CMMC 1.0 Practice SI.3.218 Requirement:

Employ spam protection mechanisms at information system access entry and exit points.

CMMC 1.0 SI.3.218 Requirement Explanation:

Spam emails are often malicious. Blocking spam reduces the chance of your users receiving malicious emails.

Example CMMC 1.0 SI.3.218 Implementation:

Implement spam filtering for your email services. Restrict spam from coming into your organization. Restrict your company's email services form being used to send spam (should be mentioned in your acceptable use agreement). Many cloud based email services such as Office 365 Exchange and Gmail have spam filtering features by default. These can be modified to increase their effectiveness. If the spam filters miss any spam email, you should manually add them to the filter.

CMMC 1.0 SI.3.218 Scenario(s):

- Scenario 1:

Your company uses Exchange with Office 365 for its email services. You log into the Exchange admin panel to ensure that spam protection is on. As you discover spam emails that were missed by the filter you manually add them to spam filter.

