Open navigation menu - Kieri Solutions
What Passed a DOD Assessment for System Baselining and Inventories

What Passed a DOD Assessment for System Baselining and Inventories

CMMC system inventory and baseline configuration monitoring dashboard

In this article

Real evidence from a successful CMMC Level 2 assessment that you can learn from


Practice 3.4.1 looks simple on the surface. Establish and maintain baseline configurations and inventories of organizational systems.

Then you read the assessment objectives. Hardware, software, firmware, and documentation. For both baselines AND inventories. Maintained over time. Reviewed periodically.

Suddenly you’re looking at one of the most complex practices in CMMC Level 2.

We interviewed Steve Pratt from SENTAR, an authorized C3PAO that passed their own DIBCAC assessment, to understand exactly what they showed assessors and what worked.

The First Thing Assessors Request During Scoping

Before your assessment even begins, you’ll have a scoping call. During that call, assessors request two things immediately: your system inventory and your scoping diagram.

Here’s the critical part. They compare them.

If a device appears in your diagram but not your inventory, that’s an immediate red flag. If something is in your inventory but missing from your diagram, same problem.

Your inventory and your scoping diagram must match exactly. Every device that processes, stores, or transmits CUI needs to appear in both places with consistent information.

Categorizing Devices by CMMC Scoping Guide

Many organizations have robust system inventories. They track hardware, software, and device owners. They scan networks and maintain accurate records.

But they haven’t categorized devices according to the CMMC scoping guide.

Is this a CUI Asset? Is it a Security Protection Asset? Is it a Contractor Risk Managed Asset? Is it a Specialized Asset?

These categories come directly from the CMMC scoping guide. Assessors expect to see them. Organizations that haven’t done this categorization often think they’re ready for assessment when they’re not.

Before your scoping call, go through every device in your inventory and assign the appropriate category from the scoping guide.

How SENTAR Built Their System Inventory

SENTAR used their help desk software as the foundation for their system inventory. The software includes network scanning capability that discovers devices automatically.

Automated Discovery with Manual Control

The scanning feature finds devices on the network and gathers information automatically. Hardware details, software installed, firmware versions. This creates a baseline inventory without manual data entry for every device.

But automated discovery isn’t perfect. Sometimes it misses devices. Sometimes it sees one device as two separate entries (like when a laptop connects via both WiFi and ethernet).

SENTAR’s system allows manual modification. They can add devices the scanner missed. They can merge duplicate entries. They can correct information the scanner got wrong.

This combination of automated discovery and manual control creates accurate inventories without excessive administrative burden.

Tying Devices to Owners

Every device in their inventory connects to an owner. This isn’t just good practice for asset management. It supports CMMC requirements around accountability and access control.

When assessors ask who’s responsible for a particular device, you need an answer. Your inventory should provide it.

Showing the Inventory is Maintained

Static inventories don’t satisfy CMMC requirements. You need to demonstrate that the inventory stays current as your environment changes.

SENTAR showed evidence in two ways.

For additions, they demonstrated how new devices appear automatically when connected to the network. The system prompts administrators to confirm whether new devices are authorized and should be added to the inventory.

For removals, they showed system logs documenting when devices were retired and removed from the inventory. The audit trail proves ongoing maintenance.

What About Hardware, Software, Firmware, and Documentation?

The assessment objectives mention hardware, software, firmware, and documentation for system inventories. Many organizations struggle with how to address all four.

Hardware, Software, and Firmware in Inventory

SENTAR showed their inventory includes hardware details (device type, model, specifications), software installed on each device, and firmware versions for network equipment.

Their help desk software captures much of this automatically through scanning. Administrators supplement with manual entries where needed.

Documentation in Inventory

Here’s good news. SENTAR’s DIBCAC assessors didn’t strictly require documentation as part of the system inventory.

Documentation can mean policies applying to devices, best practices documents, or user manuals. Including all of this in a system inventory is challenging.

In practice, documentation often fits better with baselines than with inventories. Your baseline documentation explains how devices should be configured. Your inventory tracks what devices exist.

If your assessor asks about documentation in your inventory, be prepared to explain your approach. But don’t assume you need elaborate documentation linked to every inventory entry.

Creating Baseline Configurations That Work

Baselines describe how systems should be configured. But what exactly does that mean in practice?

One Baseline Per Device Type

SENTAR doesn’t create individual baselines for each of their laptops. They create one baseline for each device type and operating system combination.

All Windows 10 laptops share one baseline. If they had Windows 11 laptops, those would have a separate baseline.

This is practical and scalable. You’re not maintaining dozens or hundreds of separate baseline documents. You’re maintaining baselines for each category of device.

Supplemental Baselines for Server Roles

Servers add complexity because they serve different functions. A file server has different configuration requirements than an Exchange server or a SharePoint server.

SENTAR handles this with layered baselines. Every server gets the base server baseline for that operating system. Then it gets a supplemental baseline for its specific role.

The base baseline covers configurations common to all servers. The supplemental baseline covers role-specific settings.

This approach keeps documentation manageable while still capturing the unique requirements of each server type.

Scripts and Installers in Baselines

When building a new system, you might run scripts or installers to apply configurations. Are these part of your baseline?

SENTAR’s approach: if the script remains on the system after deployment, it’s part of the baseline documentation. If the script runs once during setup and then gets removed, it’s captured in the procedure for applying baselines rather than the baseline itself.

Either way, the configuration change gets documented. The difference is where that documentation lives.

What Does a Baseline Actually Look Like?

This question seems basic but trips up many organizations. What format should baselines take?

Images as Baselines

The classic baseline is a system image. You configure a device correctly, capture an image, and use that image to deploy new devices. The image IS your baseline.

For virtual servers, SENTAR uses snapshots as their baseline starting point. Every new virtual server begins from the approved snapshot.

For network devices like switches and firewalls, they export configuration files. The exported config is the baseline. If they need to rebuild or replace the device, they import that configuration.

Checklists as Baselines

Not every organization can maintain images for every device type. Gold images require infrastructure to store and deploy. Some environments don’t support this approach.

SENTAR uses a checklist approach for some baselines, particularly for configurations applied after initial deployment.

The checklist documents every setting that gets changed from the default. Disable these services. Enable these features. Apply these settings. Close these ports.

If someone else needed to configure an identical device, they could follow the checklist and achieve the same result.

Assessors will accept checklists as a rudimentary form of baseline. It’s not ideal, but it meets the requirement if the checklist is thorough and accurate.

Group Policy as Part of Baselines

For Windows environments with Active Directory, group policy handles many configuration settings automatically.

SENTAR includes group policy in their baseline approach. Once a laptop joins the domain and gets added to the correct organizational unit, group policy applies standardized configurations.

This works well for ongoing compliance. Devices stay configured correctly because group policy enforces it. But you still need documentation explaining what group policy settings apply and why.

The Formal Baseline Review Process

Baselines can’t be static. Software updates, security patches, and changing requirements mean baselines need periodic review.

Annual Formal Review

SENTAR performs a formal baseline review annually. This scheduled review examines whether baselines remain appropriate and identifies needed updates.

Annual review satisfies the “maintained” aspect of the requirement. You’re not just creating baselines once. You’re actively managing them over time.

Version-Change Updates

Major software or firmware version changes trigger baseline updates outside the annual cycle. Moving from one Windows version to another, upgrading firewall firmware, or deploying new server software all require baseline updates.

These updates go through change management. The change board reviews and approves baseline modifications before they’re implemented.

Patch-Level Tracking

SENTAR updates baseline documentation for patch levels but doesn’t require full change board review for routine patches.

This is a practical distinction. Running a formal change process for every monthly Windows patch would create administrative burden without proportional security benefit. But you still want baseline documentation to reflect current patch levels.

What Assessors Actually Verified

Understanding what assessors check helps you prepare appropriate evidence.

Documentation Review

Assessors reviewed SENTAR’s baseline documentation. They wanted to see that baselines existed, were documented, and covered the required elements.

They also reviewed procedures for applying baselines to new systems. How do you ensure a new laptop matches the baseline? What’s the process for deploying a new server?

Random Device Verification

Assessors randomly selected devices to verify against baselines. For SENTAR, this included two or three laptops, two servers, and a switch.

They compared actual device configurations to baseline documentation. Do the settings on this laptop match what your baseline says they should be?

This is why accurate, current baselines matter. Assessors will check actual devices. If reality doesn’t match documentation, you have a problem.

Evidence of Maintenance

Assessors wanted evidence that inventories and baselines are maintained over time. System logs showing device additions and removals. Change management records for baseline updates. Annual review documentation.

Static documents created for the assessment don’t satisfy this. You need ongoing processes with audit trails.

Practical Tips from the Interview

Blow Away All Partitions When Reimaging

Steve shared an important lesson from a previous incident. Malware sometimes copies itself to recovery partitions that vendor-imaged systems include.

You might completely wipe and reimage a system, but if the malware copied itself to the Dell or HP recovery partition, it comes back after reimaging.

The solution: don’t just reimage. Delete all existing partitions first. Start completely fresh. This prevents malware from surviving in hidden partitions.

Remove Bloatware and Close Unnecessary Ports

Vendor-imaged systems come with extra software you don’t need. Trial applications, vendor utilities, promotional content.

Your baseline process should remove this bloatware. It should also close ports you don’t use and disable services you don’t need.

Assessors may accept a process that starts with vendor images and applies documented hardening. But they might note this as an opportunity for improvement compared to building from clean images.

Understand the Minimum Bar

Steve emphasized reading assessment objectives literally. Assessors should verify what the objectives say, not more.

Some organizations over-engineer their baselines, creating elaborate systems when simpler approaches would pass. Others assume requirements are more lenient than written.

The assessment objectives define the bar. Understand exactly what they say. Meet that standard. Don’t assume you need to exceed it, but don’t assume you can fall short either.

Baselines Cover Functionality and Security

Baselines aren’t just about security configurations. They’re about ensuring every system of a given type is configured identically.

This helps with troubleshooting, support, and management. When you know every Windows 10 laptop is configured the same way, you can diagnose problems faster. You can provide consistent support. You can manage systems efficiently.

Security configurations are part of baselines. But so are functional configurations that make systems work correctly and consistently.

Common Mistakes with System Baselining

Inventory Doesn’t Match Scoping Diagram

This is the most immediate problem assessors will catch. If your inventory and diagram don’t align, you’ll need to explain why.

Before your scoping call, compare these documents. Make sure every device appears in both places with consistent information.

Missing Device Categorization

Having a detailed inventory isn’t enough. Each device needs a category from the CMMC scoping guide. CUI Asset, Security Protection Asset, Contractor Risk Managed Asset, or Specialized Asset.

Assessors expect this categorization. Organizations that haven’t done it often think they’re ready when they’re not.

Baselines That Don’t Match Reality

Creating baseline documentation is one thing. Ensuring actual devices match that documentation is another.

Assessors randomly verify devices. If your laptops aren’t actually configured to your documented baseline, that’s a finding.

Review your baselines against actual devices before assessment. Fix any discrepancies.

No Evidence of Ongoing Maintenance

Static documents suggest baselines and inventories were created for the assessment rather than being part of normal operations.

You need evidence of ongoing maintenance. Change management records. System logs. Annual review documentation. Audit trails showing additions and removals over time.

Build these processes before assessment. Let them run long enough to generate meaningful evidence.

Getting Your Baseline Documentation Right

System baselining is one of the more complex CMMC practices. The assessment objectives cover a lot of ground. Getting it right requires understanding both what’s required and what assessors actually verify.

Download the free KCD brochure at https://www.kieri.com/services/cmmc-compliance-documentation/ for documentation templates that address baseline and inventory requirements correctly.

Schedule a consultation to discuss your specific baselining questions with Certified CMMC Assessors.

Watch our full interview to hear exactly what worked for SENTAR’s successful DOD assessment.


Kieri Solutions is one of 54 authorized C3PAOs in the United States. Our team of Certified CMMC Assessors helps defense contractors understand exactly what evidence assessors expect for complex practices like system baselining.

Need CMMC Level 2 Assessment Services? Visit https://www.kieri.com/services/cmmc-assessment/

Building a Compliant Network? Check out the Kieri Reference Architecture for turnkey Microsoft 365 GCC-High solutions.

Cybersecurity data analysis supporting CMMC Level 2 audit preparation for defense contractors

Talk to a CMMC Expert

Tell us where you are with CMMC and we’ll map out the next steps for your team.

Don't miss these

Is Your Security Plan Telling the Truth?
Server room corridor lined with racks in a data center covered by a System Security Plan
Is Your Security Plan Telling the Truth?
What Does the Government Actually Require of You Today?
A network of yellow lines connecting round nodes against a dark background.
What Does the Government Actually Require of You Today?
NIST SP 800-171 Rev 3, What Changed and What It Means for Your CMMC Timeline
Man at a desk in a dark office reading text on a computer monitor, NIST SP 800-171 Rev 3
NIST SP 800-171 Rev 3, What Changed and What It Means for Your CMMC Timeline
CMMC Backup Requirements and The Myths Worth Ignoring
Server backup drives in a dark data center supporting CMMC backup requirements for a defense contractor
CMMC Backup Requirements and The Myths Worth Ignoring
How to Prepare for a DIBCAC High Assessment
Analyst reviewing evidence on dark dual monitors while preparing for a DIBCAC High assessment
How to Prepare for a DIBCAC High Assessment
Out of Scope Assets - What the Final Rule Actually Changed
Abstract data cityscape tied to out of scope assets in a CMMC assessment by Kieri Solutions
Out of Scope Assets - What the Final Rule Actually Changed
CMMC Proposed Rule Analysis - What Defense Contractors Need to Know
Dark cybersecurity image with glowing data illustrating CMMC final rule compliance for defense contractors
CMMC Proposed Rule Analysis - What Defense Contractors Need to Know
CMMC Phase 2 Suspended and What Defense Contractors Need to Know
Analyst reviewing code while working toward CMMC and NIST 800-171 compliance
CMMC Phase 2 Suspended and What Defense Contractors Need to Know
CUI Assets - What Assessors Actually Evaluate
Abstract network of nodes tied to CUI assets and CMMC scope assessed by Kieri Solutions
CUI Assets - What Assessors Actually Evaluate
Do I Even Have CUI? Understanding What You Need to Protect
Abstract data network tied to finding CUI on a defense contractor network with Kieri
Do I Even Have CUI? Understanding What You Need to Protect
Why the DoD Wants Security Protection Data Protected Like CUI
Abstract data network tied to security protection data and CMMC scope assessed by Kieri
Why the DoD Wants Security Protection Data Protected Like CUI
Why Your CMMC Gap Analysis Might Be Worthless - 110 Practices vs 320 Assessment Objectives
Cybersecurity professional conducting CMMC gap analysis for a defense contracting organization
Why Your CMMC Gap Analysis Might Be Worthless - 110 Practices vs 320 Assessment Objectives
Building a CMMC Level 2 Compliant Network You Can Actually Manage
Network architecture visualization for a CMMC Level 2 reference architecture built on Microsoft 365 GCC High
Building a CMMC Level 2 Compliant Network You Can Actually Manage
Why Most CMMC Documentation Fails and How to Fix It
CMMC compliance documentation policies and procedures
Why Most CMMC Documentation Fails and How to Fix It
What Passed a DOD Assessment for System Baselining and Inventories
CMMC system inventory and baseline configuration monitoring dashboard
What Passed a DOD Assessment for System Baselining and Inventories
How to Implement Mobile Code Requirements for CMMC Level 2
CMMC mobile code security controls and technical implementation
How to Implement Mobile Code Requirements for CMMC Level 2
What Does "Monitor" Actually Mean in CMMC Requirements?
CMMC monitoring requirements - access control and password security verification
What Does "Monitor" Actually Mean in CMMC Requirements?
The Version 20 Problem and How to Avoid It
CMMC compliance documentation sequence - cybersecurity program management
The Version 20 Problem and How to Avoid It
Build Your Own CMMC Level 2 Compliant Environment with the Kieri Reference Architecture
CMMC Level 2 compliant environment security controls and access management
Build Your Own CMMC Level 2 Compliant Environment with the Kieri Reference Architecture
Inside the KCD - What Makes This Documentation Different
CMMC compliance documentation templates digital security
Inside the KCD - What Makes This Documentation Different
How the Kieri Compliance Documentation and Reference Architecture Work Together
Kieri Compliance Documentation and Reference Architecture working together for CMMC Level 2 compliance
How the Kieri Compliance Documentation and Reference Architecture Work Together
What's Actually Inside the Kieri Compliance Documentation? A Complete Walkthrough
CMMC compliance documentation and reference architecture security controls - fingerprint scanning and access management
What's Actually Inside the Kieri Compliance Documentation? A Complete Walkthrough
CMMC Assessments by Kieri Solutions
Global cybersecurity compliance support for defense contractors under DFARS
CMMC Assessments by Kieri Solutions
CMMC Education: User vs Network Session Termination
Secure IT infrastructure design supporting CMMC Level 2 compliance for defense contractors
CMMC Education: User vs Network Session Termination
CMMC Proposed Rule has been released! 
Cybersecurity threat - CMMC compliance
CMMC Proposed Rule has been released! 
Interested in the Kieri Compliance Documentation?
Secure data transmission within CMMC compliant network architecture
Interested in the Kieri Compliance Documentation?
How to fix Outlook missing Friday January 13 2023
Interconnected defense contractor networks requiring CMMC Level 2 cybersecurity certification
How to fix Outlook missing Friday January 13 2023
C3PAO Meeting - July 26, 2021 12-1 pm EDT
C3PAO Meeting - July 26, 2021 12-1 pm EDT
NIST SP 800-171 DoD Self Assessment Services
DFARS 252.204-7012 and NIST SP 800-171 requirements
NIST SP 800-171 DoD Self Assessment Services
vSphere Health detected new issues in your environment 6.7
vcenter 6.7 alarm displays vsphere health detected new issue
vSphere Health detected new issues in your environment 6.7
vCenter Health Warning: External Platform Services Controller
vCenter Health Warning: External Platform Services Controller
Synology storage latency and disconnects on VMware
Synology storage latency and disconnects on VMware
Windows Stuck in Recovery Mode Datto driver signing
Windows Stuck in Recovery Mode Datto driver signing
Office 365 MFA App Password Missing Fix
Office 365 MFA App Password Missing Fix
Microsoft Teams Conference Calls & Dial-In Numbers
Microsoft Teams Conference Calls & Dial-In Numbers
C: Drive Full Exchange
C: Drive Full Exchange
Exchange server very slow, services and network blank
Exchange server very slow, services and network blank
Exchange 2016 DAG - 3 servers 2 sites
Diagram showing mailbox servers with active and passive databases. Each database is only active on one server.
Exchange 2016 DAG - 3 servers 2 sites
Netapp 3rd-party CA certificates expiring DeutscheTelekomRootCA2
Kieri Solutions partnering with defense contractors to achieve CMMC Level 2 certification
Netapp 3rd-party CA certificates expiring DeutscheTelekomRootCA2
vCenter 6.7 Memory Exhaustion and vSphere health (Tiny)
warning vsphere health detected new issue memory exhaustion 6.7 vcenter
vCenter 6.7 Memory Exhaustion and vSphere health (Tiny)
Step by Step: Upgrade vCenter VCSA 6.0 (or 6.5) to 6.7
Step by Step: Upgrade vCenter VCSA 6.0 (or 6.5) to 6.7
How to prepare for a DoD CMMC audit and certification
cybersecurity CMMC DoD NIST 800-171 compliance nist 800-53
How to prepare for a DoD CMMC audit and certification
Fix Expired vCenter Root Password (6.5 & 6.7)
Fix Expired vCenter Root Password (6.5 & 6.7)
How to rename Windows Server 2016 Domain Controller
How to rename Windows Server 2016 Domain Controller
Runtime Error Adding Host in VMware vCenter & ESXi
add host a general runtime error occurred vcenter 6.5 6.7
Runtime Error Adding Host in VMware vCenter & ESXi
How to fix Netapp expired self-signed certificate by creating a new one
netapp certificate expired install site cant be reached
How to fix Netapp expired self-signed certificate by creating a new one
How to register a warranty or service agreement on HPE website
hpe hp register account SAR ID service agreement warranty how accept
How to register a warranty or service agreement on HPE website
How to install vCenter 6.7 (and 6.0 and 6.5) with no DNS, only IP address
vcenter ip address no dns
How to install vCenter 6.7 (and 6.0 and 6.5) with no DNS, only IP address
How to disable continuous scrolling on Kindle - turn on page flip
disable continuous scrolling option displays
How to disable continuous scrolling on Kindle - turn on page flip
17hats how to export or convert to Excel CSV TAB XLS workbook
17hats export convert iff to csv tab excel
17hats how to export or convert to Excel CSV TAB XLS workbook
How to fix "Cannot apply changes to this Internet Shortcut" Windows
cannot apply changes to this internet shortcut 2016 2019
How to fix "Cannot apply changes to this Internet Shortcut" Windows
Best Free Computer Incident Response Templates and Scenarios
best free incident response reporting form cybersecurity IT
Best Free Computer Incident Response Templates and Scenarios
Firmware & System Patching Services | DC & Maryland
poweredge server raid reconfigure add disks 1 5
Firmware & System Patching Services | DC & Maryland
Network hardening near Baltimore MD, Frederick, Rockville, Gaithersburg and DC
Best practice network segmentation and hardening prevents pivot attacks NIST
Network hardening near Baltimore MD, Frederick, Rockville, Gaithersburg and DC
VMware vSphere ESX and vCenter Upgrade 5.5 to 6.0 or 6.5 or 6.7 best practices
Best practices and how to install esxi vsphere vcenter vmware and troubleshooting problems during the migration
VMware vSphere ESX and vCenter Upgrade 5.5 to 6.0 or 6.5 or 6.7 best practices
Disaster Recovery & Business Continuity in DC & Maryland
disaster recovery drp bcp hipaa frederick columbia gaithersburg baltimore rockville
Disaster Recovery & Business Continuity in DC & Maryland
VMWare and Netapp consultant in DC, Baltimore, Columbia, Frederick, and Rockville MD
installation services netapp disk shelf baltimore columbia rockville
VMWare and Netapp consultant in DC, Baltimore, Columbia, Frederick, and Rockville MD
SBDC - Intro to GDPR training - Frederick MD
intro gdpr overall sbdc fitci frederick
SBDC - Intro to GDPR training - Frederick MD
GDPR and Human Resources
cybersecurity cyber security hardening compliance firewall design frederick
GDPR and Human Resources
No, your computer isn't slow.
why slow computer pc repair frederick damascus mt airy md
No, your computer isn't slow.
Why you should consider a credit freeze - EquiFax hack
credit freeze equifax hack how to breach innovis
Why you should consider a credit freeze - EquiFax hack
Virtual Servers, Storage, and SAN - Why your servers are slow
cybersecurity compliance design consulting engineering
Virtual Servers, Storage, and SAN - Why your servers are slow
How to un-freeze your laptop like a pro
pc or computer problem repair damascus lisbon mt airy laytonsville
How to un-freeze your laptop like a pro
Upgrade your IT Services for the New Year
managed services it department outsource company frederick columbia germantown gaithersburg
Upgrade your IT Services for the New Year
Dell PowerEdge R730 PERC RAID online reconfiguration
poweredge server raid reconfigure add disks 1 5
Dell PowerEdge R730 PERC RAID online reconfiguration
Dreamhost HTTP error Wordpress media upload and library
dreamhost http error picture disappear upload shared wordpress
Dreamhost HTTP error Wordpress media upload and library
FortiAnalyzer Configuration problems after initial deploy
FortiAnalyzer 5.4 Storage Quota Limits for ADOM root
FortiAnalyzer Configuration problems after initial deploy
FortiAnalyzer Report: User Web Browsing by Category
fortianalyzer custom report users by category who is browsing web goofing off
FortiAnalyzer Report: User Web Browsing by Category
GDPR Consulting - What you need to know
cybersecurity CMMC DoD NIST 800-171 compliance nist 800-53
GDPR Consulting - What you need to know
The #1 Computer Security Threat Just Evolved - RCE Worm
cybersecurity cyber security compliance firewall frederick md
The #1 Computer Security Threat Just Evolved - RCE Worm
Fix vSphere & vCenter Datastore Size Reverting
security design cybersecurity consulting services compliance
Fix vSphere & vCenter Datastore Size Reverting
HP DL360p g8 ESXi 5.5 to 6.5 upgrade conflicting_vibs_error
conflicting vibs error vsphere upgrade metadata consultant vmware
HP DL360p g8 ESXi 5.5 to 6.5 upgrade conflicting_vibs_error
Is your IT person holding the network hostage?
Server Upgrade Cybersecurity Consultant SAN Netapp Frederick
Is your IT person holding the network hostage?
4 Hiring Mistakes When Choosing an IT Company
mistakes when hire IT consultant MSP managed service provider computer support outsourcing
4 Hiring Mistakes When Choosing an IT Company
What you should know about Cloud Computing and Office 365
cloud IT department migration Office 365 Frederick Baltimore Columbia MD
What you should know about Cloud Computing and Office 365
Can You Make Our Nation Safe from Hackers?
Can You Make Our Nation Safe from Hackers?
The Ultimate Way to Protect Against Computer Theft
Kieri Solutions site icon
The Ultimate Way to Protect Against Computer Theft
Small / medium business security concerns
managed services it department outsource company frederick columbia germantown gaithersburg
Small / medium business security concerns
Approaches to security policy
cybersecurity cyber security hardening compliance firewall design frederick
Approaches to security policy

Article

Is Your Security Plan Telling the Truth?
Server room corridor lined with racks in a data center covered by a System Security Plan

Article

What Does the Government Actually Require of You Today?
A network of yellow lines connecting round nodes against a dark background.

Article

NIST SP 800-171 Rev 3, What Changed and What It Means for Your CMMC Timeline
Man at a desk in a dark office reading text on a computer monitor, NIST SP 800-171 Rev 3

No one wants to start from blank templates.

No one wants to start from
blank templates.

Stop starting from blank templates. Get documentation proven through actual CMMC Level 2 assessment.