Home Inspections as part of CMMC?
Usual disclaimers, this article and the opinions within are my own and not those of any of my employers. I also will not be attempting to sell you anything. Hope you enjoy and find a benefit from the article. This is not legal advice.
I am compelled to write this article because I have seen enough discussion on the topic of will assessors visit home residencies as part of CMMC assessments? Remember, everything that has been said on the topic to date has been purely opinion. There has been no official guidance from the CMMC AB or DoD A&S PMO on this topic. So, I will weigh in with my opinion as well.
Short answer is yes, there will be some home visits by CMMC assessors. However, the caveats are important and all things have to be viewed through the lens of reasonableness.
Isn't this a violation of my constitutional rights? No. This is not a unreasonable search and seizure. It is an assessor coming to observe your practices that you use to protect CUI. Nobody forces you work with CUI or with the government and you can stop at any time if you refuse to be a good data custodian and follow the data owner's requirements. But I really don't want them to come to my house and I want to keep working for the DoD? Good news, you have until 2026 (unless the date slides) to figure out an alternative arrangement.
When should I expect to receive a home visit for CMMC assessment?
When should I not expect to receive a home visit for CMMC assessment?
领英推荐
Considerations to discuss here. The idea of primary or alternative work site does apply. A good practice should be creating a Telework Agreement that employees sign for working from home as a condition as either their primary or alternative work site. The Telework Agreement satisfies PE.3.136[a] if it defines the requirements for the employee and the signature from the employee satisfies PE.3.136[b] through policy enforcement with a low level of assurance. Would a visit by an assessor provide a higher level of assurance? Yes. Is it reasonable to do it for the extra benefit it would provide? No, not really. However, it would be reasonable to expect an assessor to review any telework agreements, verify signatures, and interview an employee but that interview could be virtual and not in the employee's personal residence.
The idea that every WFH employee for every company would receive a visit from an assessor is absolutely absurd, impractical, and should not happen in any scenario. A reasonable middle ground, if a medium level of assurance is warranted or desired by the DoD, would be to do a small random sampling of WFH employees. However, this would considerably increase the cost of an already extremely expensive assessment for very little gain, with the assumption that the only CUI present at a WFH is the electronic CUI on a laptop or PC's hard drive and potentially a locked drawer or two of paper CUI.
What if all of your storing and processing of CUI occurs in the cloud and only is displayed on your screen at home via a virtual desktop? My breakdown above doesn't really change too much. Your company has a location and an address for your DUNS, your CAGE code, and it is best to demonstrate your operating procedures to the assessor in the daily environment where that CUI is processed. Could you rent out a flex workspace to show your operating procedures and meet your assessor there as an alternative? Possibly but that would probably include its own caveats to make it acceptable.
My main takeaways:
Thanks for reading. Look forward to reading your comments on my opinion. My opinion subject to change when presented with new data.
CEO @ SolonTek | Network Administration, Security, Azure Cloud Administrator | SQL Server | Windows Server | CCNA | ISO 27001 Lead Auditor | Public Speaker | AI / Data Analytics | Python/Rust | HIPAA, NERC CIP,SOC, ISO
2 年Easy read btw and I definitely agree with your opinions.
IT/OT Cybersecurity & Risk Management | International Speaker | Adjunct Professor | Mentor
3 年Jeff Baldwin, in a previous post and discussion around asset marking and labeling, “…we've established that an appropriately configured VDI can de-scope an endpoint.” If I’m a WfH employee, have a properly configured VDI, and it is agreed during the assessment that the endpoint asset is de-scoped, is the alternate worksite (home) then also de-scoped by proxy, or am I incorrectly conflating to mutually exclusive elements?
Brain rental service for ISO certifications/accreditations.
3 年Debunked back in April. https://www.oxebridge.com/emma/cmmc-ab-triples-down-on-demanding-home-inspections-risking-dib-revolt/ CMMC-AB cannot generate a single approved assessor, but you want to add 90,000 extra assessment days to a company like Boeing, to audit each WFH employee? (Remember, Edens said "100%", so no sampling.) Good luck with that.
Director of GRC Engineering at Aquia | Anchored Ambition | Dad | Husband | Veteran | Mental Health Advocate | LinkedIn Top Voice | Keynote Speaker
3 年What?