Table of Contents
Introduction:
Level 3 of the Cybersecurity Maturity Model Certification (CMMC) expands on Level 2 and covers Federal Acquisition Regulation (FAR) procedures as well as NIST SP 800-171 Rev 1 controls. It also offers 20 more critical cyber hygiene measures. This CMMC level stresses the significance of cybersecurity planning and maintenance.
Contractors and subcontractors working for the US Department of Defense (DoD) should be familiar with the Cybersecurity Maturity Model Certification (CMMC) framework. It is a collection of rules established by the Department of Defense for implementing cybersecurity protocols for contractors. These policies supplement and overlap with the provisions of the Defense Federal Acquisition Regulation Supplement (DFARS).
What are the requirements of CMMC level 3?
In contrast to Level 2, Level 3 of CMMC denotes completion. Level 3 builds on the preparation and transitional work of the previous levels to eventually achieve the aim of CUI protection, incorporating all of NIST SP 800-171, as well as many more protections from other sources.
This entails achieving “good cyber hygiene” across practices and ensuring that processes are institutionalised: not just adopted and recorded, but also managed. At Level 3 of the CMMC, you must have an action plan in place, as well as sufficient resources for long-term implementation.
Level 3 includes 58 more practises for a grand total of 130. 45 of these 58 are from NIST SP 800-171, while 13 are from other, unrelated sources. CMMC Level 3 certification necessitates far more controls than Levels 1 and 2. Level 3 requires a total of 130 processes. These restrictions are classified into 17 domains. Let’s have a look at what each of these areas entails:
1. Access Control:
Is concerned with identifying and restricting the persons and other entities who have access to your systems. It also entails restricting the types of functions and transactions that authorised users are permitted to conduct. Level 3 introduces eight new practices::
- To secure wireless access, use authentication and encryption.
- To ensure the confidentiality of remote access sessions, use cryptography.
- Separate individuals’ responsibilities to limit the risk of malicious behaviour, regardless of coordination (and to be able to identify these, as distinct from collusion).
- Prevent privileged functions from being executed from non-privileged accounts; document and analyse all executive and other privileged functions in audit logs.
- When certain circumstances are met, user access sessions are automatically terminated.
- All mobile device access should be monitored and controlled.
- Authorization is required for remote execution of security and non-security functions, as well as access to any security-related information.
- Encrypt CUI on any mobile device or computing platform.
2. Asset Management:
Covers standards for managing services and devices that store or interact with your data, whether on your network or in the cloud. Level 3 introduces one new practice:
- Establish precise processes and procedures for dealing with CUI and related data.
3. Awareness and Training:
Controls require military contractors to maintain a training programme for their employees, contractors, and vendors so that they are prepared to deal with any cybersecurity threats that may arise. Level 3 introduces one new practice:
- Provide security awareness training to employees, including best practices for monitoring, detecting, and reporting on insider threats from other employees.
4. Audit and Accountabilty:
Controls define how to build and maintain audit trails, which allow you to track individual user and system behaviour. Level 3 introduces 7 new controls:
- Review all logged occurrences on a regular basis and update or correct as needed.
- In the case that the auditing and/or logging processes fail, a warning is required.
- Collect all audit-related information into one or more central repositories to ease audit-related review, analysis, and strategy.
- Protect audit-related information and audit logs from all types of illegal access, including usage, alteration, and deletion.
- Access to auditing functions should be restricted to a small group of privileged users.
- Correlate audit record review and analysis with reporting related to inquiry and response to illegal, unauthorised, or otherwise irregular activity.
- With fast techniques for audit record reduction and audit report production, you may perform immediate, on-demand analysis and reporting.
5. Security Assesment:
Discusses the necessity for periodic assessment and testing to ensure that your system security plans are working. There are two new practices introduced in level 3:
- In practise, monitor security controls to verify their continued efficacy and safety.
- Use independent security assessment(s) for any and all software developed internally, for internal use, and recognised as a risk area.
6. Configuration Management:
Specifies the prerequisites for building baseline setups and inventories, as well as making changes to those systems It is also necessary for your organisation to keep an eye out for any unapproved alterations. There are three new practices introduced at this level:
- Control (define, document, and approve) and restrict physical and logical access to systems in accordance with the most recent changes to security configurations.
- Reduce and, ideally, eliminate all access to and usage of non-essential software, hardware, functions, services, and systems (restrict, deactivate, block, etc.).
- Use “blacklisting” (deny by exception) to prevent unauthorised use or access, or “whitelisting” (permit by exception) to allow permitted use or access.
7. Identification and Aunthentication:
In that it focuses on user access, it is similar to Domain Access Control. However, in this scenario, the emphasis is on ensuring that the individual using an account is, in fact, the correct user. There are 4 new practices at level 3:
- Use multi-factor authentication (MFA) for privileged account local and network access, as well as non-privileged account network access.
- For access to privileged and non-privileged accounts, use “replay resistant” authentication mechanisms (nonces, TLS, one-time authenticators, etc.).
- Prevent the reuse of identifying credentials (usernames, etc.) by the same or other users for a set period of time once an account has been terminated or other changes have been made to it.
- After an organizationally specified period of inactivity in the account, disable identification credentials – deactivating also prevents reuse.
8. Incident Response:
Controls address the requirement to develop a plan that anticipates security problems and describes how you will respond if they occur. There are two additional practices at this level:
- Ensure that all occurrences, both internal and external to the company, are tracked, documented, and reported on.
- Test the organization’s incident response skills on a regular basis.
9. Maintanence:
Is founded on the assumption that all computer systems will fail at some point. As a result, defence contractors must secure vital services and data from vulnerabilities in the event of a system failure. There are two additional practices in level 3:
- Sanitize equipment that has been transferred off-site for maintenance by eradicating any and all CUI, traces of CUI, and potential pathways to illegitimate CUI access.
- Prior to installing or utilising diagnostic or test programmes on organisational systems, inspect any media containing diagnostic or test programmes to ensure it is free of all forms of malicious code.
10. Media Protection:
Covers the use of removable media to store data, encompassing both electronic and paper storage devices Data storage on removable media can be hazardous, thus it must be carefully monitored. There are 4 additional practices at this level:
- Mark (or code) any CUI-containing material for restricted dissemination.
- Disallow the usage of any portable storage devices whose ownership or provenance is unknown.
- Restriction of access to CUI-containing media; accountability for such CUI-related media while movement outside of organization-controlled zones.
- Use encryption and/or physical protections to ensure the confidentiality of CUI stored on digital media, particularly during transport.
11. Physical Protection:
Explains the need of protecting your physical location and equipment from illegal entry, as such access could expose your data to security concerns. There is one new practice at this level:
- Extend physical precautions for CUI to all other workplaces.
12. Personnel Security:
Requires your company to filter individuals before granting access to systems containing regulated unclassified information (CUI). When a person is transferred or terminated and no longer has access to data, you must take precautions to preserve that data.
13. Recovery:
Requires your company to filter individuals before granting access to systems containing regulated unclassified information (CUI). When a person is transferred or terminated and no longer has access to data, you must take precautions to preserve that data.
14. Risk Management:
Focuses on the importance of doing regular risk assessments of your data and systems in order to keep them secure. There are three new additional practices at this level:
- Conduct periodic risk assessments, identifying and prioritising risks to address based on organizationally determined categories, sources, and other criteria.
- Create and implement risk-mitigation plans as they emerge.
- To prevent risks from these specific vectors, manage goods that are not supported by vendors separately; impose access and usage limitations independently of other assets.
15. Situational:
Demands a company to take cyber threat intelligence from external sources seriously and respond properly. There is one additional practise at this level:
- Collect, analyse, and disseminate any and all relevant cyber threat intelligence from external sources, including respected reports and forums, with stakeholders.
16. Systems and Communications:
Comprises a comprehensive set of rules aimed to protect information transfer within a system. It also forbids the dissemination of CUI in public forums, NIST repeatedly relies on FIPS-validated encryption to protect CUI in every circumstance. There are 15 new practices at level 3:
- To secure the confidentiality of CUI, use cryptography according to FIPS requirements.
- Ensure that information security is optimised for effectiveness and efficiency across all parts of information systems, including but not limited to:
- Designs for architecture and infrastructure
- Techniques for developing software
- Principles of System Engineering
- User access and system management are completely independent functions.
- Prevent the unintentional, unlawful, or otherwise unsafe transfer of sensitive information via shared system resources, whether internally or externally.
- Implement a “whitelist” approach to network communications traffic by refusing all such traffic by default and permitting it only on a case-by-case basis.
- Prevent the potentially dangerous phenomena of “split tunnelling,” in which remote devices establish a non-remote connection(s) with the organization’s systems as well as one or more connections to resources in external networks at the same time.
- To avoid unauthorised disclosure of CUI, use encryption and/or physical precautions, particularly during transmission or transportation.
- Terminate network connection sessions connected to communication either immediately at the end of the session or after an organizationally defined time of inactivity.
- Keep track of all cryptographic keys used across all systems.
- Control and strictly supervise the use of mobile code (s).
- Keep a close eye on the adoption of Voice over Internet Protocol (VoIP) technologies.
- Ensure authenticity in all communication sessions.
- Ensure the safety of CUI while it is “at rest” in storage or another passive capacity.
- Make use of powerful Domain Name System (DNS) filtering services.
- Create and enforce a policy that prohibits CUI from being published or “posted” on external, publicly available media and platforms.
17. Systems and Information Integrity:
Defence contractors must monitor for vulnerabilities and apply security fixes as appropriate. You should also take advantage of security capability updates. There are 3 new practices at this level:
- Deploy spam detection and prevention measures at every entry, exit, and access point to organisational information systems.
- Make use of all resources available to identify and prevent document falsification.
- Use “sandboxing” to detect, filter, block, and generally prevent harmful or suspicious email communications.
How to comply with level 3 CMMC compliance?
At Level 3 of the CMMC, there are a total of 130 practices to be concerned about — the 72 from Level 2 plus the 58 added in Level 3. Furthermore, institutionalisation is more difficult at this stage because you must go from basic documentation to more active process management.
This includes demonstrating to your assessor that you have a plan and resources in place to maintain these practises going in the long run. Certification can only be granted by a Certified Third Party Assessment Organization (C3PAO) that has been approved by the CMMC Accreditation Body.
Conclusion:
Your businesses’ security should be a primary priority. Making security a priority at all levels of the organisation aids in the achievement of a strong security posture. By implementing CMMC Level 3 requirements, defence contractors will be well-positioned in the ongoing process of protecting their networks and data. We at Security Pilgrim are here to assist you in ensuring your business CMMC compliance, to ensure a robust and secure business.
