Skip to content

Bankowość i finanse

|

CS.112

Cyber Risk Management in Strategic Investments

Supporting the general contractor of a U.S. military base construction in Europe in meeting CMMC 2.0 and RMF requirements for building automation systems.

Client

General contractor of a U.S. military base construction in Europe (U.S. DoD, USACE, NAVFAC contract)

Challenge

New U.S. Department of Defense cybersecurity standards required the contractor to simultaneously meet two frameworks: CMMC 2.0 for information protection and Risk Management Framework (RMF) for building automation systems (HVAC, access control, power). Non-compliance would prevent project acceptance.

Approach

01

CMMC 2.0 implementation

Development of the compliance model, implementation of Level 1 (17 practices), and preparation for Level 2 (110 requirements per NIST SP 800-171).

02

RMF process execution

6 steps: system categorization (DoDI 8500.01), control selection (UFC 4-410-06, NIST SP 800-53), STIG/SCAP implementation, vulnerability scanning (Nessus), penetration testing, authorization, and monitoring.

Results

0 delays in project acceptance
01

Full CMMC 2.0 compliance

02

Completion of all 6 RMF steps

03

No delays in the construction project schedule

04

Authorization of building automation OT systems

05

Organizational readiness for future DoD contracts

We'll discuss scope, methodology, and timeline.

Book a consultation

Free consultation, no strings attached.