CMMC 1.0 Practice SC.1.176 Requirement:

Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

CMMC 1.0 SC.1.176 Requirement Explanation:

The goal of a DMZ is to add an extra layer of security to your local area network.

Example CMMC 1.0 SC.1.176 Implementation:

Do not place servers or other IT systems that need to be accessible from the internet on to your local network. Instead, set up a "demilitarized zone" (DMZ). Place your systems that need to be accessed over the internet (e.g. web server) into your DMZ. Alternatively, you may move your systems that need to be publicly accessible to the cloud. Because you don't host anything that needs to be publicly accessible you would not need a DMZ.

CMMC 1.0 SC.1.176 Scenario(s):

- Scenario 1:

Alice has built a server that will host her company's website. Instead of insecurely placing the webserver on her internal network she creates a DMZ and places the webserver in it. The web server is now accessible from the internet and is separate from her company network. If a hacker takes over the webserver he gets trapped in the DMZ and can't access the internal network.

- Scenario 2:

Alice needs to find a solution to host her company's new website. Instead of setting up her own web server and DMZ, she decides to use a web hosting company. As a result, does she avoids having to set up a DMZ.
 

Discover Our NIST SP 800-171 & CMMC 2.0 Solutions:

 /assets/images/app/complaince_accelerator.gif

Compliance Accelerator

Power through compliance. Meet and maintain your NIST SP 800-171 & CMMC 2.0 compliance requirements.
 /assets/images/app/quantum_accelerator.gif

Quantum Assessor

Transform your business. Create new revenue streams and provide scalability for your NIST SP 800-171 and CMMC 2.0 services.
 /assets/images/app/supply_chain_verifier.gif

Supply Chain Verifier

Trust is everything. Verify, monitor, and support subcontactor compliance.