CMMC is a Business Challenge

CMMC has a way of turning every conversation into an IT conversation.

Which system should we use? What platform will meet the requirements?

The first questions that you really should be asking are around what your business is doing with Controlled Unclassified Information (CUI). Specifically, questions like: Where does it live? How does it move? Who needs access? Which contracts, workflows, and systems are involved?

These are business questions first, and answering them requires input from the people who understand how the business operates. Your technology team needs to be part of that conversation, but they can’t be the only voice.

Recently, experts from C3, Thrive, and Bluewave came together to discuss CMMC, and we kept coming back to the same point: CMMC is a business challenge. The technical controls are important, but they are only one part of the conversation.

CMMC Key Takeaways

  • CMMC is a business decision that requires leadership and operations participation early on.
  • Scope starts with contracts, CUI flows, systems, and users before technology selection.
  • Rushing to a solution can create unnecessary cost, rework, and disruption.
  • Business processes should shape the compliance strategy, so required changes remain workable in practice.
  • Documentation and evidence should reflect the environment your organization actually operates.

In this clip, we introduce the premise that “CMMC is a business challenge“.

Leadership Has to Set the Direction

Your CEO or president ultimately owns your company’s compliance responsibility. They don’t need to review every configuration or become a cybersecurity specialist, but someone at the executive level does need to make CMMC a business priority and keep your organization moving.

Operations, engineering, sales, finance, and other groups may all affect the CUI boundary. They also know how work gets done in practice. A change that looks simple from an IT perspective may create problems for a production workflow or a team that wasn’t part of the original discussion.

Someone needs to help resolve the tradeoffs between compliance, cost, customer commitments and day-to-day operations. When CMMC is handed to the technical team as a task to complete, those tradeoffs tend to show up later, when they are harder to address.

Check out the webinar clip below where we emphasize that the ultimate responsibility for CMMC compliance rests with your organization’s CEO or president.

Start With Scope

To get your foundation right, you should start with scope.

Before choosing a platform or discussing an enclave, map your environment. Start with the contracts that create the requirement, then follow the CUI.

Where is CUI created, stored, transmitted, or printed? Who needs access? Which applications, locations, and devices touch it? Ask these kinds of questions and determine where you stand.

Your technical team may understand the core production environment very well, while accounting, sales or executive leadership still have access to CUI documents. Those functions belong in the conversation too.

For example, your company might be faced with the decision of either uploading contract attachments into your CRM or saving them to a file storage system like SharePoint. By saving these documents to your CRM, you’re bringing that application into scope. On the other hand, a file storage system like SharePoint is likely already in the scope of your CMMC efforts and wouldn’t move the boundary. This may make the decision seem easy, but keep in mind that the technology decision should also follow the business process question: can your organization make that change and continue to operate effectively?

In this situation, scope is a business design decision. A smaller boundary may reduce cost and complexity, but only when it accurately reflects how your company works.

Watch the clip below for our thoughts on why scope is where we think organizations should start.

Three Mistakes That Create Rework

Most early problems come back to three things:

  1. Alignment breaks down when leadership assumes CMMC belongs to IT.
  2. Scope stays unclear when teams don’t map contracts, CUI, and data flows before making decisions.
  3. Technical teams move into solution mode too quickly, choosing an enclave or service provider before the business requirements are settled.

Each decision affects the next one. A rushed technology choice may need to be redesigned when the organization finds an overlooked workflow or user group. Getting the fundamentals right gives your organization more options later.

Make The SSP Reflect the Business

The System Security Plan, or SSP, should come after your organization understands its business processes. It should describe the environment your company has actually built and is actually running.

A template can make an SSP look complete, but the documentation still has to match the configuration, evidence and way people operate. If those pieces drift apart, the gap usually becomes visible during assessment preparation.

A self-assessment still requires discipline around assessment objectives, implementation and evidence collection. Keeping documentation current and managing changes deliberately makes the process easier to navigate.

Where Should You Start?

Ask three questions:

  • Which contracts and data create our obligation?
  • Where does CUI actually flow?
  • Which business leaders and process owners need to help shape the answer?

At Bluewave, we help you work through those questions, understand your current state, and identify a sensible next step. Once your business understands what it needs to protect and how its work really happens, the technology decisions become much easier to evaluate.

If you are facing a CMMC decision and aren’t sure where to start, connect with us. One of our security advisors can help.

Michael Leggett
Author

Michael Leggett

Follow the expert:

Michael brings more than a decade of experience helping...
Read Full Bio