governance objective, followed by a procedural objective

|
Embed
Progress spinner
DoctorMac
DoctorMac

After plan and do you now have to add more emphasis to check which assets can make this happen. There are three asset types in the scoping guide. You can start there. Person, Technology, or Facilities

|
Embed
Progress spinner
DoctorMac
DoctorMac

Describe the work once you have decided the asset that will do the objective. Procure software Configure baseline

Lay out the actions in a simple list with an MSP.

|
Embed
Progress spinner
DoctorMac
DoctorMac

Then use a RACI model with your MSP. The MSP maybe responbsible something but the RACI matrix will if they need to check on a team

|
Embed
Progress spinner
In reply to
DoctorMac
DoctorMac

Then decide on when you do the security assessment. The assessment check if the controls are in place and working correctly.

|
Embed
Progress spinner
DoctorMac
DoctorMac

Then think about tier 3, tier 2, and tier 1 support. When we talk CMMC the tier 3 people of an MSP hop right on. They know what to do but can't explain. They also will get hired away.

|
Embed
Progress spinner
DoctorMac
DoctorMac

Tier 3 should focus on policy, tier 2 on the standard, and tier 1 should focus on specification.

They can ask, "Am I currently connecting to a server?" You have to get to this level

|
Embed
Progress spinner