FNI’s CMMC Hero’s Journey
To our amazement, we have found the route to achieving CMMC is not unlike the Hero’s Journey. At times it is no doubt arduous, and many at first refuse the call. FNI is here to bring clarity to CMMC’s confusion.
Follow FNI on your CMMC journey to success
The moment comes when you learn that FCI/CUI must be protected following DoD rules.
There’s resistance, protecting CUI changes culture, the cost is high, denial comes by thinking the requirements won’t affect the company, or that inaction leads to little or no consequences.
Ultimately, you realize to gain new DoD business, and not lose existing DoD business, you must commit to CMMC compliance.
You find the process is very difficult, and you must have outside expertise to assist you.
Mythic Hero’s Journey
Call to Adventure:
The hero faces a problem or incident solved only by quest or adventure.
Refusal of the Call:
Initially, the hero may hesitate or refuse the call to adventure due to fear or other reasons.
Meeting the Mentor:
The hero encounters a mentor who provides guidance, advice, or magical tools, in preparation of the journey and along the way.
You determine the CMMC Timeline / the amount of time you expect the company to achieve CMMC compliance (6 – 18 months).
FNI meets with you, providing guidance as your Mentor.
FNI helps you establish where your company is regarding CMMC (e.g. Just starting, partially implemented, close to ready), and helps you chart the course to your success!
Crossing the Threshold:
The hero takes stock of himself then leaves the ordinary world to enter a new, unfamiliar world.
- You provide access to FNI.
- Key Stakeholders are available for interviews.
- You are available for discussion.
- FNI Interviews Key Stakeholders (Data, Processes).
- Documents CUI Data Flow.
- Defines Logical and Physical Isolation.
- Catalogs External Service Providers (MSPs, etc.).
- FNI Helps Scope CMMC Boundary.
Tests, Allies, and Adversaries:
The hero faces challenges, makes allies, and confronts adversaries.
- Previous participants are involved to an even greater degree than they were before.
- Greater collaboration between the company and FNI is established to accomplish your CMMC Roadmap: Gap Analysis.
FNI assists in setting up training to help your organization understand Contract/ Data Requirements / information.
- FNI Provides Project Management.
- Customized POA&M.
- Hardware/Software Recommendations.
- Policy and Procedure Review and Updating.
- Ultimately, Gaps are Filled.
- FNI undertakes In-Depth Interviews, Examinations, and Tests of your environment.
- FNI Grades Policies, Procedures and Plans against NIST 800-171 / CMMC controls.
- Produces accurate SPRS Score.
- Generates Template SSP with met controls.
Ordeal:
The hero faces a major challenge or crisis, often confronting their greatest fear.
- FNI’s MSSP Management and Technicians are Hands-on.
- Overseeing and Implementing Data Migration.
- Procuring, Configuring, and Installing Hardware and Software.
- These efforts help ensure your solutions meet CMMC compliance.
- FNI provides a Detailed Walkthrough of the Assessment Process.
- Assists with choosing a C3PAO that has experience similar to your environment.
FNI is in the Room with you during Assessment.
Return with the Elixir:
The hero returns to the ordinary world with a reward or newfound wisdom that benefits himself and others.
The Hero’s Journey was first introduced by Joseph Campbell in his 1949 book The Hero with a Thousand Faces
Does the Hero’s Journey resonate with you?