Business Owner’s Guide to CMMC
Ep 10: Maintenance
Watch episode 10 of our Business Owner’s Guide to CMMC series with Ben Scully (Avatara) and Dan Langley (Lupa Advisors), or read the transcript below. Stay tuned weekly for new episodes containing actionable insights and an overview of each CMMC domain.
BEN: Maintenance. Up front [in episode 1] you mentioned that patching systems is one of the first things that you would guide business owners to look at. So, let’s talk a little bit about maintenance.
DAN: Alright, maintenance. What we’re dealing with is six controls here. It deals with the system making sure that the vulnerabilities have been identified and that we’re patching those systems. These controls also talk about, not just I.T. stuff, it’s when the HVAC guy comes into your organization and external people come in to do service on equipment. How is that handled? Are they accessed? Do they get escorted across your organization? What do they have access to? Can they put code on your machines? It’s that overall control of anything that’s going to touch your environment. Again, whether it’s within scope.
BEN: Scope, right. It always come back to that.
DAN: It’s within scope, you have to care about it. And that’s what these controls address.
Stay tuned for Episode 11 on Media Protection.
Need help getting compliant?
Avatara’s DoD Platform is a turnkey solution for centralized data and easier compliance. Schedule a free consultation today to learn more.