Government Contractor
US
Ironfield Defense Systems
Mid-sized defense contractor with cleared personnel, handling Controlled Unclassified Information (CUI) and some ITAR data.
Systems
- On-prem enclave for CUI
- Air-gapped dev environment
- External collaboration tool (GovCloud)
- Classified network (read-only data)
Regulatory exposure
- CMMC 2.0 L2
- DFARS 7012
- ITAR
- Export Administration Regulations
Relevant frameworks
- NIST SP 800-171
- CMMC 2.0
- NIST CSF
Top risks
- CUI exfiltration via removable media
- Insider with cleared access
- Foreign national contact
- Subcontractor flow-down gaps
Control priorities
- Media control
- Personnel security
- Audit logging on the enclave
- Subcontractor flow-down
Audit concerns
- SSP currency
- POA&M closure evidence
- Annual security training records
Your task
You are 90 days from a CMMC L2 assessment. Write the readiness plan and the briefing for the COO on what is at risk if any of the top three POA&M items slip.
Vendor risk
Long subcontractor chain; flow-down clauses variance across DIB partners.
BCP/DR
Hot backup for the enclave only; classified work continuity unaddressed.