Episode Transcript
Available transcripts are automatically generated. Complete accuracy is not guaranteed.
Austin (00:00):
Hey there, welcome to
the CMMC Compliance Guide
Podcast.
I'm Austin.
And I'm Brooke.
From Justice IT Consulting.
We're here to help businesseslike yours navigate CMMC and
NIST 800-171 compliance.
We're hired guns gettingcompanies fast-tracked to
compliance, but today we're hereto give you all the secrets for
free, so if you want to tackleit yourself, you are equipped to
(00:20):
do so.
Let's dive into today's episodeand keep your business on
track.
Today, we're tackling one ofthe biggest misconceptions we
hear tattered about CMMCcompliance.
isn't that right brookeabsolutely right that
misconception is that it has tobe difficult overwhelming and
borderline impossible tosimplify cmmc compliance we here
at cmmc compliance guidecompletely reject that idea this
(00:43):
entire channel exists to makecompliance more approachable
more strategic and yes easierthe truth is compliance doesn't
have to be scary Most of theroadblocks people run into are
caused by lack of clearguidance, not because CMMC is
impossible.
Right, Brooke?
That's right.
And that is what we try to dohere.
Today's episode is all aboutshowing you that easy doesn't
(01:04):
mean effortless.
It means being strategic.
We're going to show you exactlywhat that looks like.
Okay, what I'd like to do isbreak down what easy really
means when we talk aboutcompliance and why we believe
that CMMC compliance can be easyif you do it right.
We're using the acronym EASY.
Easy, E-A-S-Y, as a framework.
(01:26):
Let's get into it.
First up in our easy acronym isexpert guided.
One of the biggest mistakes wesee companies make is trying to
go at it alone.
Sure, you can DIY compliance,but it'll take you two or three
times longer And usually costsmore.
Brooke (01:40):
Isn't that right,
Brooke?
That's absolutely right.
So, you know, we've talkedabout it on other episodes as
well.
You know, DIY approach is fine,but you need to have your own
experts in-house.
And I mean actual experts, not,you know, Johnny who you don't
like and so you assigned CMMCcompliance to him.
E for expert guided.
You want a CMMC expert.
And so, you know, a lot oftimes instead of DIY, you can
(02:05):
hire somebody expert to comehelp you.
You know, it's about bringingin a coach who can who can guide
you through it and basicallycall the plays right uh they can
uh they don't necessarilythey're not going to be coming
in and and uh running the playsuh scoring the touchdown and all
that kind of fun stuff for younecessarily but but uh they will
call the plays they can theycan call the plays they can help
(02:26):
you strategy and how to how tocomplete all
Austin (02:28):
this so even if someone
diys i mean you don't have to
fully outsource your complianceto somebody but it's it's good
to just bring in an exportregardless whether you're going
to do it yourself in-house orjust like you would a lawyer
you're not going to you caneither hire your own lawyer
right or you can have aconsultant they don't have to do
(02:50):
the entire thing for you
Brooke (02:52):
right that's exactly
right it's not all or nothing
you know I say if you can youcan outsource every single bit
of it and you can with theunderstanding that that you're
still going to be heavilyinvolved in it, and you have to
know all this, have to have someidea of all the controls and
what you're supposed to be doingbecause you're the one that has
to execute on them no matterwhat.
So there can be somebody thatcomes in and helps you get the
(03:15):
policies done, helps you throughimplementation, helps you with
ongoing support and all that.
So that would be fullyoutsourced, basically.
You still have to be involved.
You still have to understand.
You still have to be part ofthat whole process.
Or if you DIY, you can say,hey, hey, we need somebody
expert to come in and justconsult with us and call the
(03:36):
plays, right, and tell us wherewe're at, where we need to be,
and tell us where we need to go,right?
And so that would be kind ofthe difference.
And you can hire somebody forany part of this, but it's not
necessarily
Austin (03:53):
all or nothing.
So that would be the first stepin making compliance easy would
be having someone that is anexpert come in and at least
consult with you.
Yes.
Absolutely.
Okay.
Next up in our acronym EASY isA.
aligned for requirements.
What we've noticed inconsulting with a lot of
companies and doing theircompliance with them, not for
(04:13):
them, but with them, is how weapproach it.
A huge pitfall that we noticefrom the get-go is most people
tend to focus on tech first,technical.
What firewall do I need?
What tool solves this?
What security license can Ibuy?
And we view that as a hugepitfall.
Can you kind of tell me why?
Brooke (04:34):
Sure.
It is a huge pitfall becauseAnd really because it's not a
technical problem.
It's just not.
It is a business process.
Compliances.
Compliances, yes.
Compliance with CMMC, right?
And really any compliance.
It's business process.
It's the way you do things,right?
And yes, part of that is goingto be technology.
Absolutely.
(04:56):
100% it is.
This is not strictly IT.
It's not strictly technology.
So first of all, you have toknow what you have and why
you're supposed to be compliant,right?
Then you have to know wheredoes that data go?
Where does it come from?
Where does it go?
What happens with it?
And that all helps you to knowwhat you have.
to know what the flow of thedata is to scope your problem
(05:19):
correctly.
Scope your compliancecorrectly.
Once you have that scoped, youmay not necessarily want to
start with access control in theA's.
You may want to start somewhereelse in there, but you really
need to start with knowing whatyou have and where it goes.
And then, of course, you haveto be aligned with controls.
(05:40):
This is where a knowledgeablepartner comes in.
The coach, the expert, they'llhelp you trace everything back
to the appropriate controlsthey'll align everything for you
that's where an expert comes into help you with this and help
you align everything back tocontrols to where it's supposed
to be and not just doing thingswilly-nilly by you know we got
(06:00):
to have the we got to figure outthe technology solutions right
and it's again it's not abouttechnology part of it but it's
it's about the whole businessprocess and making sure you're
aligned to those controls andnot just not just the NIST
controls but the rest of therest
Austin (06:16):
of CMMC.
To your point, you may not wantto start with access control.
And if you're doing techsolutions first, you might end
up with a $15,000 iPad system atthe front door and a man trap
to track all the visitors thatcome through in and out of your
building whenever a piece ofpaper might work.
That's true.
Brooke (06:33):
You know, you can figure
out how exactly, once you have
a holistic idea of everything,of what all is needed, which
would be your POAM, right?
Then you can kind of figure outwhere your technology where
your solutions need to be.
Or you can have a $15,000solution for what a piece of
paper might work for, alongwith, you know, other very
(06:54):
expensive solutions that will dothe job that are not necessary.
Right.
Austin (07:00):
Hey, some of us like
shiny things, you know.
The next in our acronym, EASY,is S for streamlined approach.
CMMC shouldn't feel like you'rewandering through the dark.
What can you say about that,Brooke?
Brooke (07:11):
The DOD really has laid
out some good streamlined
processes.
CAP, the CMMC assessmentprocess, which assessors have to
follow that.
There can always bedifferences, of course, but it
lays out a really goodstreamlined approach to making
sure all the assessments are assimilar as possible.
They've got the assessmentguidelines to show you how
(07:32):
you're supposed to assess thesethings, which you do not have
access to.
We go through and do our gapsanalysis and all that kind of
fun stuff, but they have thethose assessment guidelines to
help you out and help you figurethis out, right?
And then there's commonaccepted tools, you know, like
Microsoft 365 GCC High, youknow?
You don't have to reinvent thewheel on every one of these
(07:53):
things, you know?
Unless you don't want to paythe cost of Microsoft 365 GCC
High, which I understand, youknow, then, you know, do you
want to go with another vendoror do you, what do you want to
do?
But there are some acceptedsolutions that you don't
necessarily have to reinvent
Austin (08:08):
the wheel on.
So really, we're just talkingabout using proven approaches
instead of trying to reinventthe wheel.
Much like I think we've said inprevious episodes, if you're a
metal fabricator or a CNC shop,you're not...
I mean, I guess...
By all means, if you want tobuy the foundry and smelt your
own metal, you can, butsometimes it's easier to bite
the bullet and get the rawmaterials elsewhere, just like
(08:31):
GCC High.
You don't have to use it.
There are other solutions, oryou could go and create your own
email server and prove it to anassessor that that's going to
work, or you could just usesomething that they're familiar
with and that they're morelikely to approve, and that's
kind of what we're suggesting isgo streamline go with what's
(08:54):
accepted practice and make it alittle easier.
You can absolutely
Brooke (08:59):
design your own
solutions, but one, is it going
to check off all the boxes?
I have a problem with peoplejust checking boxes, so that's a
different story.
But is it going to check allthe boxes off for this
compliance?
Yes or no, maybe so.
But what's the ongoingmanagement of it?
What does that look like?
If you design your ownsolution, is it going to depend
(09:19):
on what it is, how you get itupdated, how you make sure it
continues to comply How do youdo all these things, right?
Or if you use something that's365 GCC high or Prevail or
something else, you know whereit stands and you know ongoing
what it's going to take.
Austin (09:34):
Why is for you your
competitive edge?
Because I stop at E-A-S.
That's no fun.
We have customers andprospective customers that fall
on a couple different camps.
And the ones that we see kindof on the leading edge of things
and that are leaning intocompliance are using this as a
(09:58):
competitive advantage.
And using appliance in theirfavor.
And so, um, I'll let you takeit over from there, but, um, you
know, it kind of, they, theyfeel that helps them with maybe
contracts and stuff in thefuture.
Brooke (10:16):
Absolutely.
That's what we've heard, youknow, and, and, uh, what we can,
what we kind of see is thatforward thinking businesses are,
are, uh, going to use this, uh,as a competitive edge, just
like you said.
Uh, and, and they, they kind ofsee, um, uh, being careful not
to tell you necessarily what I'mthinking, but that's, you know,
(10:37):
This is probably going to washout quite a few suppliers or
some suppliers, however manythat may be.
It's going to wash some outbecause they don't want to deal
with compliance.
Shoot, I had somebody tell methe other day, if I have to do
all this and I have to spend$100,000 just for an assessment
every three years, I'm not goingto do it.
I will go find businesselsewhere.
(10:59):
I don't blame you.
If it's not that much businessto you, then don't blame me a
bit.
It will wash some people out.
The The pool will get smalleras a result of this compliance.
And so those who are left andhave risen to the challenge and
met the bar of compliance andgot their L2 certification, they
(11:20):
will have a competitiveadvantage.
And the sooner you get that,the sooner you'll be able to win
contracts easier because youhave that.
All you have to do is say, hereit is,
Austin (11:28):
basically.
Two sides to every coin.
There is.
In an opportunity or one thatdoesn't look like an
opportunity.
It looks more like animposition.
That's right.
Some people do.
That's right.
Okay, so here's the recap.
Easy doesn't mean thatcompliance is effortless.
It means E, you've got expertguidance instead of going at it
alone.
A, you align everything to theactual real requirements, not
(11:51):
focusing on tools or tech first.
S, you follow a streamlined,proven process instead of
reinventing the wheel.
And Y, you turn your compliancerequirements into a competitive
edge or an advantage.
Brooke (12:04):
And if anybody's telling
you that CMMC compliance can't
be easy...
They're not necessarily wrong,but it can be made easier.
That's what people like us areout here to do is help you out,
make it easier, not make iteffortless because there will be
effort involved.
It'll just...
It'll just be less effort andguided expert
Austin (12:28):
help to get you there.
If you have any questions aboutwhat we've covered here, please
reach out to us.
We're here to help fast-trackyour compliance journey.
Please text, email, or call us,and we'll answer your questions
for free here on the podcast.
Find our contact information atcmmccomplianceguide.com.
Stay tuned for our nextepisode.
(12:49):
Until then, stay compliant andstay secure.
Like, subscribe, and share.