Q: 3
When validating an OSC’s proposed CMMC assessment scope, the Assessment Team finds that the
OSC has properly categorized its assets. The OSC has contracted an External Service Provider (ESP)
for various cybersecurity functions. The ESP has deployed FortiSIEM and Splunk for real-time security
monitoring, threat intelligence, application monitoring, log management, and reporting. They also
deployed Microsoft Intune and configured app protection policies blocking proscribed apps and
those suspected of data exfiltration. How should you handle the ESP during the CMMC assessment?
Options
Discussion
Honestly these ESP scoping questions drive me nuts. C tbh, since reviewing the SSP per CA.L2-3.12.4 feels like what they'd expect when it's about documentation. I think that's enough unless the OSC actually outsources implementation, but not 100% sure here.
Nah, I think A makes more sense. ESP delivers critical security controls for CUI so full assessment is needed, not just reviewing SSP or limiting to one practice. D is a common trap since ESPs are definitely in scope for CMMC if they touch CUI functions.
Not D, B. Is "best" practice the key here, or are we supposed to check only required documentation first before looking at technical controls? That would change if it's just about order of operations.
C , because if all you do is review the SSP per CA.L2-3.12.4 that technically covers documentation, right?
I get why someone might think C or B, since ESPs often provide their own SSPs. But if the ESP is actually operating SIEM and Intune that protect CUI assets, you have to fully assess them under CMMC practices (A). The only exception would be if the services were truly segregated from CUI, which isn't the case here. Let me know if you see a different angle.
Why do people keep picking C? The ESP provides direct security services tied to CUI, so full assessment (A) applies. Scoping guidance makes them in-scope, not just a doc review. Let me know if I'm missing something here.
Think it's more C in this scenario. If the ESP is just providing services, you review their System Security Plan under CA.L2-3.12.4 to ensure proper documentation. Not fully confident, could be missing a nuance here.
Be respectful. No spam.