COVID-19 Remote Working Leveraging NIST/CMMC Cyber Guidance
NIST SP800-171 and CMMC best practices enclosed provide guidance to meet compliance requirements for remote working. The talented Cytellix Corporation cyber analysts prepared the following guidance. Please take advantage of this valuable set of insights to support your organizations needs for safe remote working and cyber compliance: "Its just good cyber hygiene"
Remote Work Cybersecurity Concerns
Working from home, along with other forms of remote work, can present many challenges for organizations trying to balance security concerns with the ability to operate as effectively as possible. The NIST SP 800-171 and now CMMC standards for cybersecurity define several best practices that help to secure access to systems and data, as well as the practices needed to continue business operations by remote workers.
Practices directly related to NIST SP 800-171/CMMC (the Cybersecurity Maturity Model Certification)
Secure connections to your environment from the outside
If employees require access to systems and/or data that reside at company facilities, maintaining the security of those connections is a top priority. Remote access extends the security control enabled on-premise to remotely connected systems, but different risks need to be mitigated with expanded connectivity.
Consider and authorize high-privileged remote access to both systems and data, following the least privilege principle.
High privileged access carries inherent risks that are amplified when extended over remote access. With unrestricted high-privilege access, a compromise of a system admin account may result in unchecked lateral movement of attacks by external threats in your environment. Limiting the scope of high-privileged access as much as is feasible, for both systems and data, helps to mitigate the risks related to compromise of high-privilege accounts.
Ensure procedures are in place for the handling of sensitive data (controlled unclassified information, federal contract information, personal identifiable information, and other confidential/proprietary data)
Measures for secure handling of sensitive data should cover operations and activities both inside and outside controlled facilities and spaces. Certain types of data have more directed requirements for handling (e.g. CUI/FCI), but organizations should determine how other types of sensitive data should be handled—from receiving and processing, to storage, and disposal/destruction.
Establish and enforce guidelines for system and device security
The systems used for remote work, whether company provided or BYOD, should have a level of security enforcement to mitigate risks from unauthorized installations and working in unsecured spaces and networks. Also, with corporate provided systems seeing more general use in remote work scenarios, control over physical media use help reduce risk of malware attacks and data breaches.
Other considerations for remote work security
Contact Cytellix: [email protected]
Cytellix® Cyber Watch Platform (C-CWP™)
C-CWP™ provides value by baselining the truth about the true cyber posture of our customers. We then move towards a cybersecurity mesh architecture of integrated continuous improvement that aligns with business objectives. C-CWP™ is an interoperable and open platform designed for change in posture and threat landscape. C-CWP™ is delivered as a complete “turnkey” outsourced service or in combination with internal teams and previously purchased security capabilities
Cytellix® Endpoint Detection Response (C-EDR™)
Cytellix® Endpoint Detection & Response (C-EDR™) is a flexible solution that can be used standalone, enables bring-your-own-license or can be provided turnkey as a complete managed solution with our C-GRC™, C-MDR™, XDR, SOC 24x7x365 managed Turnkey Solutions. The Cytellix turnkey C-EDR™ is a Enterprise grade solution that is complete and has full integration with the Cytellix platform.
Cytellix® Governance Risk & Compliance (C-GRC™) & IT Risk Management (IRM)
Risk Management requirements are evolving to align to the changes arising from compliance risk shifting towards regulatory impact on business process. The demand on organizations to understand their cybersecurity posture, report status and meet regulatory obligations is driving demand across the enterprise (small>large) for a non-technical, turnkey all-inclusive platform.
Cytellix® Managed Detection Response (C-MDR™)
Patented technology compiles information from the vulnerability's, governance, risk, compliance assessments, event data, and analytics. Delivers real-time analysis, including continuous improvement visualization and scorecard.
Extended Detection Response (C-XDR™)
The Cytellix® Extended Detection Response (C-XDR™) solution leverages our flagship Cytellix Cyber Watch Portal (C-CWP™) as turnkey compliance, awareness and response platform. Our C-XDR™ includes, vulnerability management, devices profiling, network segmentation, asset discover, threat intelligence, leak detection, EDR, pre-defined use cases for log ingestion and correlation of threats and our USA based 24x7x365 Security Operations Center (SOC). The Cytellix platform leverages our in-house AI/ML models for real-time telemetry, threat discovery/hunting and ticket reduction. This is a complete turn-key, affordable XDR solution.
Cybersecurity for Small and Medium Business
Cytellix® has designed its platform to enable the small and medium business to adopt quickly, with low friction at an affordable price. We have found that the tasks of both regulatory compliance with cybersecurity frameworks and building a high quality cybersecurity monitoring and infrastructure is a significant time, resource and expense issue for SMB's.
We will get btackts to you as soon as posTsible.
Oops, there was an error sending your message.
Please try again later.
The Cytellix® team of experts have been delivering cybersecurity for the past 15-years to some of the largest networks in the world. This expertise is delivered to our SMB customers as an affordable, precise, and comprehensive solution designed for organizations who need to comply with Cybersecurity regulatory requirements. There is no other fully integrated GRC, MDR, XDR, EDR single pane of glass solution that is as rich in capabilities, as easy to use and available in production today.
Cytellix® - Patent Pending. All Rights are Reserved By Cytellix®