image

Imprimis Integrated Services Framework

Government contractors are currently operating under strict federal mandates—primarily DFARS 252.204-7012 and the evolving Cybersecurity Maturity Model Certification (CMMC), which require the robust protection of Controlled Unclassified Information (CUI). To maintain eligibility for Department of Defense (DoD) contracts, firms must move beyond basic self-attestation toward verifiable compliance with NIST SP 800-171 standards. They need to complete their Level 2 CMMC Assessment and achieve Certification, perform remediation tasks to their IT and cloud-based networks to securely handle CUI, as well as be potentially audited by a third party assessor (C3PAO) depending on the requirements of their government DFARS contracts).

The Imprimis 3-Phase|Multistage CMMC Assessment, Remediation, and Sustainment Model

Over the last 10 years Imprimis has been actively engaged in the Cybersecurity Assessment and Compliance marketplace. During this time we have conducted many assessments using our i2ACT Assessment and Compliance Software Tool, designed and remediated a wide variety of complex IT and networking systems for our customers, developed all required compliance documentation, and established sustainable network security programs and training. This real-life, practical experience has allowed us to develop and fine-tune a number of cybersecurity best-practices, processes, and procedures that not only streamline the overall CMMC certification process but put into place a resilient and responsive security awareness ecosystem for our clients – at a reasonable price.


An effective cybersecurity program requires not only a technical overhaul of information systems but also the creation of rigorous documentation, to include Policies/Procedures, Security Plans, and Incident Response Plans just to mention a few. For many contractors, the internal overhead of managing these complex, and oft times shifting regulations, while maintaining core operations creates a significant risk of non-compliance and potential loss of contract eligibility. The i2 "3-Phase | Multistage CMMC Assessment, Remediation, and Sustainment Model" shown below has been practiced and has survived the rigors of C3PAO Certification Assessments and has proven to be a repeatable, and more importantly... a budget-friendly solution for our customers.

The Imprimis Approach

To address these unique NIST and CMMC requirements, Imprimis deploys a unique “Integrated Services Framework" developed by the company, that is supported by a series of 6 Logical Procedure Steps. These steps can be implemented rapidly with assistance from Imprimis, or you can work at your own pace with a self-assessment track supported by our i2ACT Software Tool. Our solutions and services are primarily designed for DoD contractors and their supply chains but can be easily adapted to commercial entities wishing to elevate their level of "Cybersecurity Readiness".

Below are summary details of each of the 6-Logical Procedure Steps:

1. Planning

Imprimis engages the client in a series of Initial Planning sequences that begins with an initial Readiness Report and Gap Analysis using our IC2E Fundamentals to ascertain an initial "Cybersecurity Situational Awareness" status for the client.

Read More

2. Assessment

Following the initial planning, we move the client into an Assessment Phase that includes a detailed review of a client’s overall NIST|CMMC cybersecurity posture. We use our i2ACT Software Tool to assess the NIST|CMMC requirements and objectives and input the current compliance status… met, not met, or remediation needed. All associated reports are generated in the i2ACT tool.

Read More

3. Remediation

After the initial assessment, the Remediation Phase begins where all required physical, procedural and logical security requirements are addressed to include networking infrastructure, hardware, software, documentation, and Government Community Cloud migrations. Sustaining security protocols are also established during the remediation phase.

Read More

4. Education

In parallel, we use our ITSG (Information Technology Steering Group) model to provide a stakeholder governance and management authority, as well as encouraging our clients to utilize our built-in NIST and CMMC Cybersecurity Education Tools in the i2ACT Software tool.

Read More

5. Documentation

During the remediation phase, our complete package of compliance documentation can be selected (i2ExpressDocs) for purchase and Imprimis will populate them with client-specific data. This documentation package contains all relevant Policies and Procedures, SSP, IRP, CUI Management Plan, Configuration Management Plan and CMMC related/required catalogs and matrices.

Read More

6. Sustainment

Many of the required sustainment activities will be selected and activated during the remediation phase but a few may not be implemented until remediation is complete. These services will include a disciplined Remote Monitoring and End-Point Protection Program (for Servers, Workstations, Laptops, IoT devices, etc.), as well as Vulnerability Scanning, Event Logging services and Training.

Read More

Imprimis Process Workflows

To properly assess, remediate and sustain an "Organization Seeking Certification" (OSC) for any Department of Defense (DoD) contractor, subcontractor, or vendor that handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) contractors must undergo a complete assessment to verify compliance, make changes to their networking and security postures through expert remediation, as well as put in place long term sustainment solutions to maintain compliance in the future. To meet these objectives, Imprimis has developed a specialized set of  "8 Process Workflows". This process helps establish a comprehensive baseline program management methodology that is complemented by expert consultative support, applied technology, and IT network engineering solutions. Use of the i2ACT software tool enables capture of detailed artifacts and evidence and supports full documentation management.

The 8 Process Workflows


  • image

    IC2E Fundamentals

    Imprimis Cybersecurity Compliance Essentials

    Every robust security program stands on four pillars – physical, procedural, logical, and transformational. Yet many organizations stop at door locks and firewalls, leaving the human and process layers fragmented, or have not addressed cybersecurity at all.

    (IC2E™) transcends this piecemeal approach by uniting all four dimensions into a single, streamlined framework and is designed for companies just developing their cybersecurity program or for companies not in the defense sector.


  • image

    i2CyberStart

    Commercial Entities - Initial Gap Analysis and Network Design/Implementation

    The i2CyberStart program has been designed for commercial businesses not needing to be NIST 800-171 or CMMC compliant.

    This program is targeted at small to medium sized businesses, however it dynamically scales up for use with larger commercial enterprises as well.

    The program utilizes best practices accepted throughout the industry by selecting specific requirements contained in NIST 800-171 and adapting them to the commercial environment. This ensures that the basic requirements for a minimum level of security are met and allows companies to build on that security as time moves on and as their operational and security requirements change.


  • image

    i2ACT

    Assessment and Compliance Software Tool

    1. On-premises software solution designed to support structured CMMC Level 1 & 2 | NIST 800-171 assessments
    2. Built primarily for organizations handling both Federal Contract Information (FCI) and Controlled Unclassified Information (CUI)
    3. Can easily be adopted for use by commercial entities
    4. Combines the benefits of an assessment with a Document and Evidence Management System and comprehensive Reference Guides
    5. Offers standard, or Imprimis developed, remediation actions plus references, standards and auditor guides at any step in the assessment process
    6. Contains many report options to include conformity statements, assessor/auditor notes, remediation actions, and evidence and artifacts at the Control level


  • image

    i2Assess

    Comprehensive CMMC Level 1 & 2 | NIST 800-171 Assessments

    During the i2Assess phase, an initial assessment will be performed using the i2ACT Assessment and Compliance Software Tool to the desired baseline.

    A Quick Start Phase I Package is available to start the assessment and compliance process that is affordable, repeatable and gets compliance moving quickly and most clients select this option.

    The Package consists of:

    1. An initial assessment
    2. A network architecture review and design
    3. SPRS scoring
    4. Draft System Security Plan
    5. Network Drawings and Documentation
    6. Implement the Initial IT Steering Group Meeting & Process
    7. Draft Plan of Action and Milestones (POA&M)

    Identification of the specific remediation actions and documents required for compliance occurs during this time.


  • image

    i2Portal

    Secure Customer Portal

    Imprimis has deployed a secure customer-centric, online communication and collaboration space called "i2Portal".

    It's a unique online support solution that allows Imprimis to tailor client communications as well as provide direct customer support. Clients will be able to directly access the status of their projects, retrieve files and submit detailed support tickets.

    The client portal is secure and each Imprimis client will only see their data, documentation and support tickets. Each client will be required to have their own login credentials, and 2-factor authentication will be implemented.


  • image

    i2CyberBuild

    Network and System Remediation

    During i2CyberBuild, Imprimis provides services to support the remediation process to include:

    1. Physical Security to protect facilities, systems, and materials
    2. Government Community Cloud High (GCCH) tenant creation and setup
    3. Domain Determination/Acquisition & Setup
    4. Local Network & Infrastructure
    5. Encryption
    6. Backup and Recovery
    7. Documentation/Catalogs
    8. ITSG Management Procedures

    This process is typically directed by Imprimis staff at the client’s pace with the client participating as much or as little as they choose.

    Several of the Sustainment requirements may be initiated during the remediation phase.


  • image

    i2ExpressDoc Packages

    Cybersecurity Documentation

    Based upon the mandated DoD CMMC | NIST 800-171 requirements, Imprimis has developed a Document Express Package specifically designed to meet compliance and stand up to a C3PAO assessment.

    The documents provided can easily be edited to account for client differences and requirements. The documents can be purchased individually or as the Express Package at a 30% discount for all.

    Documents Offered:

    1. Policies (20) and Procedures (46)
    2. System Security Plan
    3. Incident Response Plan
    4. CUI Management Plan
    5. Configuration Management Plan
    6. Catalogs such as ODP’s, Access & Authorization Matrix, Document Traceability Matrix, Client Risk Registry


  • image

    i2Sustain

    Security Stack Sustainment

    Once an organization achieves full compliance with a CMMC | NIST mandate, they need to commit to ongoing efforts to remain in compliance – or sustain compliance.

    Imprimis provides a full suite of supporting services called i2Sustain and includes endpoint protection, vulnerability monitoring and scanning, multi-factor authentication, backups, SIEM, SASE and training.

    Many of these services will be implemented during the remediation phase and are divided into two groups:

    1. Continuous Sustainment Services
    2. On-Demand Services


How to Make our Solutions Work for You

Imprimis recognizes that every business is unique. Even businesses of the same size in the same business are very different and have different needs, policies, cultures and approaches to their business. They also have different capability sets where some may have experienced IT and information security personnel, others outsource their IT and some very small companies may have no IT support at all. Imprimis can adapt to the needs of our clients in one or a combination of the following ways:

Working With Imprimis

TEAM UP
Imprimis can work with your company as a ‘Team’ – this approach is useful when a client has either full-time IT support or is knowledgeable in the DoD compliance requirements.  In this scenario, the client might select our Fixed price Phase I Package which would culminate in remediation, or Imprimis would first use the i2ACT Software tool for the initial assessment and then move methodically through the rest of the Phase I tasks to meet the SPRS requirements and completion of the planning phase. 

The client then decides on an approach to remediation implementation: use internal staff, Imprimis services, another third party, or any combination that fits their needs. Imprimis will provide as much or as little remediation support as the client wants and needs.  

The compliance documentation would be completed during the remediation phase, again, either by selecting the i2ExpressDoc Package or by the client utilizing or preparing their own documents.   

Once compliance is achieved, Imprimis is available to provide the sustainment support or a security stack specifically designed for the client, if desired.  Sustainment activities typically include endpoint management, multi-factor authentication, vulnerability scanning, monitoring, training, backups, incident response exercises, and ongoing CISO advisory. 

HAVE IT DONE
Another option is for Imprimis to take on all tasks associated with cybersecurity compliance with the client observing,  learning, and approving as the process unfolds. This is particularly helpful for small or intermediate clients desiring to reach full, auditable compliance as soon as possible.

Of course, Imprimis can always provide hourly consultation services whenever required by our clients. This support can apply to strategic planning or technology, and cybersecurity advisory. Considering cybersecurity requirements during the acquisition of new technology is always recommended to avoid buying technology that does not support the client’s overall cybersecurity plan.

Once an organization achieves full compliance with any standard or regulation, they need to commit to remaining in compliance – or sustaining compliance. Imprimis provides a full suite of on demand supporting services to include continuous monitoring of the system, vulnerability scans, CISO (Chief Information Security Officer) support and training. Additional services include incident response, forensic analysis, annual reassessments and advisory services.
.

Contact US

Contact Imprimis at 719-463-0333 or visit https://www.imprimis-inc.com/contact-us  to take the first step toward true cybersecurity resilience.