logo

NJP

Explore CMMC:​ Automation of NIST 800-171 assessments and vendor questionnaires using ServiceNow

Import · Aug 01, 2023 · video

hello everybody and welcome to our webinar today it's live on service now and on servicenow community and I am Roslyn Memorial and I'm delighted to bring you today the cmmc 2.0 accelerator on servicenow I have with me guests from security books and I'm really excited to talk to you about what they have in the store and it's just live and available today and we're going to go through uh just a little bit about the product and then through a demo and I'll introduce Sarah but before we get started I do have a little bit of a couple of housekeeping issues to get started so if you can move on to the next slide that would be great there seems to be a little bit of delay because I've moved slides okay all right well we've got to several people online someone was asking who's speaking so it's Roswell Marvel and Sarah speaking um Sarah can you see if you can um unshare and share again and see if that helps we got it how's that great I can see the housekeeping the slide fantastic fantastic so I'll just wait one second so before we get started I just want to let everyone know that they're automatically placed on you if you do have questions please use the Q a feature rather than the chat to ask questions we'd be happy to chat or have you uh follow along with a conversation and add antidotes into the chat but the Q a is the easiest way for both for us to answer those questions and also follow up if we don't have time to get any questions answered during this session we are reporting the session and it will be available in the community afterwards and at the end of the session you will be prompted to fill out a short survey we really appreciate your feedback we're just using that internally to understand how we can better services next slide So speaking about this session we're excited to have security bricks here today um but we do have a lot of live risk webinars coming up in the near future because we are coming out with our latest release so we've got what's new in business continuity happening on August 10th and you'll be joined by me on that one as well as the third party risk management session on the 15th and then we've got what's new in Risk Management on the 17th compliance case management we're going to be doing an on-demand session for that and then policy and compliance will wrap up um our sessions at the end of the month so definitely uh look forward to that I think that is on the 24th but all those sessions are available in the community and we will have a sign up form at the end of this presentation so definitely uh check out for that um but we're happy to share any information on that in the chat if you do need more additional information on signing up so next slide all right folks so um I'm Sarah Lang and I'm going to go ahead and go through our agenda and talk a little bit about cmmc so we're going to cover what the new DOD regulations are what cnnc 2.0 is and how the servicenow can and accelerators will be able to help your organization in achieving the cmmc compliance and then we're going to follow that up by a short demo um security bricks is a consulting firm here in the U.S um all of our consultants and employers are U.S citizens and we stagger the four time zones here um with a minimum of 15 years of experience that we bring including DOD experience as well and our certifications for our assessors include cissp ceh Chris and the system so this covers a little bit about who we are and talks about um our Partnerships so we are a Fed ramp third party assessor organization or also servicenow partners and state ramp assessment organizations as well um and so we've taken all of our experience in these areas and brought together um with servicenow an application to really help each one of you and uh managing and maintaining your cmmc so we've already covered this a little bit about our Focus areas um so our Focus areas are here um we also have a platform called appstone that helps to secure the software supply chain for a third-party risk management so a little bit about cmnc so I'll cover a little bit about some of the acronyms you're going to hear things like cui and FCI so cui is called control unclassified controlled information so what this means is it's information that's not publicly available they consider it sensitive information that if possessed or published and available to people that did not have a need to know could potentially lead to a security breach FCI um is information that's not intended for public release as well that has a different classification and this could be things like contracts pii all right um goods and services right and the delivery of those items as well and uh what is the 800 171 framework that is a nist standard um that is what cmmc is built off of so this is basically a security framework um for all non-federal computer systems um that need to implement that standard and that is for anyone that is going to be working with the dod that processes stores or transmits FCI or cui data right now what that looks like um it is currently implemented as part of dfars which is already there um and it is as a self-assessment today which means organizations have to implement and do a self-assessment of the 800 171 controls write up a system security plan documenting their environment and then they submit it currently through What's called the sprs which is the EMASS and that gets submitted as a self-assessment and then it is reviewed by um the dod to validate the implementation what it's moving to is going to be to cmmc which is the new um framework that has been um developed let me go back there how that has been developed as well UMC is going to do is it's going to go ahead and require all contractors to protect the control that classified information and all non-verbal systems so if you are planning on doing business with DOD either currently are or plan in the future this will apply to you um there are currently three levels of um classifications for contractors the first two have been published which is level one and level two and level three is currently in development so we know that level three is going to be for the the more sensitive data uh could be for the organizations that then there's a higher risk level and so the controls and how those controls will be implemented are going to be a little bit more stringing um this will become part of uh any rfps that the dod puts out so anyone that's going to submit a proposal for an uh an RFP or an RFI that the drd puts out we'll need to meet this and it also is going to pertain to any current DOD contractors um one key thing to know is that on here it is also going to apply to all subcontractors for the bidding agency so at 800 171 um is going to be broken out by its 110 controls and out of those controls each control has a series of what they considered implementation requirements so you have control a and there will be maybe two or three things that you have to have in place in order to say that you've implemented control a um 800 171 is broken down around 15 control families each family covers a different aspect of protecting cui and it is mapped back to the nist CSF or identify protect detect respond and recover functions this is kind of a little table um to cover the 800 171 framework so what you'll notice here on this table if there's a significant amount of Technical and administrative controls so if you see it's kind of balanced right it's not only do you have to have technical controls in place to protect this data but you also have to have it documented you need to have policies procedures and standards that are going to be used to implement those policies and then those need to be put into practice and it also includes um Gathering evidence for all of these controls so that you can satisfy your assessors to provide to show that you not only have implemented them but you're ongoing continuous monitoring and that you're following all of your procedures that you have in place so we covered a little bit about the cnnc levels um so let's go take a little bit of a deeper dive into these today so what is level one this is considered the foundational level so this is where you're doing an annual self-assessment there's only 17 practices within level one so it's thin down a little bit there's less implementation requirements um this is a considered basic cyber hygiene right um and yes can you track for one second um there are Parts on this when your voice is going out your um mic is moving a little bit so I don't know uh minimize that at all as possible let me see if I can get a little closer is that better that's great I think it's sometimes when you're moving around but that's great okay um so the self-assessments are going to be something where an organization isn't going to be required to have an actual third-party assessment organization do an audit against their controls but they are going to have to complete their system security plan and they're going to have to do a self-assessment of the controls that apply to them and they're going to have to submit all of that documentation and attest to the reporting that they're including level two is a little bit more advanced this is where you get into the controlled unclassified information um there is a total of the 110 controls that apply and you will have to have a third party assessment organization um conduct an audit and provide the assessment reports for your organization to validate your implementation and then of course level three right now is TBD and this is because it's still under development it's been going through some changes so online you'll find some documentation uh related to what they think level three will be but it is still currently in development so when we talk about cmnc it it is very similar to anyone here on the call it's familiar to fedrap um to a physical process and which also aligns which is what is your authorization boundary all right so this is where you really have to know your environment this is where your asset inventory your cmdb really comes into play understanding your applications and your data flow is going to be key because once you acknowledge and accept your authorization boundary then you're going to have to start documenting everything within that boundary and any interconnections into and out of that boundary that may occur that um usually takes quite a bit of time for most organizations right because it you really are going to have to have a solid um inventory and understanding of your systems and their functions in order to be able to create this boundary from there there's this requirement to have what's called a system security plan on average the SSP typically will run anywhere from 350 to 400 Pages for cmnc sspm and in here you not only have to document what your business is what your product is your organizational structure for security um your incident response how you've implemented every single control of the 110 controls um you need to document your data flows so it's a real detailed document that will be done and you're really pulling in data from everywhere there's a you know from HR through IT service desk incident response your security operations teams um all of this will come together and then of course those two both are dependent on this asset inventory what are all of the assets that are going to be part of that boundary what are your security protection assets do you have a SIM or are you currently in the cloud is it a data center what types of tools are you using right um and then your poem so a poem is short for plan of action and Milestones and what plan is is it's basically a running risk register all right so these are all of the gaps that have been identified within your boundary so whether or not it's anything from not being able to implement a control to uh maybe having a system who can't patch apply a patch to right so anything that would present a risk to that data in which case it gets documented um and that document gets monitored and you continuously review and try to implement a defense in-depth strategy to reduce the risk to an acceptable level yeah once you get through those your next step is really going to be about assessment evidence so what are artifacts so this is where you're going to be gathering screen prints documents right reports can you send me a report on the latest incident response event that we occurred I need to have all the details of the um event starting from when it was initially reported all the way through to the investigation completion and the final after Action Report right that would be considered evidence and then you're also going to be looking at your inherited controls so if you are in a cloud environment right you will inherit some controls from that environment those kids clothes will vary you know are you in AWS gcp Azure are you in the government you know so say Azure government or are you going to be a commercial which level are you are you using an E3 license or an E5 license because every one of those will come in and add an additional narrative controls that you will be able to take advantage of if you're using an mssp for anything you'll inherit some controls from them and so you're going to need to work with those managed service providers to find out how they implemented certain things on their end and incorporate that as well okay vulnerability management it's always really big right we know from all of the breaches that we have seen out there that it really just takes one system to have one vulnerability that a bad actor can take advantage of and even if that system itself doesn't hold sensitive data it may actually be able to lead somebody to hop through your network and get to that sensitive data so there is um high priority on vulnerability management Within cnmc all right so critical and high vulnerabilities get reported application security vulnerabilities a lot of times people stay at that level of vulnerability management looking at their infrastructure but they're not looking at the applications themselves um you will be required to not only provide the latest scanning results as an artifact but they're going to want to look at things like your time to close time to patch values so some kpis and Kris will need to be provided as well and they're going to validate that they're going to look at the data out of the scans we're going to say how often are you scanning adopted already patching how is that patching maintenance looking oh and does that also light up with the documentation that you've provided um they're also looking at vulnerability scanning at how are you running these scans are they credentialed scans all right so that you can actually get in and access and do a deeper dive into the vulnerability management of a system next is the security configurations all right so c3paos which is a certified third-party assessor all right we're going to be asking for evidence in terms of it asset configurations we're going to want to look at your endpoint devices firewall rules your server configurations Cloud configurations um we're going to be looking not only at how it's been implemented but how what are your plans and processes for maintaining it um they are usually assessed against an industry Benchmark so the organization can decide you know are we using CIS are we using stigs you know how are we adopting a security Benchmark for hardening our systems is that potentially are we using azure's blueprints or aws's gold images right um as well and then sometimes security configurations can become really difficult to report accurately especially if you're in a multi-computing boundary if you're using multiple clouds um not all Cloud providers provide excellent reporting to just export your configuration so there's a lot of manual work that could go into having to document those hardening procedures that are in place next we've got the pane of manual process right so currently cmfc assessments involve very manual processes to identify the assets Define the boundary and gather all the evidence you're managing and gathering information and working with all the various groups within your organization you're looking at and managing gathering information through your subcontractors all your vendors and suppliers um you're also going to be looking at your mssps your any staff service that you're are signed up for and using within that boundary you're going to be talking to and looking at your thoughts or providers so there's a lot of moving parts and pieces to putting cmmc puzzle together and that alone usually takes a significant amount of resource and time to gather that much information and I'm going to throw a little monkey wrench in here all your evidence that you have to use for your assessment cannot be older than 30 days so you'll do this twice once as you're preparing and getting ready to see make sure you um can pass your cmmc audit and then again right before your assessment date approaches you're going to have to go through the same function again to update all of your evidence that you've gathered so now we're going to kind of go into how to servicenow help with this right so servicenows cam The Continuous authorization and monitoring module allows um in creating the assistant creating the authorization boundary with data from the cmdb so this is huge right no manual mapping and spreadsheets that you're going to have to use um creation of the SSP so that alone I mean I've written ssps and I'm going to tell you is a significant amount of time that you're going to shave off your Readiness and preparation for your assessment for cmnc um for those that have not had the choice of creating an SSP uh you will find that um you have to not only gather all this information from various groups but now you've got a word Smith it all together and put together for example access controls you might have to gather information from your single sign-on group your Active Directory Group your Cloud group if it's not integrated local accounts user accounts service accounts privileged access accounts and then you're gonna have to take all that information and worse method into a nice cohesive um excuse me nice cohesive implementation statement that needs to go into your SSP so imagine doing that for all 110 controls and that's just part of your SSP so being able to automatically create this by pulling in that information through the questionnaires is going to be a game saver um next is the creation of control test which is including all the inherited controls so what this means is right now what you'll have to do is you're going to have to reach out and you're going to contact your cloud service provider you're going to ask them for their inherited controls um they're going to write you some piece of information or report usually in in word PDF or Excel is the standard formats right and you're going to have to take that and go map in and copy and paste and write up your responses for each one of your controls that you inherit and inherited controls you're going to get three options it's either not inherited and it's up to you to implement it's fully inherited right in which you the organization that's using that CSP will not have to do anything or it's going to be partially like a shared control so they have a part to plan it and you have a part to play and you're going to have to marry those two together okay next is going to be your assessment workflow so this is where instead of having to go out and have meetings and send emails and gather all this information and keep it stored someplace whether you're storing it in SharePoint or OneDrive or anywhere else that you're usually storing your documentation you're managing it through spreadsheets right and so this is going to allow you to have a workflow that can go out and assign the controls to the correct internal and external owners allow you to gather that evidence gather their implementations validate whether or not something's in place and be able to review it all in a single location and because it's built on service now right you're going to be able to use all of the wonderful Rich features such as notifications and reminders dashboards and reports and and all the automation you're able to pull out next is going to be your vulnerability response integration so being able to process and parse through all of that vulnerability data and pull out exactly what needs to be documented within your poem and do that for you so again another use case for this how many of you have ever run vulnerability scans or had to look at them usually the output is pretty significant you've got a lot of data you have to parse through and try to figure out exactly which systems what systems what environment what subnet what's the vulnerability what's the severity can it be fixed can it not be fixed right is there a patch available and this is going to automate that for you so you don't have to spend all of that time going through all of that data on your own manually next is the asset visibility right asset management is a key Foundation to any security implementation how do you protect what you don't know you have how do you find the weakest link if you're not sure what you should be monitoring so asset availability it is going to give you all the visibility into your assets which are within your boundary and the data that you need to know about those assets was stored on them what are they used for very key next is our cmsc accelerator so this inspired security breaks Kevin so what we've done is we've created two um accelerators Within servicenow uh the cnmc 2.0 accelerator is built on cam and it's an application there and servicenow irm module um we've currently published it as a free app on the app store and it comes with the nist 800 171 content that includes Authority documents and control objectives it's a complete set of the questionnaires for both level one and level two uh with all the supplemental guidance and evidence requirements that you'll have to pull for each one um next is our vendor compliance accelerator that is currently built on the vendor risk management module and servicenow and what that does is it's got a survey um to help meet the contractual flow down um for cmnc and that is whoops excuse me um content covers both level one and level two and it's full vendor questionnaires it also includes reporting and dashboards for vendor responses um where is this key this one is that you know cnnc contract does require that cnnc applies to all subcontractors so what that means is if if security bricks was a DOD contractor and we had to be cmsc level two because we had cui any subcontractor vendor or partner that we were to use whether it's an mssp whether or not it's a CSP whether or not it's another organization that's just doing some support for an application if they have access to our systems or they have access to processed or transmit that cui data they also have to be level two cmmc compliant um and as part of your assessment you will be asked for each one of your vendors and you're going to have to validate whether or not they potentially would have some compliance requirements here and you have to be able to assess them validate that they have these 800 171 controls implemented so now we're going to go ahead into a product demo and I'm going to go ahead and switch my screen over while you're doing that might I ask one question from the audience sure right there was a question that came in that says do you have a way to manage a shared responsibility rule trips with a business a business business partner or with other parts of your own organization we we do so as part of our um Advanced cnnc application accelerator as we automatically will pull in all the inherited controls and supporting information that you need to complete those within the application itself so you don't have to do that all right so okay I just wanted to verify um you can see my screen switching screens you can see it okay so here I am I servicenow so we're going to go ahead and we're going to start with the vendors since we were just talking about those right so I'm going to come over here and I'm going to go ahead and start looking at my vendors all assessments where I'm at and you can see I can go ahead and create a new one and this is just how easy it is I'm going to create new I'm going to select my vendor let's go ahead and select Acer here I'm going to give it an owner and then I'm going to select my assessment template and let's go ahead and do a level two here okay from there I'll go ahead and save that and say submit to vendor now that's as easy as it is to go ahead and use the vendor assessment here for cmmc now you can see that this has been submitted to that organization and their contacts so that they can go ahead and complete this questionnaire for us now I'm going to come over here and I'm going to go ahead and sign in as that user oh all right so now it's time is Acer all right and I can see I have two assessments over here and both of them are coming here soon so I'm just going to go ahead and click over here and I can see my assessments so this is my new one here and I haven't completed anything yet and I have a due date that's not too far off in the future so I'm going to go ahead and open this up and go right into my questionnaire and here I can see each section so you know if there's a particular section I want to start with maybe I don't want to go in order I can or I can come on over here and just say let's just go down the list so now I've got my questions right does the organization limit information system access to authorized users and processes here's my guidance on what has to be implemented this is where that follow-up which is how does the dod um need you to implement this control right their expectations is that you have each one of these in place from here I'm going to be able to look at that say you know is this fully implemented planned implementation or not applicable this is really key so plan n implementation is important because you know whenever there's a new standard right that goes out like a PCI came out years ago um I know everyone's going to have every single one of these controls implemented so your vendor can come over here and easily say oh well we do a b and c but we don't have F right in which case from your perspective you want to know if you're not compliant with something do you have plans to be compliant so in this case I'm going to say this is planned and this is going to say okay well when do you plan on having that implemented because I need to be able to manage this if I know that we're having our audit in November of 23 I need to make sure your dates are going to be before that right so I'm going to come over here show the calendar and maybe I say oh the end of the month will be good and now I can go ahead and describe the planned implementation what does that give me as an organization is it's going to allow you when you're looking at this to say okay it's not in place today they do have a date which shows that they've actually done some planning that date meets our timeline but let's look at what they're planning on doing because what if their interpretation is incorrect what if they say they're going to do something to meet this and you look at that and you say oh that actually isn't what they want right so that this is going to get you ahead of that next you're going to be able to come down and they're going to scroll right down and see their things and you know yeah fully implement it okay describe how that was implemented so you notice all of this information Ryan is information that you have to have to answer those assessment questions and for your audit so once they go through this and finish they'll be able to submit this right I'm going to say this as draft because I'm still working on it then once this is done they'll submit that to you for review uh-huh go ahead and I'm going to remove this bar real quick all right so now what does this look like once we've got that vendor assessment back here so now I'm going to log back in as the user that is in service now and I'm going to come back over here I'm going to go back into all assessments and here's mine I'm going to go ahead and look at this I only find one that actually has a response in here in this case we'll really say response received and just buy one for Sam MC and I'm going to go ahead and open this up and now I can view those responses and I can see based on the responses that they provided that it's got a very high risk grading all right so there's quite a bit of things they haven't implemented yet so now that I come into view responses and now I can go in and select and look at my controls so I can see what they provided and not only can I see what they provided but then I can add in any internal comments that I want so only our teams inside can see them and it's not viewable to the vendor I can provide information to the vendor and I can flag this for follow-up because there's some remediation that needs to occur right and I can create risk items out of that so here I can create my issues right here and then when you need to provide your assessment evidence to your veteran even easily export things so now moving on from the vendors we're going to go ahead and look at the other cmnc accelerator Sarah can I ask you a question from the audience yes so there's a um is there an option to check off the requirements of the assessment objective levels attracting amen um so when you say assessment I'm sorry yeah so uh we don't have that um in the free version but we can do it when we are implementing it for the client that's possible but not yeah thanks so much so now we're going to come over here and look at the cam module in the CMC accelerator app all right and we can go ahead and I'm going to type that cmosi and now you'll be able to pull up our security Baseline and now in here this is what you're going to be doing internally right because not only do you have to worry about your vendors and subcontractors but you also have to look at how you've implemented these controls as well so here I can see all my control requirements and I'm going to go uh go ahead these are Authority documents that are already created and mapped out I'm going to say new it's not good there sorry go into a control and the right place select like that underneath but yeah you have to go into the um control objective and the metal entities into it yeah you were on the right spot um you just go into the yep right there into citations you can pick up the second citation that's fine yes okay there we go okay sorry about that guys no worries you have to go into the control objective not into not into the edit okay okay here yep and I'm gonna go ahead and edit the entity types and basically I can come over here and select the entity type for Access Control so this is the people internally that are going to be responding to access control questions I'm going to hit save you have to move into entity types you have to edit and just mold it yeah all right there we go sorry about that folks um so now I've got my access controls here if I go ahead and refresh this will start seeing my controls have now updated to four and so these are all those users that are responsible for access controls and what those entities are right so now I can say well I'm only going to send it to one or maybe I want to send it to all four and I'm going to say go ahead and attest so now it's going to create the attestation surveys and send those questions over to those assigned people so that they can go ahead and provide the information we need so so now if I go down and look let's go ahead and look at able tutor here so in this case I'm going to come over here you can just search my assessments or all assessments that's my assessments okay in the cam module yep you can just hit the assign to Able tutor in the right there in the filter ah yep around there all right so now we're going to come over here on or MP so here we go this is all we did there's the one just now so ready to take I'm going to go ahead and click on this and in here you can see I've got these assigned to me and are able does and I can go right in and say take assessment and now I've got the questionnaires I've got the guidance that's necessary this time I'm implemented describe my current implementation you know if it's not applicable provide that rationale here as well trial and now I can go ahead and submit that and file that over so that it can be reviewed um so it's straightforward being able to gather that information and have that ready to be reviewed and looked at internally and then all of the information that you gather through both surveys is going to allow us and you as an organization to take that data and create the documentation templates that are you're required to provide such as the SSP and the program oh okay let's go back over here just want to check to say are you able to see the product demo slide now or is it still showing service now all right well that was great to uh um thank you so much for walking us through that and letting us know our ins and outs of how that works and your presentation was packed with so much information that I'm a little bit helpful but we do have a couple of more questions that I wanted to throw in there if we could uh if you want to completely talk to the end but um one of the questions was uh will you be able to pull evidence and data from my Azure tenant yes so in our when we do the implementations it's not part of the um app you can just download and use will then be able to connect through the apis and servicenow to pull that information automatically so you're actually right ahead of it we are just getting ready to cover this on the slide we're seeing right now um and basically all of that information and evidence will be able to be pulled down automatically from your csps and also through your other servicenow modules that you use so if you're using cmdb or incident response or secops or devsecops or anything like that all of those will be able to automatically pull that stuff in which means instead of having to go through the manual process for each one of them you're looking at a significant reduction and the numbers you're going to have to go through another question that came in is can you generate a poem yes a poem can be generated and you know if you have monthly requirements to submit your poem you would come in every month generate that poem and it will pull all the up-to-date information so if you have um findings that are in your poem and those findings close um or any kind of Milestones get adjusted than when you pull that monthly poem you'll be able to have all those up-to-date information in there right and I don't know if you know this so you might be able to find out but does the risk scoring use the brm normalized scoring calculation I like Ahmad answer that question right so we used out of the box functionality for the scoring for this version for your for right now yeah okay that's fair um and how do I know which vendors need to be cmmc compliant so with your vendors um any vendor that stores processes or transmits right or has access to cui data will need to be cmfc compliant um you will gather that information through the vendor profile so that you'll be able to see what that vendor does and for your organization um and um from there if if you don't have that information and it's something you need to do then you know you could send out a survey to your internal Vendor Manager or to your vendor themselves and ask them if they could describe you know what their process is and gather that information so there's a number of methods to get that information if you don't already have it um the key thing is that once you've identified your boundary right and you know that this is this is your circle around your network diagram that's going to have to be cmmc compliant then it's going to be a lot easier to narrow down what vendors work within that Circle right yeah so you kind of picture yourself taking a red crayon and drawing a circle around your network infrastructure picture and say okay anything within here right and so if it's in there then you're going to be able to say okay here's my list of vendors that are working in here now I'm going to say what vendors you know in there are doing what you know and for some of them it's going to be so straightforward and easy to know and others not so much right and so that's where you're going to look at um the vendor profile and see what they provide awesome so that's it for the questions from the audience perfect so um our solution does an extension to the accelerator that's on the servicenow app right now um and this is going to be where we kind of covered a little bit right the cloud connections to AWS to Azure right others are will be coming um where we can go in and automate those do those connections into um your csps and be able to automatically pull the evidence pull uh pull down configurations pull down what it is that you have in place and automatically score those for you then you've got your inherited controls we talked a little bit about right so you know some of those are pretty straightforward others are not everyone knows if you're in a cloud right physical security is going to belong to that CSP because you don't have access to that data center you're not managing that but again just saying that oh well Azure does that for me isn't going to be enough for your assessment so you have to be able to say azure's data center this is the data center I'm in this is the controls that they have in place at that data center here is the reference to their cage code here is the reference to this data Center's fedrap right accreditation that shows that and so that's what your cmmc 3pao is going to be asking for they are looking to say how do you know that they need these controls and have you done your due diligence to verify that what they're doing is is enough right you're you're on top of it basically you're not just passing it over to them that's what they're looking for um the indicator templates right so to be able to automatically generate um the um compliance assessment results for the attestations being able to validate automatically by pulling into the other modules that you use within servicenow as well um to automate that I mean just think about it so there's a whole section in on incident response right within cmmc so let's say you have servicenow incident response module and it's goes out and some of your controls are do you test your incident response what is the frequency of those testing do you have slas associated with your incidents have those been met right here's all these things you have to document so now the indicator templates are going to be able to go out there and look at your incident response module and servicenow and check each one of these requirements and come back and say Here's your evidence and yes it's implemented and compliant next is your enhanced dashboards now getting your required reports that you need to submit to your c3pao all right is one thing those are absolutely necessary and save a ton of time but internally when you're managing projects like this you're going to need a lot more dashboards you need to be able to look at your metrics how are we doing as we're getting ready what does our Readiness look like is there anything that we need to be paying a closer attention to do I have a bright red flashing issue right that I need to know now or are we looking pretty good we're on track we're not running into any issues we're way better than we thought we would be by now right and so that's where these enhance enhanced dashboards will come into play it's going to provide you a quick glance and nice easy reporting uh UI to be able to see where we are at any given time did you have a visitor that failed right is it a key critical vendor um and then of course the validation so as a cmmc c3pao being able to um come in and actually be able to provide you with a review of your evidence and your responses and give you um support and validate your control implementations another option that is available as well as doing what's called a mock audit so what this means is if you'd like to be able to have a 3pao come in and actually do a mock audit and help prepare your organization those that will be part of the audit on making sure that they're comfortable with answering the questions and what to expect from the audit and that they have the correct evidence and responses that's also an option that's available as part of the extension from our solution something you just touched a little bit on this but um the question came in can the platform generate policies or the SSP and are we able to use this to collect and store evidence yes yes and yes absolutely

View original source

https://www.youtube.com/watch?v=T12CceeOTPM