SPONSORED CONTENT: Taking CMMC Seriously - What Is The Cost Of Compliance?

JSchaus & Associates
JSchaus & AssociatesFED Govt Contracts Consulting + 1 - 2 0 2 - 3 6 5 - 0 5 9 8 en JSchaus & Associates
Taking CMMC Seriously:
What is the Cost of
Compliance?
September, 19, 2023
Welcome!
Bill Wootton
Chief Revenue Officer
C3 Integrated Solutions
bwootton@C3isit.com
© 2023 C3 Integrated Solutions. All Rights Reserved.
3
Today’s Topics
▸Overview: Major Components of the Cost of CMMC
▸Building a Strategy
▸Deployment
▸Management and Monitoring
▸Compliance
▸Data Enclaves: Options and Impact
▸Three Types of Companies
Building a Strategy
© 2023 C3 Integrated Solutions. All Rights Reserved.
5
Building Your CMMC Strategy
Understanding
your business
Setting the
system
boundary
Determining the
organizational
impact
Determining
the expertise
you need
© 2023 C3 Integrated Solutions. All Rights Reserved.
6
Understanding Your Business
External Factors Internal Factors
▸ Your Customers…
▸ Which agencies do you work with?
▸ Your Partners…
▸ Who are your primes and subs?
▸ What are THEIR requirements to continue
working with them?
▸ Your Contracts…
▸ What clauses are already in your contracts?
▸ Your Future…
▸ Where will your business be in 2-3 years?
▸ Your Data…
▸ Do you have CUI?
▸ Do you have export-controlled data?
▸ Can you segment it from the rest of the
organization?
▸ Your People…
▸ Who directly interacts with CUI
▸ Who indirectly interacts with CUI?
▸ Your Systems…
▸ Which systems store, process, or transit
data?
The better you know your business, the less you will need a consultant to answer these questions.
© 2023 C3 Integrated Solutions. All Rights Reserved.
7
Company Examples: All 100-Person Firms
Research Firm
• Almost all commercial work
• Single DoD contract
• Team segmented from rest
of the firm
Manufacturing Firm
• Approximately 90% DoD
work
• Highly customized parts for
aircraft
• Large amounts of export-
controlled data
Professional Services
• Many distributed contracts
• Team members rotate
between DoD and civilian work
regularly
• Centralized admin supports all
contracts
Current systems are not compliant. No preexisting certifications (e.g. ISO
9001)
© 2023 C3 Integrated Solutions. All Rights Reserved.
8
Employee Access to CUI (100-person
Company)
????????
90 People 10 people
90 People
10 people
Commercial
Within CUI Boundary
Company 1 – Research
Firm
Company 3 – Professional Services Firm
Company 2 – Manufacturing Firm
© 2023 C3 Integrated Solutions. All Rights Reserved.
9
Determining System Boundaries: Enclave or
All-In?
ENCLAVE
Separate environment isolated
from the corporate environment
ALL-IN
Full configuration of corporate
environment to meet CMMC
requirements
Pros
▸ Reduced investment and scope
▸ Smaller attack surface
▸ More controlled system
boundary
▸ Limited (if any) data migration
Cons
▸ Swivel-seat user impact
▸ Illusion of cost savings
▸ Dual administration
▸ Unintended spillage
Pros
▸ Single, consolidated
environment
▸ Eliminates all technical debt
(fresh start)
Cons
▸ Data migration
▸ User impact
▸ Higher deployment costs
▸ Everyone is “locked down”
▸ Non-approved applications
© 2023 C3 Integrated Solutions. All Rights Reserved.
10
Enclave or All-In?
????????
90 People 10 people
90 People
10 people
Commercial
Within CUI Boundary
Company 1 – Research
Firm
Company 3 – Professional
Services
Company 2 - Manufacturing
Enclave
????
All-in
© 2023 C3 Integrated Solutions. All Rights Reserved.
11
Cost Drivers in Building a Strategy
Drivers Costs
▸ Knowledge of business
▸ Knowledge of data
▸ Current situation
▸ Technical debt
▸ Documentation
▸ Previous investment
▸ Internal resources
▸ Expertise/knowledge
▸ Availability
▸ Direct costs
▸ Outside consultant
▸ Internal effort
▸ Indirect costs
▸ Organization impact beyond IT
⁃ Business process changes
⁃ Segmenting and isolating data in an
enclave
▸ Impact of Strategy
⁃ Determines cost of the rest of the
process
▸ Confidence
▸ Risk of pursuing the wrong approach
Strategy costs are
not directly related to
the size of the
company. In most
cases, the scope of
effort drives the cost
profile.
Deployment
© 2023 C3 Integrated Solutions. All Rights Reserved.
13
Setting the System Boundary
System Boundary System Selection
• Communications
• E-mail
• Unified communications
• Collaboration
• Documents
• Other data
• CRM
• Financial
• Operational technology
• Access
• Virtual desktop
• Physical devices
• Mobile devices
• Cloud v. on-premises
• FedRAMP
• Export control
• US data residency
• US persons
Minimizing the
system boundary
reduces the services
that need to be fully
compliant
© 2023 C3 Integrated Solutions. All Rights Reserved.
14
Technology Costs
▸System selection
criteria
▸Accreditations
▸Attestations
▸Export control
▸GovCloud is
typically at least
30% higher
Commercial GCC GCC High
Data Centers Worldwide US Only US only
Accreditation FedRAMP
Moderate*
FedRAMP
Moderate
FedRAMP High
DFARS 7012 No Yes Yes
ITAR/EAR No No Yes
CUI/CDI No Maybe Yes
Customer
Support
Worldwide/Commercial
Personnel
Directory/Nt
k Azure Commercial Azure Gov
M365 G5
($/yr) $684 $684 $1120
Source: Understanding Compliance Between Microsoft 365 Commercial, GCC, GCC-High and DoD Offerings - Microsoft Community Hub
Microsoft 365 Example
Critical to choose the right systems that are accredited and can attest to requirements
© 2023 C3 Integrated Solutions. All Rights Reserved.
15
Deployment Costs
▸Provisioning
▸Establish the tenant
▸Configure
▸Should align to NIST SP 800-171
▸Data migration
▸Proportional to the size of the company
▸Microsoft 365 examples
⁃ Mailboxes
⁃ Teams and SharePoint
• Complexity – Workflows, etc.
Management and
Monitoring
© 2023 C3 Integrated Solutions. All Rights Reserved.
17
Management
Standard Services Compliant Services
▸ System administration
▸ Operational monitoring
▸ Patch management
▸ Support Desk
▸ Moves, adds, changes
▸ Documentation
▸ SLA
▸ SRM
▸ Standardized
procedures
▸ Configuration updates
▸ System reviews
▸ Support for GRC tool
▸ Assessment support
▸ U.S. based
If your corporate IT or
current MSP provider
cannot support
requirements (i.e. US
person only support),
an MSP specializing in
the DIB should be
considered.
© 2023 C3 Integrated Solutions. All Rights Reserved.
18
Monitoring – What to look for
▸ Automation
▸ Export control
▸ 24x7
▸ Documentation
▸SLA
▸SRM
▸IR Plan
▸ Assessment support
▸ Incident response
▸ Certifications
▸SOC-2
▸ Vulnerability scanning
Costs vary widely
depending on the
level of services and
the sophistication of
the solution.
Compliance
© 2023 C3 Integrated Solutions. All Rights Reserved.
20
Cost of Managing Compliance
Initial Costs Ongoing Costs
▸ Pre-assessment review
▸ Documentation
development
▸ System Security Plan (SSP)
▸ Policies
▸ Procedures
▸ Incident response plan
▸ Initial assessment
▸ Gap analysis
▸ POAM development
▸ Initial table-top
▸ Documentation
▸ Management and upkeep
▸ Integration with services?
▸ Assessment support
▸ Annual validations
▸ Table-top
▸ GRC tool
▸ Licensing
▸ Information upkeep
▸ Ad hoc consulting
Compliance costs have a
minimum threshold where
certain activities (i.e.
assessment) are required
regardless of company
size.
Back to Our Examples…
Numbers provided are for illustration purposes only.
© 2023 C3 Integrated Solutions. All Rights Reserved.
22
Cost Profile
Considerations
▸ Commercial v. GCCH M365
▸ IT support costs
▸ Monitoring costs
▸ Users swivel seat
▸ Double count users across both
environments
Not considered
▸ Additional applications
▸ Intangibles
▸User frustration
▸Overhead and administration of multiple
environments
Corporate Government
Microsoft
365
Commercial M365 G5
$57/month
GCC High M365
G5
$1120/year
IT Support
Internal
$150 month
equivalent
Outsourced
$200/month
Monitoring
Commercial Grade
$26/endpoint
Compliant
$35/endpoint
Strategy, deployment and cost of compliance
assumed comparable across examples unless noted.
© 2023 C3 Integrated Solutions. All Rights Reserved.
23
Pre-CMMC Annual IT Budget
▸M365 Commercial
▸G5 license
▸100 users
▸IT Support
▸$150/user cost of operation
▸May be internal or external
▸Monitoring
▸“Commercial grade”
▸$26/endpoint
▸Assume 100 endpoints
▸Annual budget: $279,600
$68,400
$180,00
0
$31,200
$-
$50,000
$100,000
$150,000
$200,000
$250,000
$300,000
Corporate
M365 IT Support Monitoring
© 2023 C3 Integrated Solutions. All Rights Reserved.
24
Company 1: Research Firm
▸GCC High enclave
▸10 users, M365 G5
▸Azure Virtual Desktop
▸User access
▸No additional applications
▸$2000/month usage
▸IT Support
▸$200/user, External vendor
▸Monitoring
▸$35/endpoint (virtual)
▸Total Budget: $343,700
$279,60
0
$64,100
$-
$50,000
$100,000
$150,000
$200,000
$250,000
$300,000
$350,000
$400,000
Annual Budget
Corporate Enclave
© 2023 C3 Integrated Solutions. All Rights Reserved.
25
Company 2: Manufacturing Firm
▸All-In
▸Microsoft 365 GCC High
▸100 users
▸Azure Virtual Desktop
▸Not required
▸Endpoints converted
▸IT Support
▸$200/user
▸External vendor
▸Monitoring
▸$35/endpoint (virtual)
▸Migration costs not considered
▸Total Budget: $401,000
$119,00
0
$240,00
0
$42,000
$-
$50,000
$100,000
$150,000
$200,000
$250,000
$300,000
$350,000
$400,000
$450,000
All-In
M365 IT Support Monitoring
© 2023 C3 Integrated Solutions. All Rights Reserved.
26
Company 3: Professional Services
▸ All-in or Enclave?
▸ Likely the most expensive from a
strategy development perspective
▸ Escalating commitment as users
are added
▸ Increased risk of unintended
spillage
▸ Increased user frustration and
confusion
▸ Break even to go all-in just under
30 users
* Does not consider other applications
nor strain of managing multiple
environments for both IT and users
$-
$100,000
$200,000
$300,000
$400,000
$500,000
$600,000
$700,000
$800,000
0 10 20 30 40 50 60 70 80 90 100
Commerical GCCH Enclave All-In
© 2023 C3 Integrated Solutions. All Rights Reserved.
27
About C3 Integrated Solutions
Technology
Experience
11 years Microsoft partner
6+ years experience in GCC
High
Multiple Gold competencies
Co-Sell Authorized
Client Experience
450+ Microsoft 365 clients
200+ GCC High clients
Deep NIST, DFARS, ITAR
experience
Industry Leader
First to offer GCC High
backup and hosted voice
CMMC Registered
Practitioner Organization
Two successful C3PAO
clients
Wrap-up and Questions
Get Started
Build the barriers that
protect your business,
not disrupt it.
Our mission is to protect sensitive data and prevent breaches by providing world-class
cybersecurity and compliance services to businesses of all sizes.
visit
c3isit.com
1 de 29

Recomendados

OPTIMIZING PIPELINES WITH MACHINE LEARNING DECISION SUPPORT por
OPTIMIZING PIPELINES WITH MACHINE LEARNING DECISION SUPPORTOPTIMIZING PIPELINES WITH MACHINE LEARNING DECISION SUPPORT
OPTIMIZING PIPELINES WITH MACHINE LEARNING DECISION SUPPORTwle-ss
20 vistas29 diapositivas
Cloud ROI and Implementation - A TechBlocks Solutions Guide por
Cloud ROI and Implementation - A TechBlocks Solutions GuideCloud ROI and Implementation - A TechBlocks Solutions Guide
Cloud ROI and Implementation - A TechBlocks Solutions GuideTechBlocks
367 vistas12 diapositivas
ITAM Tools Day, November 2015 - Concorde por
ITAM Tools Day, November 2015 - ConcordeITAM Tools Day, November 2015 - Concorde
ITAM Tools Day, November 2015 - ConcordeMartin Thompson
444 vistas14 diapositivas
The CMDB/CMS in the Digital Age: A Bedrock for IT Transformation por
The CMDB/CMS in the Digital Age: A Bedrock for IT TransformationThe CMDB/CMS in the Digital Age: A Bedrock for IT Transformation
The CMDB/CMS in the Digital Age: A Bedrock for IT TransformationEnterprise Management Associates
489 vistas46 diapositivas
Best Practices for Embedding Analytics by GoodData Product Leader por
Best Practices for Embedding Analytics by GoodData Product LeaderBest Practices for Embedding Analytics by GoodData Product Leader
Best Practices for Embedding Analytics by GoodData Product LeaderProduct School
134 vistas25 diapositivas
PCM Vision 2019 Keynote: Elliot Baretz por
PCM Vision 2019 Keynote: Elliot BaretzPCM Vision 2019 Keynote: Elliot Baretz
PCM Vision 2019 Keynote: Elliot BaretzPCM
592 vistas21 diapositivas

Más contenido relacionado

Similar a SPONSORED CONTENT: Taking CMMC Seriously - What Is The Cost Of Compliance?

How to Calculate ROI for Network Management & Monitoring por
How to Calculate ROI for Network Management & MonitoringHow to Calculate ROI for Network Management & Monitoring
How to Calculate ROI for Network Management & MonitoringSolarWinds
5.6K vistas23 diapositivas
Microsoft licensing analysis - an introduction por
Microsoft licensing analysis - an introductionMicrosoft licensing analysis - an introduction
Microsoft licensing analysis - an introductionNiels Jørgen Hansen
1.2K vistas38 diapositivas
CRMIT Solutions - An Overview por
CRMIT Solutions - An OverviewCRMIT Solutions - An Overview
CRMIT Solutions - An OverviewCRMIT
952 vistas17 diapositivas
AssetsHub Pitch Deck por
AssetsHub Pitch DeckAssetsHub Pitch Deck
AssetsHub Pitch DeckAssetsHub
25 vistas15 diapositivas
financial_close_and_disclosure_management_on_cloud por
financial_close_and_disclosure_management_on_cloudfinancial_close_and_disclosure_management_on_cloud
financial_close_and_disclosure_management_on_cloudCharles Wilson
378 vistas18 diapositivas
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ... por
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...ThousandEyes
87 vistas25 diapositivas

Similar a SPONSORED CONTENT: Taking CMMC Seriously - What Is The Cost Of Compliance? (20)

How to Calculate ROI for Network Management & Monitoring por SolarWinds
How to Calculate ROI for Network Management & MonitoringHow to Calculate ROI for Network Management & Monitoring
How to Calculate ROI for Network Management & Monitoring
SolarWinds5.6K vistas
CRMIT Solutions - An Overview por CRMIT
CRMIT Solutions - An OverviewCRMIT Solutions - An Overview
CRMIT Solutions - An Overview
CRMIT952 vistas
AssetsHub Pitch Deck por AssetsHub
AssetsHub Pitch DeckAssetsHub Pitch Deck
AssetsHub Pitch Deck
AssetsHub25 vistas
financial_close_and_disclosure_management_on_cloud por Charles Wilson
financial_close_and_disclosure_management_on_cloudfinancial_close_and_disclosure_management_on_cloud
financial_close_and_disclosure_management_on_cloud
Charles Wilson378 vistas
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ... por ThousandEyes
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...
ThousandEyes87 vistas
VMSDeploymentGuide_Extract1a por Tom - Creed
VMSDeploymentGuide_Extract1aVMSDeploymentGuide_Extract1a
VMSDeploymentGuide_Extract1a
Tom - Creed51 vistas
Under cloud cover: How leaders are accelerating competitive differentiation por Susanne Hupfer, Ph.D.
Under cloud cover: How leaders are accelerating competitive differentiationUnder cloud cover: How leaders are accelerating competitive differentiation
Under cloud cover: How leaders are accelerating competitive differentiation
Migrating apps-to-the-cloud-final por eng999
Migrating apps-to-the-cloud-finalMigrating apps-to-the-cloud-final
Migrating apps-to-the-cloud-final
eng999289 vistas
Bhawani prasad mdm-cdi-methodology por Bhawani N Prasad
Bhawani prasad mdm-cdi-methodologyBhawani prasad mdm-cdi-methodology
Bhawani prasad mdm-cdi-methodology
Bhawani N Prasad1.5K vistas
How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2... por Ignyte Assurance Platform
How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2...How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2...
How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2...
MongoDB World 2019: Data Digital Decoupling por MongoDB
MongoDB World 2019: Data Digital DecouplingMongoDB World 2019: Data Digital Decoupling
MongoDB World 2019: Data Digital Decoupling
MongoDB602 vistas
Critical functionality testing por Maveric Systems
Critical functionality testingCritical functionality testing
Critical functionality testing
Maveric Systems4.3K vistas
Preview novarica1908 eb-core-business_case por ~Eric Principe
Preview novarica1908 eb-core-business_casePreview novarica1908 eb-core-business_case
Preview novarica1908 eb-core-business_case
~Eric Principe25 vistas
The Advantages and Pitfalls of Data Centre Consolidation por DAYWATCHER.COM
The Advantages and Pitfalls of Data Centre ConsolidationThe Advantages and Pitfalls of Data Centre Consolidation
The Advantages and Pitfalls of Data Centre Consolidation
DAYWATCHER.COM551 vistas
Planning for Cloud Profitability From Day One: MSP VAR Companies and Cloud Co... por ProfitBricks
Planning for Cloud Profitability From Day One: MSP VAR Companies and Cloud Co...Planning for Cloud Profitability From Day One: MSP VAR Companies and Cloud Co...
Planning for Cloud Profitability From Day One: MSP VAR Companies and Cloud Co...
ProfitBricks960 vistas

Más de JSchaus & Associates

SPONSORED CONTENT: Finding Federal Contract Opportunities (Part 1 Of 2) por
SPONSORED CONTENT: Finding Federal Contract Opportunities (Part 1 Of 2)SPONSORED CONTENT: Finding Federal Contract Opportunities (Part 1 Of 2)
SPONSORED CONTENT: Finding Federal Contract Opportunities (Part 1 Of 2)JSchaus & Associates
36 vistas21 diapositivas
Top 40 Federal Contractors - PROFILE #40 - GSK Glaxo Smith Kline por
Top 40 Federal Contractors - PROFILE #40 - GSK Glaxo Smith KlineTop 40 Federal Contractors - PROFILE #40 - GSK Glaxo Smith Kline
Top 40 Federal Contractors - PROFILE #40 - GSK Glaxo Smith KlineJSchaus & Associates
20 vistas81 diapositivas
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps Construction por
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps ConstructionTop 40 Federal Contractors - PROFILE #39 - Hensel Phelps Construction
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps ConstructionJSchaus & Associates
18 vistas77 diapositivas
Top 40 Federal Contractors - PROFILE #38 - Dell por
Top 40 Federal Contractors - PROFILE #38 - DellTop 40 Federal Contractors - PROFILE #38 - Dell
Top 40 Federal Contractors - PROFILE #38 - DellJSchaus & Associates
14 vistas75 diapositivas
Top 40 Federal Contractors - PROFILE #37 - CACI por
Top 40 Federal Contractors - PROFILE #37 - CACITop 40 Federal Contractors - PROFILE #37 - CACI
Top 40 Federal Contractors - PROFILE #37 - CACIJSchaus & Associates
43 vistas76 diapositivas
GSA Schedules - Requirements & Strategies For Success por
GSA Schedules - Requirements & Strategies For SuccessGSA Schedules - Requirements & Strategies For Success
GSA Schedules - Requirements & Strategies For SuccessJSchaus & Associates
19 vistas46 diapositivas

Más de JSchaus & Associates(20)

SPONSORED CONTENT: Finding Federal Contract Opportunities (Part 1 Of 2) por JSchaus & Associates
SPONSORED CONTENT: Finding Federal Contract Opportunities (Part 1 Of 2)SPONSORED CONTENT: Finding Federal Contract Opportunities (Part 1 Of 2)
SPONSORED CONTENT: Finding Federal Contract Opportunities (Part 1 Of 2)
Top 40 Federal Contractors - PROFILE #40 - GSK Glaxo Smith Kline por JSchaus & Associates
Top 40 Federal Contractors - PROFILE #40 - GSK Glaxo Smith KlineTop 40 Federal Contractors - PROFILE #40 - GSK Glaxo Smith Kline
Top 40 Federal Contractors - PROFILE #40 - GSK Glaxo Smith Kline
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps Construction por JSchaus & Associates
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps ConstructionTop 40 Federal Contractors - PROFILE #39 - Hensel Phelps Construction
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps Construction
Top 40 Federal Contractors - PROFILE #34 - Steel and Shipbuilding Company por JSchaus & Associates
Top 40 Federal Contractors - PROFILE #34 - Steel and Shipbuilding CompanyTop 40 Federal Contractors - PROFILE #34 - Steel and Shipbuilding Company
Top 40 Federal Contractors - PROFILE #34 - Steel and Shipbuilding Company
GSA Schedule: Requirements, Proposal Prep and - What's Next por JSchaus & Associates
GSA Schedule: Requirements, Proposal Prep and - What's NextGSA Schedule: Requirements, Proposal Prep and - What's Next
GSA Schedule: Requirements, Proposal Prep and - What's Next
Top 40 Federal Contractors - PROFILE #29 - National Security por JSchaus & Associates
Top 40 Federal Contractors - PROFILE #29 - National SecurityTop 40 Federal Contractors - PROFILE #29 - National Security
Top 40 Federal Contractors - PROFILE #29 - National Security
Top 40 Federal Contractors - PROFILE #27 - Oshkosh Defense por JSchaus & Associates
Top 40 Federal Contractors - PROFILE #27 - Oshkosh DefenseTop 40 Federal Contractors - PROFILE #27 - Oshkosh Defense
Top 40 Federal Contractors - PROFILE #27 - Oshkosh Defense

Último

Advancing innovation for Global Aviation Development por
Advancing innovation for Global Aviation DevelopmentAdvancing innovation for Global Aviation Development
Advancing innovation for Global Aviation DevelopmentChristina Parmionova
5 vistas1 diapositiva
COP28 President Launches Global Decarbonization Accelerator por
COP28 President Launches Global Decarbonization AcceleratorCOP28 President Launches Global Decarbonization Accelerator
COP28 President Launches Global Decarbonization AcceleratorEnergy for One World
40 vistas3 diapositivas
Mukhya Mantri Gramin Peyjal Nishchay Yojana (MGPNY) – Bihar_Pankaj Kumar_AKRS... por
Mukhya Mantri Gramin Peyjal Nishchay Yojana (MGPNY) – Bihar_Pankaj Kumar_AKRS...Mukhya Mantri Gramin Peyjal Nishchay Yojana (MGPNY) – Bihar_Pankaj Kumar_AKRS...
Mukhya Mantri Gramin Peyjal Nishchay Yojana (MGPNY) – Bihar_Pankaj Kumar_AKRS...India Water Portal
22 vistas15 diapositivas
November-2023 PPT roadsafetysuperoheros full slides.ppt por
November-2023 PPT roadsafetysuperoheros full slides.pptNovember-2023 PPT roadsafetysuperoheros full slides.ppt
November-2023 PPT roadsafetysuperoheros full slides.pptINDIAN YOUTH SECURED ORGANISATION
7 vistas30 diapositivas
Advancing and democratizing business data in Canada- Patrick Gill & Stephen Tapp por
Advancing and democratizing business data in Canada- Patrick Gill & Stephen TappAdvancing and democratizing business data in Canada- Patrick Gill & Stephen Tapp
Advancing and democratizing business data in Canada- Patrick Gill & Stephen TappOECD CFE
7 vistas16 diapositivas
Support Girl students with Education por
Support Girl students with EducationSupport Girl students with Education
Support Girl students with EducationSERUDS INDIA
7 vistas6 diapositivas

Último(20)

COP28 President Launches Global Decarbonization Accelerator por Energy for One World
COP28 President Launches Global Decarbonization AcceleratorCOP28 President Launches Global Decarbonization Accelerator
COP28 President Launches Global Decarbonization Accelerator
Mukhya Mantri Gramin Peyjal Nishchay Yojana (MGPNY) – Bihar_Pankaj Kumar_AKRS... por India Water Portal
Mukhya Mantri Gramin Peyjal Nishchay Yojana (MGPNY) – Bihar_Pankaj Kumar_AKRS...Mukhya Mantri Gramin Peyjal Nishchay Yojana (MGPNY) – Bihar_Pankaj Kumar_AKRS...
Mukhya Mantri Gramin Peyjal Nishchay Yojana (MGPNY) – Bihar_Pankaj Kumar_AKRS...
India Water Portal22 vistas
Advancing and democratizing business data in Canada- Patrick Gill & Stephen Tapp por OECD CFE
Advancing and democratizing business data in Canada- Patrick Gill & Stephen TappAdvancing and democratizing business data in Canada- Patrick Gill & Stephen Tapp
Advancing and democratizing business data in Canada- Patrick Gill & Stephen Tapp
OECD CFE7 vistas
Support Girl students with Education por SERUDS INDIA
Support Girl students with EducationSupport Girl students with Education
Support Girl students with Education
SERUDS INDIA7 vistas
Job Posting - Fire Inspector, PT.pdf por NorthwestBOCA
Job Posting - Fire Inspector, PT.pdfJob Posting - Fire Inspector, PT.pdf
Job Posting - Fire Inspector, PT.pdf
NorthwestBOCA28 vistas
Case study of Gokarna Multi-village scheme, Kumta, Karnataka_IIM-B_2023.pdf por India Water Portal
Case study of Gokarna Multi-village scheme, Kumta, Karnataka_IIM-B_2023.pdfCase study of Gokarna Multi-village scheme, Kumta, Karnataka_IIM-B_2023.pdf
Case study of Gokarna Multi-village scheme, Kumta, Karnataka_IIM-B_2023.pdf
Ending Stagnation: A New Economic Strategy for Britain por ResolutionFoundation
Ending Stagnation: A New Economic Strategy for BritainEnding Stagnation: A New Economic Strategy for Britain
Ending Stagnation: A New Economic Strategy for Britain
ResolutionFoundation1.5K vistas
COP 28 GHANA DELEGATES.docx por Kweku Zurek
COP 28 GHANA DELEGATES.docxCOP 28 GHANA DELEGATES.docx
COP 28 GHANA DELEGATES.docx
Kweku Zurek6.7K vistas
Financial sustainability of schemes managed by PHED in Punjab_Krishnakumar Th... por India Water Portal
Financial sustainability of schemes managed by PHED in Punjab_Krishnakumar Th...Financial sustainability of schemes managed by PHED in Punjab_Krishnakumar Th...
Financial sustainability of schemes managed by PHED in Punjab_Krishnakumar Th...
India Water Portal10 vistas
Social behavioural change to drive community ownership_ Divyang Waghela_Tata ... por India Water Portal
Social behavioural change to drive community ownership_ Divyang Waghela_Tata ...Social behavioural change to drive community ownership_ Divyang Waghela_Tata ...
Social behavioural change to drive community ownership_ Divyang Waghela_Tata ...
India Water Portal13 vistas

SPONSORED CONTENT: Taking CMMC Seriously - What Is The Cost Of Compliance?

  • 1. Taking CMMC Seriously: What is the Cost of Compliance? September, 19, 2023
  • 2. Welcome! Bill Wootton Chief Revenue Officer C3 Integrated Solutions bwootton@C3isit.com
  • 3. © 2023 C3 Integrated Solutions. All Rights Reserved. 3 Today’s Topics ▸Overview: Major Components of the Cost of CMMC ▸Building a Strategy ▸Deployment ▸Management and Monitoring ▸Compliance ▸Data Enclaves: Options and Impact ▸Three Types of Companies
  • 5. © 2023 C3 Integrated Solutions. All Rights Reserved. 5 Building Your CMMC Strategy Understanding your business Setting the system boundary Determining the organizational impact Determining the expertise you need
  • 6. © 2023 C3 Integrated Solutions. All Rights Reserved. 6 Understanding Your Business External Factors Internal Factors ▸ Your Customers… ▸ Which agencies do you work with? ▸ Your Partners… ▸ Who are your primes and subs? ▸ What are THEIR requirements to continue working with them? ▸ Your Contracts… ▸ What clauses are already in your contracts? ▸ Your Future… ▸ Where will your business be in 2-3 years? ▸ Your Data… ▸ Do you have CUI? ▸ Do you have export-controlled data? ▸ Can you segment it from the rest of the organization? ▸ Your People… ▸ Who directly interacts with CUI ▸ Who indirectly interacts with CUI? ▸ Your Systems… ▸ Which systems store, process, or transit data? The better you know your business, the less you will need a consultant to answer these questions.
  • 7. © 2023 C3 Integrated Solutions. All Rights Reserved. 7 Company Examples: All 100-Person Firms Research Firm • Almost all commercial work • Single DoD contract • Team segmented from rest of the firm Manufacturing Firm • Approximately 90% DoD work • Highly customized parts for aircraft • Large amounts of export- controlled data Professional Services • Many distributed contracts • Team members rotate between DoD and civilian work regularly • Centralized admin supports all contracts Current systems are not compliant. No preexisting certifications (e.g. ISO 9001)
  • 8. © 2023 C3 Integrated Solutions. All Rights Reserved. 8 Employee Access to CUI (100-person Company) ???????? 90 People 10 people 90 People 10 people Commercial Within CUI Boundary Company 1 – Research Firm Company 3 – Professional Services Firm Company 2 – Manufacturing Firm
  • 9. © 2023 C3 Integrated Solutions. All Rights Reserved. 9 Determining System Boundaries: Enclave or All-In? ENCLAVE Separate environment isolated from the corporate environment ALL-IN Full configuration of corporate environment to meet CMMC requirements Pros ▸ Reduced investment and scope ▸ Smaller attack surface ▸ More controlled system boundary ▸ Limited (if any) data migration Cons ▸ Swivel-seat user impact ▸ Illusion of cost savings ▸ Dual administration ▸ Unintended spillage Pros ▸ Single, consolidated environment ▸ Eliminates all technical debt (fresh start) Cons ▸ Data migration ▸ User impact ▸ Higher deployment costs ▸ Everyone is “locked down” ▸ Non-approved applications
  • 10. © 2023 C3 Integrated Solutions. All Rights Reserved. 10 Enclave or All-In? ???????? 90 People 10 people 90 People 10 people Commercial Within CUI Boundary Company 1 – Research Firm Company 3 – Professional Services Company 2 - Manufacturing Enclave ???? All-in
  • 11. © 2023 C3 Integrated Solutions. All Rights Reserved. 11 Cost Drivers in Building a Strategy Drivers Costs ▸ Knowledge of business ▸ Knowledge of data ▸ Current situation ▸ Technical debt ▸ Documentation ▸ Previous investment ▸ Internal resources ▸ Expertise/knowledge ▸ Availability ▸ Direct costs ▸ Outside consultant ▸ Internal effort ▸ Indirect costs ▸ Organization impact beyond IT ⁃ Business process changes ⁃ Segmenting and isolating data in an enclave ▸ Impact of Strategy ⁃ Determines cost of the rest of the process ▸ Confidence ▸ Risk of pursuing the wrong approach Strategy costs are not directly related to the size of the company. In most cases, the scope of effort drives the cost profile.
  • 13. © 2023 C3 Integrated Solutions. All Rights Reserved. 13 Setting the System Boundary System Boundary System Selection • Communications • E-mail • Unified communications • Collaboration • Documents • Other data • CRM • Financial • Operational technology • Access • Virtual desktop • Physical devices • Mobile devices • Cloud v. on-premises • FedRAMP • Export control • US data residency • US persons Minimizing the system boundary reduces the services that need to be fully compliant
  • 14. © 2023 C3 Integrated Solutions. All Rights Reserved. 14 Technology Costs ▸System selection criteria ▸Accreditations ▸Attestations ▸Export control ▸GovCloud is typically at least 30% higher Commercial GCC GCC High Data Centers Worldwide US Only US only Accreditation FedRAMP Moderate* FedRAMP Moderate FedRAMP High DFARS 7012 No Yes Yes ITAR/EAR No No Yes CUI/CDI No Maybe Yes Customer Support Worldwide/Commercial Personnel Directory/Nt k Azure Commercial Azure Gov M365 G5 ($/yr) $684 $684 $1120 Source: Understanding Compliance Between Microsoft 365 Commercial, GCC, GCC-High and DoD Offerings - Microsoft Community Hub Microsoft 365 Example Critical to choose the right systems that are accredited and can attest to requirements
  • 15. © 2023 C3 Integrated Solutions. All Rights Reserved. 15 Deployment Costs ▸Provisioning ▸Establish the tenant ▸Configure ▸Should align to NIST SP 800-171 ▸Data migration ▸Proportional to the size of the company ▸Microsoft 365 examples ⁃ Mailboxes ⁃ Teams and SharePoint • Complexity – Workflows, etc.
  • 17. © 2023 C3 Integrated Solutions. All Rights Reserved. 17 Management Standard Services Compliant Services ▸ System administration ▸ Operational monitoring ▸ Patch management ▸ Support Desk ▸ Moves, adds, changes ▸ Documentation ▸ SLA ▸ SRM ▸ Standardized procedures ▸ Configuration updates ▸ System reviews ▸ Support for GRC tool ▸ Assessment support ▸ U.S. based If your corporate IT or current MSP provider cannot support requirements (i.e. US person only support), an MSP specializing in the DIB should be considered.
  • 18. © 2023 C3 Integrated Solutions. All Rights Reserved. 18 Monitoring – What to look for ▸ Automation ▸ Export control ▸ 24x7 ▸ Documentation ▸SLA ▸SRM ▸IR Plan ▸ Assessment support ▸ Incident response ▸ Certifications ▸SOC-2 ▸ Vulnerability scanning Costs vary widely depending on the level of services and the sophistication of the solution.
  • 20. © 2023 C3 Integrated Solutions. All Rights Reserved. 20 Cost of Managing Compliance Initial Costs Ongoing Costs ▸ Pre-assessment review ▸ Documentation development ▸ System Security Plan (SSP) ▸ Policies ▸ Procedures ▸ Incident response plan ▸ Initial assessment ▸ Gap analysis ▸ POAM development ▸ Initial table-top ▸ Documentation ▸ Management and upkeep ▸ Integration with services? ▸ Assessment support ▸ Annual validations ▸ Table-top ▸ GRC tool ▸ Licensing ▸ Information upkeep ▸ Ad hoc consulting Compliance costs have a minimum threshold where certain activities (i.e. assessment) are required regardless of company size.
  • 21. Back to Our Examples… Numbers provided are for illustration purposes only.
  • 22. © 2023 C3 Integrated Solutions. All Rights Reserved. 22 Cost Profile Considerations ▸ Commercial v. GCCH M365 ▸ IT support costs ▸ Monitoring costs ▸ Users swivel seat ▸ Double count users across both environments Not considered ▸ Additional applications ▸ Intangibles ▸User frustration ▸Overhead and administration of multiple environments Corporate Government Microsoft 365 Commercial M365 G5 $57/month GCC High M365 G5 $1120/year IT Support Internal $150 month equivalent Outsourced $200/month Monitoring Commercial Grade $26/endpoint Compliant $35/endpoint Strategy, deployment and cost of compliance assumed comparable across examples unless noted.
  • 23. © 2023 C3 Integrated Solutions. All Rights Reserved. 23 Pre-CMMC Annual IT Budget ▸M365 Commercial ▸G5 license ▸100 users ▸IT Support ▸$150/user cost of operation ▸May be internal or external ▸Monitoring ▸“Commercial grade” ▸$26/endpoint ▸Assume 100 endpoints ▸Annual budget: $279,600 $68,400 $180,00 0 $31,200 $- $50,000 $100,000 $150,000 $200,000 $250,000 $300,000 Corporate M365 IT Support Monitoring
  • 24. © 2023 C3 Integrated Solutions. All Rights Reserved. 24 Company 1: Research Firm ▸GCC High enclave ▸10 users, M365 G5 ▸Azure Virtual Desktop ▸User access ▸No additional applications ▸$2000/month usage ▸IT Support ▸$200/user, External vendor ▸Monitoring ▸$35/endpoint (virtual) ▸Total Budget: $343,700 $279,60 0 $64,100 $- $50,000 $100,000 $150,000 $200,000 $250,000 $300,000 $350,000 $400,000 Annual Budget Corporate Enclave
  • 25. © 2023 C3 Integrated Solutions. All Rights Reserved. 25 Company 2: Manufacturing Firm ▸All-In ▸Microsoft 365 GCC High ▸100 users ▸Azure Virtual Desktop ▸Not required ▸Endpoints converted ▸IT Support ▸$200/user ▸External vendor ▸Monitoring ▸$35/endpoint (virtual) ▸Migration costs not considered ▸Total Budget: $401,000 $119,00 0 $240,00 0 $42,000 $- $50,000 $100,000 $150,000 $200,000 $250,000 $300,000 $350,000 $400,000 $450,000 All-In M365 IT Support Monitoring
  • 26. © 2023 C3 Integrated Solutions. All Rights Reserved. 26 Company 3: Professional Services ▸ All-in or Enclave? ▸ Likely the most expensive from a strategy development perspective ▸ Escalating commitment as users are added ▸ Increased risk of unintended spillage ▸ Increased user frustration and confusion ▸ Break even to go all-in just under 30 users * Does not consider other applications nor strain of managing multiple environments for both IT and users $- $100,000 $200,000 $300,000 $400,000 $500,000 $600,000 $700,000 $800,000 0 10 20 30 40 50 60 70 80 90 100 Commerical GCCH Enclave All-In
  • 27. © 2023 C3 Integrated Solutions. All Rights Reserved. 27 About C3 Integrated Solutions Technology Experience 11 years Microsoft partner 6+ years experience in GCC High Multiple Gold competencies Co-Sell Authorized Client Experience 450+ Microsoft 365 clients 200+ GCC High clients Deep NIST, DFARS, ITAR experience Industry Leader First to offer GCC High backup and hosted voice CMMC Registered Practitioner Organization Two successful C3PAO clients
  • 29. Get Started Build the barriers that protect your business, not disrupt it. Our mission is to protect sensitive data and prevent breaches by providing world-class cybersecurity and compliance services to businesses of all sizes. visit c3isit.com