Preparing for compliance audits, especially under the rigorous requirements of the Cybersecurity Maturity Model Certification (CMMC), can be exhausting.Audit fatigue
| Control | Requirement |
|---|---|
| 3.1.13 | Use cryptographic methods to protect the confidentiality of remote access sessions. |
| 3.1.17 | Protect wireless access using authentication and encryption. |
| 3.1.19 | Encrypt CUI on mobile devices and mobile computing platforms. |
| 3.8.6 | Use cryptographic mechanisms to protect CUI on digital media during transport. |
| 3.13.8 | Use cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission. |
| 3.13.11 | Employ FIPS-validated cryptography when used to protect the confidentiality of CUI. This is the anchor control—it explicitly names the FIPS validation requirement. |
| 3.13.15 | Protect the authenticity of communications sessions. |
| 3.13.16 | Protect the confidentiality of CUI at rest. |
“A condition where remediation of a discovered deficiency is feasible, and a known fix is available or is in process. The deficiency must be documented in an operational plan of action. A temporary deficiency is not based on an ‘in progress’ initial implementation of a CMMC security requirement but arises after implementation. A temporary deficiency may apply during the initial implementation of a security requirement if, during roll-out, specific issues with a very limited subset of equipment is discovered that must be separately addressed. There is no standard duration for which a temporary deficiency may be active. For example, FIPS-validated cryptography that requires a patch and the patched version is no longer the validated version may be a temporary deficiency.”Three takeaways from this section:
Preparing for compliance audits, especially under the rigorous requirements of the Cybersecurity Maturity Model Certification (CMMC), can be exhausting.Audit fatigue