Government Contractor
US

Ironfield Defense Systems

Mid-sized defense contractor with cleared personnel, handling Controlled Unclassified Information (CUI) and some ITAR data.

Systems
  • On-prem enclave for CUI
  • Air-gapped dev environment
  • External collaboration tool (GovCloud)
  • Classified network (read-only data)
Regulatory exposure
  • CMMC 2.0 L2
  • DFARS 7012
  • ITAR
  • Export Administration Regulations
Relevant frameworks
  • NIST SP 800-171
  • CMMC 2.0
  • NIST CSF
Top risks
  • CUI exfiltration via removable media
  • Insider with cleared access
  • Foreign national contact
  • Subcontractor flow-down gaps
Control priorities
  • Media control
  • Personnel security
  • Audit logging on the enclave
  • Subcontractor flow-down
Audit concerns
  • SSP currency
  • POA&M closure evidence
  • Annual security training records
Your task
You are 90 days from a CMMC L2 assessment. Write the readiness plan and the briefing for the COO on what is at risk if any of the top three POA&M items slip.
Vendor risk
Long subcontractor chain; flow-down clauses variance across DIB partners.
BCP/DR
Hot backup for the enclave only; classified work continuity unaddressed.