SPONSORED CONTENT: Taking CMMC Seriously - What Is The Cost Of Compliance?

JSchaus & Associates
JSchaus & AssociatesFED Govt Contracts Consulting + 1 - 2 0 2 - 3 6 5 - 0 5 9 8 em JSchaus & Associates
Taking CMMC Seriously:
What is the Cost of
Compliance?
September, 19, 2023
Welcome!
Bill Wootton
Chief Revenue Officer
C3 Integrated Solutions
bwootton@C3isit.com
© 2023 C3 Integrated Solutions. All Rights Reserved.
3
Today’s Topics
▸Overview: Major Components of the Cost of CMMC
▸Building a Strategy
▸Deployment
▸Management and Monitoring
▸Compliance
▸Data Enclaves: Options and Impact
▸Three Types of Companies
Building a Strategy
© 2023 C3 Integrated Solutions. All Rights Reserved.
5
Building Your CMMC Strategy
Understanding
your business
Setting the
system
boundary
Determining the
organizational
impact
Determining
the expertise
you need
© 2023 C3 Integrated Solutions. All Rights Reserved.
6
Understanding Your Business
External Factors Internal Factors
▸ Your Customers…
▸ Which agencies do you work with?
▸ Your Partners…
▸ Who are your primes and subs?
▸ What are THEIR requirements to continue
working with them?
▸ Your Contracts…
▸ What clauses are already in your contracts?
▸ Your Future…
▸ Where will your business be in 2-3 years?
▸ Your Data…
▸ Do you have CUI?
▸ Do you have export-controlled data?
▸ Can you segment it from the rest of the
organization?
▸ Your People…
▸ Who directly interacts with CUI
▸ Who indirectly interacts with CUI?
▸ Your Systems…
▸ Which systems store, process, or transit
data?
The better you know your business, the less you will need a consultant to answer these questions.
© 2023 C3 Integrated Solutions. All Rights Reserved.
7
Company Examples: All 100-Person Firms
Research Firm
• Almost all commercial work
• Single DoD contract
• Team segmented from rest
of the firm
Manufacturing Firm
• Approximately 90% DoD
work
• Highly customized parts for
aircraft
• Large amounts of export-
controlled data
Professional Services
• Many distributed contracts
• Team members rotate
between DoD and civilian work
regularly
• Centralized admin supports all
contracts
Current systems are not compliant. No preexisting certifications (e.g. ISO
9001)
© 2023 C3 Integrated Solutions. All Rights Reserved.
8
Employee Access to CUI (100-person
Company)
????????
90 People 10 people
90 People
10 people
Commercial
Within CUI Boundary
Company 1 – Research
Firm
Company 3 – Professional Services Firm
Company 2 – Manufacturing Firm
© 2023 C3 Integrated Solutions. All Rights Reserved.
9
Determining System Boundaries: Enclave or
All-In?
ENCLAVE
Separate environment isolated
from the corporate environment
ALL-IN
Full configuration of corporate
environment to meet CMMC
requirements
Pros
▸ Reduced investment and scope
▸ Smaller attack surface
▸ More controlled system
boundary
▸ Limited (if any) data migration
Cons
▸ Swivel-seat user impact
▸ Illusion of cost savings
▸ Dual administration
▸ Unintended spillage
Pros
▸ Single, consolidated
environment
▸ Eliminates all technical debt
(fresh start)
Cons
▸ Data migration
▸ User impact
▸ Higher deployment costs
▸ Everyone is “locked down”
▸ Non-approved applications
© 2023 C3 Integrated Solutions. All Rights Reserved.
10
Enclave or All-In?
????????
90 People 10 people
90 People
10 people
Commercial
Within CUI Boundary
Company 1 – Research
Firm
Company 3 – Professional
Services
Company 2 - Manufacturing
Enclave
????
All-in
© 2023 C3 Integrated Solutions. All Rights Reserved.
11
Cost Drivers in Building a Strategy
Drivers Costs
▸ Knowledge of business
▸ Knowledge of data
▸ Current situation
▸ Technical debt
▸ Documentation
▸ Previous investment
▸ Internal resources
▸ Expertise/knowledge
▸ Availability
▸ Direct costs
▸ Outside consultant
▸ Internal effort
▸ Indirect costs
▸ Organization impact beyond IT
⁃ Business process changes
⁃ Segmenting and isolating data in an
enclave
▸ Impact of Strategy
⁃ Determines cost of the rest of the
process
▸ Confidence
▸ Risk of pursuing the wrong approach
Strategy costs are
not directly related to
the size of the
company. In most
cases, the scope of
effort drives the cost
profile.
Deployment
© 2023 C3 Integrated Solutions. All Rights Reserved.
13
Setting the System Boundary
System Boundary System Selection
• Communications
• E-mail
• Unified communications
• Collaboration
• Documents
• Other data
• CRM
• Financial
• Operational technology
• Access
• Virtual desktop
• Physical devices
• Mobile devices
• Cloud v. on-premises
• FedRAMP
• Export control
• US data residency
• US persons
Minimizing the
system boundary
reduces the services
that need to be fully
compliant
© 2023 C3 Integrated Solutions. All Rights Reserved.
14
Technology Costs
▸System selection
criteria
▸Accreditations
▸Attestations
▸Export control
▸GovCloud is
typically at least
30% higher
Commercial GCC GCC High
Data Centers Worldwide US Only US only
Accreditation FedRAMP
Moderate*
FedRAMP
Moderate
FedRAMP High
DFARS 7012 No Yes Yes
ITAR/EAR No No Yes
CUI/CDI No Maybe Yes
Customer
Support
Worldwide/Commercial
Personnel
Directory/Nt
k Azure Commercial Azure Gov
M365 G5
($/yr) $684 $684 $1120
Source: Understanding Compliance Between Microsoft 365 Commercial, GCC, GCC-High and DoD Offerings - Microsoft Community Hub
Microsoft 365 Example
Critical to choose the right systems that are accredited and can attest to requirements
© 2023 C3 Integrated Solutions. All Rights Reserved.
15
Deployment Costs
▸Provisioning
▸Establish the tenant
▸Configure
▸Should align to NIST SP 800-171
▸Data migration
▸Proportional to the size of the company
▸Microsoft 365 examples
⁃ Mailboxes
⁃ Teams and SharePoint
• Complexity – Workflows, etc.
Management and
Monitoring
© 2023 C3 Integrated Solutions. All Rights Reserved.
17
Management
Standard Services Compliant Services
▸ System administration
▸ Operational monitoring
▸ Patch management
▸ Support Desk
▸ Moves, adds, changes
▸ Documentation
▸ SLA
▸ SRM
▸ Standardized
procedures
▸ Configuration updates
▸ System reviews
▸ Support for GRC tool
▸ Assessment support
▸ U.S. based
If your corporate IT or
current MSP provider
cannot support
requirements (i.e. US
person only support),
an MSP specializing in
the DIB should be
considered.
© 2023 C3 Integrated Solutions. All Rights Reserved.
18
Monitoring – What to look for
▸ Automation
▸ Export control
▸ 24x7
▸ Documentation
▸SLA
▸SRM
▸IR Plan
▸ Assessment support
▸ Incident response
▸ Certifications
▸SOC-2
▸ Vulnerability scanning
Costs vary widely
depending on the
level of services and
the sophistication of
the solution.
Compliance
© 2023 C3 Integrated Solutions. All Rights Reserved.
20
Cost of Managing Compliance
Initial Costs Ongoing Costs
▸ Pre-assessment review
▸ Documentation
development
▸ System Security Plan (SSP)
▸ Policies
▸ Procedures
▸ Incident response plan
▸ Initial assessment
▸ Gap analysis
▸ POAM development
▸ Initial table-top
▸ Documentation
▸ Management and upkeep
▸ Integration with services?
▸ Assessment support
▸ Annual validations
▸ Table-top
▸ GRC tool
▸ Licensing
▸ Information upkeep
▸ Ad hoc consulting
Compliance costs have a
minimum threshold where
certain activities (i.e.
assessment) are required
regardless of company
size.
Back to Our Examples…
Numbers provided are for illustration purposes only.
© 2023 C3 Integrated Solutions. All Rights Reserved.
22
Cost Profile
Considerations
▸ Commercial v. GCCH M365
▸ IT support costs
▸ Monitoring costs
▸ Users swivel seat
▸ Double count users across both
environments
Not considered
▸ Additional applications
▸ Intangibles
▸User frustration
▸Overhead and administration of multiple
environments
Corporate Government
Microsoft
365
Commercial M365 G5
$57/month
GCC High M365
G5
$1120/year
IT Support
Internal
$150 month
equivalent
Outsourced
$200/month
Monitoring
Commercial Grade
$26/endpoint
Compliant
$35/endpoint
Strategy, deployment and cost of compliance
assumed comparable across examples unless noted.
© 2023 C3 Integrated Solutions. All Rights Reserved.
23
Pre-CMMC Annual IT Budget
▸M365 Commercial
▸G5 license
▸100 users
▸IT Support
▸$150/user cost of operation
▸May be internal or external
▸Monitoring
▸“Commercial grade”
▸$26/endpoint
▸Assume 100 endpoints
▸Annual budget: $279,600
$68,400
$180,00
0
$31,200
$-
$50,000
$100,000
$150,000
$200,000
$250,000
$300,000
Corporate
M365 IT Support Monitoring
© 2023 C3 Integrated Solutions. All Rights Reserved.
24
Company 1: Research Firm
▸GCC High enclave
▸10 users, M365 G5
▸Azure Virtual Desktop
▸User access
▸No additional applications
▸$2000/month usage
▸IT Support
▸$200/user, External vendor
▸Monitoring
▸$35/endpoint (virtual)
▸Total Budget: $343,700
$279,60
0
$64,100
$-
$50,000
$100,000
$150,000
$200,000
$250,000
$300,000
$350,000
$400,000
Annual Budget
Corporate Enclave
© 2023 C3 Integrated Solutions. All Rights Reserved.
25
Company 2: Manufacturing Firm
▸All-In
▸Microsoft 365 GCC High
▸100 users
▸Azure Virtual Desktop
▸Not required
▸Endpoints converted
▸IT Support
▸$200/user
▸External vendor
▸Monitoring
▸$35/endpoint (virtual)
▸Migration costs not considered
▸Total Budget: $401,000
$119,00
0
$240,00
0
$42,000
$-
$50,000
$100,000
$150,000
$200,000
$250,000
$300,000
$350,000
$400,000
$450,000
All-In
M365 IT Support Monitoring
© 2023 C3 Integrated Solutions. All Rights Reserved.
26
Company 3: Professional Services
▸ All-in or Enclave?
▸ Likely the most expensive from a
strategy development perspective
▸ Escalating commitment as users
are added
▸ Increased risk of unintended
spillage
▸ Increased user frustration and
confusion
▸ Break even to go all-in just under
30 users
* Does not consider other applications
nor strain of managing multiple
environments for both IT and users
$-
$100,000
$200,000
$300,000
$400,000
$500,000
$600,000
$700,000
$800,000
0 10 20 30 40 50 60 70 80 90 100
Commerical GCCH Enclave All-In
© 2023 C3 Integrated Solutions. All Rights Reserved.
27
About C3 Integrated Solutions
Technology
Experience
11 years Microsoft partner
6+ years experience in GCC
High
Multiple Gold competencies
Co-Sell Authorized
Client Experience
450+ Microsoft 365 clients
200+ GCC High clients
Deep NIST, DFARS, ITAR
experience
Industry Leader
First to offer GCC High
backup and hosted voice
CMMC Registered
Practitioner Organization
Two successful C3PAO
clients
Wrap-up and Questions
Get Started
Build the barriers that
protect your business,
not disrupt it.
Our mission is to protect sensitive data and prevent breaches by providing world-class
cybersecurity and compliance services to businesses of all sizes.
visit
c3isit.com
1 de 29

Recomendados

OPTIMIZING PIPELINES WITH MACHINE LEARNING DECISION SUPPORT por
OPTIMIZING PIPELINES WITH MACHINE LEARNING DECISION SUPPORTOPTIMIZING PIPELINES WITH MACHINE LEARNING DECISION SUPPORT
OPTIMIZING PIPELINES WITH MACHINE LEARNING DECISION SUPPORTwle-ss
20 visualizações29 slides
Cloud ROI and Implementation - A TechBlocks Solutions Guide por
Cloud ROI and Implementation - A TechBlocks Solutions GuideCloud ROI and Implementation - A TechBlocks Solutions Guide
Cloud ROI and Implementation - A TechBlocks Solutions GuideTechBlocks
367 visualizações12 slides
ITAM Tools Day, November 2015 - Concorde por
ITAM Tools Day, November 2015 - ConcordeITAM Tools Day, November 2015 - Concorde
ITAM Tools Day, November 2015 - ConcordeMartin Thompson
444 visualizações14 slides
The CMDB/CMS in the Digital Age: A Bedrock for IT Transformation por
The CMDB/CMS in the Digital Age: A Bedrock for IT TransformationThe CMDB/CMS in the Digital Age: A Bedrock for IT Transformation
The CMDB/CMS in the Digital Age: A Bedrock for IT TransformationEnterprise Management Associates
489 visualizações46 slides
Best Practices for Embedding Analytics by GoodData Product Leader por
Best Practices for Embedding Analytics by GoodData Product LeaderBest Practices for Embedding Analytics by GoodData Product Leader
Best Practices for Embedding Analytics by GoodData Product LeaderProduct School
134 visualizações25 slides
PCM Vision 2019 Keynote: Elliot Baretz por
PCM Vision 2019 Keynote: Elliot BaretzPCM Vision 2019 Keynote: Elliot Baretz
PCM Vision 2019 Keynote: Elliot BaretzPCM
592 visualizações21 slides

Mais conteúdo relacionado

Similar a SPONSORED CONTENT: Taking CMMC Seriously - What Is The Cost Of Compliance?

How to Calculate ROI for Network Management & Monitoring por
How to Calculate ROI for Network Management & MonitoringHow to Calculate ROI for Network Management & Monitoring
How to Calculate ROI for Network Management & MonitoringSolarWinds
5.6K visualizações23 slides
Microsoft licensing analysis - an introduction por
Microsoft licensing analysis - an introductionMicrosoft licensing analysis - an introduction
Microsoft licensing analysis - an introductionNiels Jørgen Hansen
1.2K visualizações38 slides
CRMIT Solutions - An Overview por
CRMIT Solutions - An OverviewCRMIT Solutions - An Overview
CRMIT Solutions - An OverviewCRMIT
952 visualizações17 slides
AssetsHub Pitch Deck por
AssetsHub Pitch DeckAssetsHub Pitch Deck
AssetsHub Pitch DeckAssetsHub
25 visualizações15 slides
financial_close_and_disclosure_management_on_cloud por
financial_close_and_disclosure_management_on_cloudfinancial_close_and_disclosure_management_on_cloud
financial_close_and_disclosure_management_on_cloudCharles Wilson
378 visualizações18 slides
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ... por
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...ThousandEyes
87 visualizações25 slides

Similar a SPONSORED CONTENT: Taking CMMC Seriously - What Is The Cost Of Compliance? (20)

How to Calculate ROI for Network Management & Monitoring por SolarWinds
How to Calculate ROI for Network Management & MonitoringHow to Calculate ROI for Network Management & Monitoring
How to Calculate ROI for Network Management & Monitoring
SolarWinds5.6K visualizações
Microsoft licensing analysis - an introduction por Niels Jørgen Hansen
Microsoft licensing analysis - an introductionMicrosoft licensing analysis - an introduction
Microsoft licensing analysis - an introduction
Niels Jørgen Hansen1.2K visualizações
CRMIT Solutions - An Overview por CRMIT
CRMIT Solutions - An OverviewCRMIT Solutions - An Overview
CRMIT Solutions - An Overview
CRMIT952 visualizações
AssetsHub Pitch Deck por AssetsHub
AssetsHub Pitch DeckAssetsHub Pitch Deck
AssetsHub Pitch Deck
AssetsHub25 visualizações
financial_close_and_disclosure_management_on_cloud por Charles Wilson
financial_close_and_disclosure_management_on_cloudfinancial_close_and_disclosure_management_on_cloud
financial_close_and_disclosure_management_on_cloud
Charles Wilson378 visualizações
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ... por ThousandEyes
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...
ThousandEyes87 visualizações
VMSDeploymentGuide_Extract1a por Tom - Creed
VMSDeploymentGuide_Extract1aVMSDeploymentGuide_Extract1a
VMSDeploymentGuide_Extract1a
Tom - Creed51 visualizações
Under cloud cover: How leaders are accelerating competitive differentiation por Susanne Hupfer, Ph.D.
Under cloud cover: How leaders are accelerating competitive differentiationUnder cloud cover: How leaders are accelerating competitive differentiation
Under cloud cover: How leaders are accelerating competitive differentiation
Susanne Hupfer, Ph.D.178 visualizações
Migrating apps-to-the-cloud-final por eng999
Migrating apps-to-the-cloud-finalMigrating apps-to-the-cloud-final
Migrating apps-to-the-cloud-final
eng999289 visualizações
Bring Your Own Disaster por Peter Witsenburg
Bring Your Own DisasterBring Your Own Disaster
Bring Your Own Disaster
Peter Witsenburg570 visualizações
Bhawani prasad mdm-cdi-methodology por Bhawani N Prasad
Bhawani prasad mdm-cdi-methodologyBhawani prasad mdm-cdi-methodology
Bhawani prasad mdm-cdi-methodology
Bhawani N Prasad1.5K visualizações
How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2... por Ignyte Assurance Platform
How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2...How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2...
How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2...
Ignyte Assurance Platform33 visualizações
AMI Global Award Write Up por Claudia Toscano
AMI Global Award Write UpAMI Global Award Write Up
AMI Global Award Write Up
Claudia Toscano149 visualizações
MongoDB World 2019: Data Digital Decoupling por MongoDB
MongoDB World 2019: Data Digital DecouplingMongoDB World 2019: Data Digital Decoupling
MongoDB World 2019: Data Digital Decoupling
MongoDB602 visualizações
Gsx code two gsx final por GSX Solutions
Gsx code two gsx finalGsx code two gsx final
Gsx code two gsx final
GSX Solutions663 visualizações
Critical functionality testing por Maveric Systems
Critical functionality testingCritical functionality testing
Critical functionality testing
Maveric Systems4.3K visualizações
NG-Brochure por Trevor Gordon
NG-BrochureNG-Brochure
NG-Brochure
Trevor Gordon188 visualizações
Preview novarica1908 eb-core-business_case por ~Eric Principe
Preview novarica1908 eb-core-business_casePreview novarica1908 eb-core-business_case
Preview novarica1908 eb-core-business_case
~Eric Principe25 visualizações
The Advantages and Pitfalls of Data Centre Consolidation por DAYWATCHER.COM
The Advantages and Pitfalls of Data Centre ConsolidationThe Advantages and Pitfalls of Data Centre Consolidation
The Advantages and Pitfalls of Data Centre Consolidation
DAYWATCHER.COM551 visualizações
Planning for Cloud Profitability From Day One: MSP VAR Companies and Cloud Co... por ProfitBricks
Planning for Cloud Profitability From Day One: MSP VAR Companies and Cloud Co...Planning for Cloud Profitability From Day One: MSP VAR Companies and Cloud Co...
Planning for Cloud Profitability From Day One: MSP VAR Companies and Cloud Co...
ProfitBricks960 visualizações

Mais de JSchaus & Associates

SPONSORED CONTENT: Finding Federal Contract Opportunities (Part 1 Of 2) por
SPONSORED CONTENT: Finding Federal Contract Opportunities (Part 1 Of 2)SPONSORED CONTENT: Finding Federal Contract Opportunities (Part 1 Of 2)
SPONSORED CONTENT: Finding Federal Contract Opportunities (Part 1 Of 2)JSchaus & Associates
36 visualizações21 slides
Top 40 Federal Contractors - PROFILE #40 - GSK Glaxo Smith Kline por
Top 40 Federal Contractors - PROFILE #40 - GSK Glaxo Smith KlineTop 40 Federal Contractors - PROFILE #40 - GSK Glaxo Smith Kline
Top 40 Federal Contractors - PROFILE #40 - GSK Glaxo Smith KlineJSchaus & Associates
20 visualizações81 slides
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps Construction por
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps ConstructionTop 40 Federal Contractors - PROFILE #39 - Hensel Phelps Construction
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps ConstructionJSchaus & Associates
18 visualizações77 slides
Top 40 Federal Contractors - PROFILE #38 - Dell por
Top 40 Federal Contractors - PROFILE #38 - DellTop 40 Federal Contractors - PROFILE #38 - Dell
Top 40 Federal Contractors - PROFILE #38 - DellJSchaus & Associates
14 visualizações75 slides
Top 40 Federal Contractors - PROFILE #37 - CACI por
Top 40 Federal Contractors - PROFILE #37 - CACITop 40 Federal Contractors - PROFILE #37 - CACI
Top 40 Federal Contractors - PROFILE #37 - CACIJSchaus & Associates
43 visualizações76 slides
GSA Schedules - Requirements & Strategies For Success por
GSA Schedules - Requirements & Strategies For SuccessGSA Schedules - Requirements & Strategies For Success
GSA Schedules - Requirements & Strategies For SuccessJSchaus & Associates
19 visualizações46 slides

Mais de JSchaus & Associates(20)

SPONSORED CONTENT: Finding Federal Contract Opportunities (Part 1 Of 2) por JSchaus & Associates
SPONSORED CONTENT: Finding Federal Contract Opportunities (Part 1 Of 2)SPONSORED CONTENT: Finding Federal Contract Opportunities (Part 1 Of 2)
SPONSORED CONTENT: Finding Federal Contract Opportunities (Part 1 Of 2)
JSchaus & Associates36 visualizações
Top 40 Federal Contractors - PROFILE #40 - GSK Glaxo Smith Kline por JSchaus & Associates
Top 40 Federal Contractors - PROFILE #40 - GSK Glaxo Smith KlineTop 40 Federal Contractors - PROFILE #40 - GSK Glaxo Smith Kline
Top 40 Federal Contractors - PROFILE #40 - GSK Glaxo Smith Kline
JSchaus & Associates20 visualizações
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps Construction por JSchaus & Associates
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps ConstructionTop 40 Federal Contractors - PROFILE #39 - Hensel Phelps Construction
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps Construction
JSchaus & Associates18 visualizações
Top 40 Federal Contractors - PROFILE #38 - Dell por JSchaus & Associates
Top 40 Federal Contractors - PROFILE #38 - DellTop 40 Federal Contractors - PROFILE #38 - Dell
Top 40 Federal Contractors - PROFILE #38 - Dell
JSchaus & Associates14 visualizações
Top 40 Federal Contractors - PROFILE #37 - CACI por JSchaus & Associates
Top 40 Federal Contractors - PROFILE #37 - CACITop 40 Federal Contractors - PROFILE #37 - CACI
Top 40 Federal Contractors - PROFILE #37 - CACI
JSchaus & Associates43 visualizações
GSA Schedules - Requirements & Strategies For Success por JSchaus & Associates
GSA Schedules - Requirements & Strategies For SuccessGSA Schedules - Requirements & Strategies For Success
GSA Schedules - Requirements & Strategies For Success
JSchaus & Associates19 visualizações
Top 40 Federal Contractors - PROFILE #36 - Merck & Co por JSchaus & Associates
Top 40 Federal Contractors - PROFILE #36 - Merck & CoTop 40 Federal Contractors - PROFILE #36 - Merck & Co
Top 40 Federal Contractors - PROFILE #36 - Merck & Co
JSchaus & Associates22 visualizações
Top 40 Federal Contractors - PROFILE #35 - Moderna por JSchaus & Associates
Top 40 Federal Contractors - PROFILE #35 - ModernaTop 40 Federal Contractors - PROFILE #35 - Moderna
Top 40 Federal Contractors - PROFILE #35 - Moderna
JSchaus & Associates28 visualizações
Top 40 Federal Contractors - PROFILE #34 - Steel and Shipbuilding Company por JSchaus & Associates
Top 40 Federal Contractors - PROFILE #34 - Steel and Shipbuilding CompanyTop 40 Federal Contractors - PROFILE #34 - Steel and Shipbuilding Company
Top 40 Federal Contractors - PROFILE #34 - Steel and Shipbuilding Company
JSchaus & Associates17 visualizações
Top 40 Federal Contractors - PROFILE #33 - Caddell por JSchaus & Associates
Top 40 Federal Contractors - PROFILE #33 - CaddellTop 40 Federal Contractors - PROFILE #33 - Caddell
Top 40 Federal Contractors - PROFILE #33 - Caddell
JSchaus & Associates11 visualizações
Top 40 Federal Contractors - PROFILE #32 - Mitre por JSchaus & Associates
Top 40 Federal Contractors - PROFILE #32 - MitreTop 40 Federal Contractors - PROFILE #32 - Mitre
Top 40 Federal Contractors - PROFILE #32 - Mitre
JSchaus & Associates16 visualizações
GSA Schedule: Requirements, Proposal Prep and - What's Next por JSchaus & Associates
GSA Schedule: Requirements, Proposal Prep and - What's NextGSA Schedule: Requirements, Proposal Prep and - What's Next
GSA Schedule: Requirements, Proposal Prep and - What's Next
JSchaus & Associates14 visualizações
Top 40 Federal Contractors - PROFILE #31 - KBR por JSchaus & Associates
Top 40 Federal Contractors - PROFILE #31 - KBRTop 40 Federal Contractors - PROFILE #31 - KBR
Top 40 Federal Contractors - PROFILE #31 - KBR
JSchaus & Associates31 visualizações
Top 40 Federal Contractors - PROFILE #30 - Cal Tech por JSchaus & Associates
Top 40 Federal Contractors - PROFILE #30 - Cal TechTop 40 Federal Contractors - PROFILE #30 - Cal Tech
Top 40 Federal Contractors - PROFILE #30 - Cal Tech
JSchaus & Associates34 visualizações
Top 40 Federal Contractors - PROFILE #29 - National Security por JSchaus & Associates
Top 40 Federal Contractors - PROFILE #29 - National SecurityTop 40 Federal Contractors - PROFILE #29 - National Security
Top 40 Federal Contractors - PROFILE #29 - National Security
JSchaus & Associates17 visualizações
GSA Schedule Basics - Part 2 por JSchaus & Associates
GSA Schedule Basics - Part 2GSA Schedule Basics - Part 2
GSA Schedule Basics - Part 2
JSchaus & Associates26 visualizações
Top 40 Federal Contractors - PROFILE #28 - Maximus por JSchaus & Associates
Top 40 Federal Contractors - PROFILE #28 - MaximusTop 40 Federal Contractors - PROFILE #28 - Maximus
Top 40 Federal Contractors - PROFILE #28 - Maximus
JSchaus & Associates44 visualizações
Top 40 Federal Contractors - PROFILE #27 - Oshkosh Defense por JSchaus & Associates
Top 40 Federal Contractors - PROFILE #27 - Oshkosh DefenseTop 40 Federal Contractors - PROFILE #27 - Oshkosh Defense
Top 40 Federal Contractors - PROFILE #27 - Oshkosh Defense
JSchaus & Associates39 visualizações
Top 40 Federal Contractors - SpaceX por JSchaus & Associates
Top 40 Federal Contractors - SpaceXTop 40 Federal Contractors - SpaceX
Top 40 Federal Contractors - SpaceX
JSchaus & Associates33 visualizações

Último

Prof. George B. Ploubidis - Future of Ageing por
Prof. George B. Ploubidis - Future of AgeingProf. George B. Ploubidis - Future of Ageing
Prof. George B. Ploubidis - Future of AgeingILCUK
22 visualizações27 slides
Professor Stephen Harridge and Tom Addison - Future of Ageing 2023 por
Professor Stephen Harridge and Tom Addison - Future of Ageing 2023Professor Stephen Harridge and Tom Addison - Future of Ageing 2023
Professor Stephen Harridge and Tom Addison - Future of Ageing 2023ILCUK
27 visualizações13 slides
Katie Waldegrave MBE - Future of Ageing 2023 por
Katie Waldegrave MBE - Future of Ageing 2023Katie Waldegrave MBE - Future of Ageing 2023
Katie Waldegrave MBE - Future of Ageing 2023ILCUK
28 visualizações3 slides
MVX Nexus por
MVX NexusMVX Nexus
MVX NexusMountain Valley Express Collective Society
29 visualizações32 slides
PPT - SIGMA-GIZ Academies - Topic 4 - Amenia - Citizen Feedback Platform.pdf por
PPT - SIGMA-GIZ Academies - Topic 4 - Amenia - Citizen Feedback Platform.pdfPPT - SIGMA-GIZ Academies - Topic 4 - Amenia - Citizen Feedback Platform.pdf
PPT - SIGMA-GIZ Academies - Topic 4 - Amenia - Citizen Feedback Platform.pdfSupport for Improvement in Governance and Management SIGMA
48 visualizações8 slides
Contributi L. 3/2019 por
Contributi L. 3/2019Contributi L. 3/2019
Contributi L. 3/2019Partito democratico
65 visualizações256 slides

Último(20)

Prof. George B. Ploubidis - Future of Ageing por ILCUK
Prof. George B. Ploubidis - Future of AgeingProf. George B. Ploubidis - Future of Ageing
Prof. George B. Ploubidis - Future of Ageing
ILCUK22 visualizações
Professor Stephen Harridge and Tom Addison - Future of Ageing 2023 por ILCUK
Professor Stephen Harridge and Tom Addison - Future of Ageing 2023Professor Stephen Harridge and Tom Addison - Future of Ageing 2023
Professor Stephen Harridge and Tom Addison - Future of Ageing 2023
ILCUK27 visualizações
Katie Waldegrave MBE - Future of Ageing 2023 por ILCUK
Katie Waldegrave MBE - Future of Ageing 2023Katie Waldegrave MBE - Future of Ageing 2023
Katie Waldegrave MBE - Future of Ageing 2023
ILCUK28 visualizações
World Soil Day 2023 Key messages. por Christina Parmionova
 World Soil Day 2023 Key messages. World Soil Day 2023 Key messages.
World Soil Day 2023 Key messages.
Christina Parmionova8 visualizações
Arunima Himawan (Prevention Index) - Future of Ageing 2023 por ILCUK
Arunima Himawan (Prevention Index) - Future of Ageing 2023Arunima Himawan (Prevention Index) - Future of Ageing 2023
Arunima Himawan (Prevention Index) - Future of Ageing 2023
ILCUK31 visualizações
Build Insp 2023jd.pdf por NorthwestBOCA
Build Insp 2023jd.pdfBuild Insp 2023jd.pdf
Build Insp 2023jd.pdf
NorthwestBOCA19 visualizações
David Sinclair - Future of Ageing 2023 por ILCUK
David Sinclair - Future of Ageing 2023David Sinclair - Future of Ageing 2023
David Sinclair - Future of Ageing 2023
ILCUK35 visualizações
COP 28 GHANA DELEGATES.docx por Kweku Zurek
COP 28 GHANA DELEGATES.docxCOP 28 GHANA DELEGATES.docx
COP 28 GHANA DELEGATES.docx
Kweku Zurek6.7K visualizações
Assets of Community Value: From a Local Council Perspective por Scribe
 Assets of Community Value: From a Local Council Perspective Assets of Community Value: From a Local Council Perspective
Assets of Community Value: From a Local Council Perspective
Scribe 21 visualizações
Report of the Scientific Advisory Group on the status and developments regard... por Christina Parmionova
Report of the Scientific Advisory Group on the status and developments regard...Report of the Scientific Advisory Group on the status and developments regard...
Report of the Scientific Advisory Group on the status and developments regard...
Christina Parmionova5 visualizações
Food for Elderly homeless por SERUDS INDIA
Food for Elderly homelessFood for Elderly homeless
Food for Elderly homeless
SERUDS INDIA10 visualizações
WCAG 2.2 - An Overview of the New Accessibility Guidelines.pptx por AbilityNet
WCAG 2.2 - An Overview of the New Accessibility Guidelines.pptxWCAG 2.2 - An Overview of the New Accessibility Guidelines.pptx
WCAG 2.2 - An Overview of the New Accessibility Guidelines.pptx
AbilityNet88 visualizações

SPONSORED CONTENT: Taking CMMC Seriously - What Is The Cost Of Compliance?

  • 1. Taking CMMC Seriously: What is the Cost of Compliance? September, 19, 2023
  • 2. Welcome! Bill Wootton Chief Revenue Officer C3 Integrated Solutions bwootton@C3isit.com
  • 3. © 2023 C3 Integrated Solutions. All Rights Reserved. 3 Today’s Topics ▸Overview: Major Components of the Cost of CMMC ▸Building a Strategy ▸Deployment ▸Management and Monitoring ▸Compliance ▸Data Enclaves: Options and Impact ▸Three Types of Companies
  • 5. © 2023 C3 Integrated Solutions. All Rights Reserved. 5 Building Your CMMC Strategy Understanding your business Setting the system boundary Determining the organizational impact Determining the expertise you need
  • 6. © 2023 C3 Integrated Solutions. All Rights Reserved. 6 Understanding Your Business External Factors Internal Factors ▸ Your Customers… ▸ Which agencies do you work with? ▸ Your Partners… ▸ Who are your primes and subs? ▸ What are THEIR requirements to continue working with them? ▸ Your Contracts… ▸ What clauses are already in your contracts? ▸ Your Future… ▸ Where will your business be in 2-3 years? ▸ Your Data… ▸ Do you have CUI? ▸ Do you have export-controlled data? ▸ Can you segment it from the rest of the organization? ▸ Your People… ▸ Who directly interacts with CUI ▸ Who indirectly interacts with CUI? ▸ Your Systems… ▸ Which systems store, process, or transit data? The better you know your business, the less you will need a consultant to answer these questions.
  • 7. © 2023 C3 Integrated Solutions. All Rights Reserved. 7 Company Examples: All 100-Person Firms Research Firm • Almost all commercial work • Single DoD contract • Team segmented from rest of the firm Manufacturing Firm • Approximately 90% DoD work • Highly customized parts for aircraft • Large amounts of export- controlled data Professional Services • Many distributed contracts • Team members rotate between DoD and civilian work regularly • Centralized admin supports all contracts Current systems are not compliant. No preexisting certifications (e.g. ISO 9001)
  • 8. © 2023 C3 Integrated Solutions. All Rights Reserved. 8 Employee Access to CUI (100-person Company) ???????? 90 People 10 people 90 People 10 people Commercial Within CUI Boundary Company 1 – Research Firm Company 3 – Professional Services Firm Company 2 – Manufacturing Firm
  • 9. © 2023 C3 Integrated Solutions. All Rights Reserved. 9 Determining System Boundaries: Enclave or All-In? ENCLAVE Separate environment isolated from the corporate environment ALL-IN Full configuration of corporate environment to meet CMMC requirements Pros ▸ Reduced investment and scope ▸ Smaller attack surface ▸ More controlled system boundary ▸ Limited (if any) data migration Cons ▸ Swivel-seat user impact ▸ Illusion of cost savings ▸ Dual administration ▸ Unintended spillage Pros ▸ Single, consolidated environment ▸ Eliminates all technical debt (fresh start) Cons ▸ Data migration ▸ User impact ▸ Higher deployment costs ▸ Everyone is “locked down” ▸ Non-approved applications
  • 10. © 2023 C3 Integrated Solutions. All Rights Reserved. 10 Enclave or All-In? ???????? 90 People 10 people 90 People 10 people Commercial Within CUI Boundary Company 1 – Research Firm Company 3 – Professional Services Company 2 - Manufacturing Enclave ???? All-in
  • 11. © 2023 C3 Integrated Solutions. All Rights Reserved. 11 Cost Drivers in Building a Strategy Drivers Costs ▸ Knowledge of business ▸ Knowledge of data ▸ Current situation ▸ Technical debt ▸ Documentation ▸ Previous investment ▸ Internal resources ▸ Expertise/knowledge ▸ Availability ▸ Direct costs ▸ Outside consultant ▸ Internal effort ▸ Indirect costs ▸ Organization impact beyond IT ⁃ Business process changes ⁃ Segmenting and isolating data in an enclave ▸ Impact of Strategy ⁃ Determines cost of the rest of the process ▸ Confidence ▸ Risk of pursuing the wrong approach Strategy costs are not directly related to the size of the company. In most cases, the scope of effort drives the cost profile.
  • 13. © 2023 C3 Integrated Solutions. All Rights Reserved. 13 Setting the System Boundary System Boundary System Selection • Communications • E-mail • Unified communications • Collaboration • Documents • Other data • CRM • Financial • Operational technology • Access • Virtual desktop • Physical devices • Mobile devices • Cloud v. on-premises • FedRAMP • Export control • US data residency • US persons Minimizing the system boundary reduces the services that need to be fully compliant
  • 14. © 2023 C3 Integrated Solutions. All Rights Reserved. 14 Technology Costs ▸System selection criteria ▸Accreditations ▸Attestations ▸Export control ▸GovCloud is typically at least 30% higher Commercial GCC GCC High Data Centers Worldwide US Only US only Accreditation FedRAMP Moderate* FedRAMP Moderate FedRAMP High DFARS 7012 No Yes Yes ITAR/EAR No No Yes CUI/CDI No Maybe Yes Customer Support Worldwide/Commercial Personnel Directory/Nt k Azure Commercial Azure Gov M365 G5 ($/yr) $684 $684 $1120 Source: Understanding Compliance Between Microsoft 365 Commercial, GCC, GCC-High and DoD Offerings - Microsoft Community Hub Microsoft 365 Example Critical to choose the right systems that are accredited and can attest to requirements
  • 15. © 2023 C3 Integrated Solutions. All Rights Reserved. 15 Deployment Costs ▸Provisioning ▸Establish the tenant ▸Configure ▸Should align to NIST SP 800-171 ▸Data migration ▸Proportional to the size of the company ▸Microsoft 365 examples ⁃ Mailboxes ⁃ Teams and SharePoint • Complexity – Workflows, etc.
  • 17. © 2023 C3 Integrated Solutions. All Rights Reserved. 17 Management Standard Services Compliant Services ▸ System administration ▸ Operational monitoring ▸ Patch management ▸ Support Desk ▸ Moves, adds, changes ▸ Documentation ▸ SLA ▸ SRM ▸ Standardized procedures ▸ Configuration updates ▸ System reviews ▸ Support for GRC tool ▸ Assessment support ▸ U.S. based If your corporate IT or current MSP provider cannot support requirements (i.e. US person only support), an MSP specializing in the DIB should be considered.
  • 18. © 2023 C3 Integrated Solutions. All Rights Reserved. 18 Monitoring – What to look for ▸ Automation ▸ Export control ▸ 24x7 ▸ Documentation ▸SLA ▸SRM ▸IR Plan ▸ Assessment support ▸ Incident response ▸ Certifications ▸SOC-2 ▸ Vulnerability scanning Costs vary widely depending on the level of services and the sophistication of the solution.
  • 20. © 2023 C3 Integrated Solutions. All Rights Reserved. 20 Cost of Managing Compliance Initial Costs Ongoing Costs ▸ Pre-assessment review ▸ Documentation development ▸ System Security Plan (SSP) ▸ Policies ▸ Procedures ▸ Incident response plan ▸ Initial assessment ▸ Gap analysis ▸ POAM development ▸ Initial table-top ▸ Documentation ▸ Management and upkeep ▸ Integration with services? ▸ Assessment support ▸ Annual validations ▸ Table-top ▸ GRC tool ▸ Licensing ▸ Information upkeep ▸ Ad hoc consulting Compliance costs have a minimum threshold where certain activities (i.e. assessment) are required regardless of company size.
  • 21. Back to Our Examples… Numbers provided are for illustration purposes only.
  • 22. © 2023 C3 Integrated Solutions. All Rights Reserved. 22 Cost Profile Considerations ▸ Commercial v. GCCH M365 ▸ IT support costs ▸ Monitoring costs ▸ Users swivel seat ▸ Double count users across both environments Not considered ▸ Additional applications ▸ Intangibles ▸User frustration ▸Overhead and administration of multiple environments Corporate Government Microsoft 365 Commercial M365 G5 $57/month GCC High M365 G5 $1120/year IT Support Internal $150 month equivalent Outsourced $200/month Monitoring Commercial Grade $26/endpoint Compliant $35/endpoint Strategy, deployment and cost of compliance assumed comparable across examples unless noted.
  • 23. © 2023 C3 Integrated Solutions. All Rights Reserved. 23 Pre-CMMC Annual IT Budget ▸M365 Commercial ▸G5 license ▸100 users ▸IT Support ▸$150/user cost of operation ▸May be internal or external ▸Monitoring ▸“Commercial grade” ▸$26/endpoint ▸Assume 100 endpoints ▸Annual budget: $279,600 $68,400 $180,00 0 $31,200 $- $50,000 $100,000 $150,000 $200,000 $250,000 $300,000 Corporate M365 IT Support Monitoring
  • 24. © 2023 C3 Integrated Solutions. All Rights Reserved. 24 Company 1: Research Firm ▸GCC High enclave ▸10 users, M365 G5 ▸Azure Virtual Desktop ▸User access ▸No additional applications ▸$2000/month usage ▸IT Support ▸$200/user, External vendor ▸Monitoring ▸$35/endpoint (virtual) ▸Total Budget: $343,700 $279,60 0 $64,100 $- $50,000 $100,000 $150,000 $200,000 $250,000 $300,000 $350,000 $400,000 Annual Budget Corporate Enclave
  • 25. © 2023 C3 Integrated Solutions. All Rights Reserved. 25 Company 2: Manufacturing Firm ▸All-In ▸Microsoft 365 GCC High ▸100 users ▸Azure Virtual Desktop ▸Not required ▸Endpoints converted ▸IT Support ▸$200/user ▸External vendor ▸Monitoring ▸$35/endpoint (virtual) ▸Migration costs not considered ▸Total Budget: $401,000 $119,00 0 $240,00 0 $42,000 $- $50,000 $100,000 $150,000 $200,000 $250,000 $300,000 $350,000 $400,000 $450,000 All-In M365 IT Support Monitoring
  • 26. © 2023 C3 Integrated Solutions. All Rights Reserved. 26 Company 3: Professional Services ▸ All-in or Enclave? ▸ Likely the most expensive from a strategy development perspective ▸ Escalating commitment as users are added ▸ Increased risk of unintended spillage ▸ Increased user frustration and confusion ▸ Break even to go all-in just under 30 users * Does not consider other applications nor strain of managing multiple environments for both IT and users $- $100,000 $200,000 $300,000 $400,000 $500,000 $600,000 $700,000 $800,000 0 10 20 30 40 50 60 70 80 90 100 Commerical GCCH Enclave All-In
  • 27. © 2023 C3 Integrated Solutions. All Rights Reserved. 27 About C3 Integrated Solutions Technology Experience 11 years Microsoft partner 6+ years experience in GCC High Multiple Gold competencies Co-Sell Authorized Client Experience 450+ Microsoft 365 clients 200+ GCC High clients Deep NIST, DFARS, ITAR experience Industry Leader First to offer GCC High backup and hosted voice CMMC Registered Practitioner Organization Two successful C3PAO clients
  • 29. Get Started Build the barriers that protect your business, not disrupt it. Our mission is to protect sensitive data and prevent breaches by providing world-class cybersecurity and compliance services to businesses of all sizes. visit c3isit.com