Automating Cybersecurity Maturity Model Certification Assessment Scoping in Microsoft Azure
Open Access DepositedThe Cybersecurity Maturity Model Certification (CMMC) Program serves as the Department of Defense (DoD) framework for validating the implementation of adequate security of Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) across the Defense Industrial Base (DIB). Organizations Seeking Certification (OSC) at CMMC Level 2 must demonstrate that they have implemented all 110 security controls defined in National Institute of Standards and Technology Special Publication 800-171 Revision 2 (NIST SP 800-171r2). Prior to engaging in a CMMC certification assessment, organizations must define the scope of their assessment in accordance with the CMMC Level 2 Scoping Guide, which specifies the assets and environments to be included.This research presents an automation framework designed for Microsoft Azure Government Community Cloud (GCC) High environments which assists organizations in identification of information system components, categorization of assets, and visualization of scoping determinations. The framework of the research requires only Microsoft GCC High native services such as Microsoft Purview, Microsoft Intune, Microsoft Entra ID, and Azure Monitor, with automation pipelines developed in Azure Data Factory pipelines. This framework collects, normalizes, and correlates evidence related to system components and user interactions. The resulting data are classified according to CMMC Level 2 Scoping Guidance categories and presented using Power BI dashboards for OSC and assessor evaluation.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.