The internet (a.k.a. the cloud) has become an essential component of doing business. That’s as true for DoD prime contractors and subcontractors as it is for any other industry segment. The benefits of using cloud service providers (CSPs) are numerous, including lower maintenance costs, higher efficiency, and the ability to scale cloud-based solutions to meet your current business needs. Most CSPs also offer top-notch security—a matter of paramount importance to DoD primes and subs.
But how do you select a CSP that aligns with your need to achieve compliance with CMMC? What does CMMC require of a DoD contractor’s CSPs? How do you maintain compliance while using cloud services? This post explores those concerns and offers best practices for promoting compliance in the cloud.
Selecting a Compliant CSP
In most cases, the CMMC rule requires that CSPs have Federal Risk and Authorization Management Program (FedRAMP) authorization to prove their ability to securely handle sensitive data. However, if you are using a Managed Service Provider (MSP) or Managed Security Service Provider (MSSP) who also provides cloud services, that provider will need CMMC certification at the same level as your organization as well as FedRAMP authorization. FedRAMP is a government program geared specifically toward the safe handling of government data in the cloud. As such, it has many parallels with CMMC, including a rigorous assessment and authorization process.
When selecting a CSP, you must understand your own organization’s CMMC level as well as the type of data your CSP will be handling for you. Your CSP must have FedRAMP authorization at the appropriate level: Low, Moderate, or High. If your CSP handles Federal Contract Information (FCI) for you, they will need a minimum of FedRAMP Low authorization. If they handle your Controlled Unclassified Information (CUI), they will need FedRAMP Moderate or higher. Or if the CSP is not yet FedRAMP-authorized, it may be acceptable if they can prove FedRAMP equivalency.
Some other considerations when selecting a CSP:
Best Practices for Ongoing Compliance
Once you have selected your CSP, you will need to configure your cloud services to align with CMMC security requirements. Key security practices include:
Maintaining CMMC compliance is an ongoing commitment. The following practices can help you maintain your cybersecurity posture particularly in regard to working with CSPs.
CyberNINES is here to help! If you have specific questions or would like to talk over your options, just send us a contact request at this link, and one of our cybersecurity experts will soon be in touch. You can also select this link for a free e-book describing what to look for in CSPs, MSPs, MSSPs, and the myriad other service providers you may work with on your CMMC journey.
Next up: Team building for CMMC compliance
Resources