Event banner
Microsoft Government CMMC AMA
Event Ended
Tuesday, Apr 12, 2022, 10:30 AM PDTEvent details
We want to hear from our customers and answer their questions around how we can help them achieve CMMC compliance with your Microsoft Azure and Microsoft 365 subscriptions. We will be hosting an "Ask...
Sarah_Gilbert
Updated Apr 12, 2022
Joeatheist
Apr 12, 2022Copper Contributor
Thanks for holding this/these discussions! My company does not use any cloud services. It is a preferential choice made by our CEO. We are currently using Office 2021 Pro. Does this meet the requirements for NIST 800-171/CMMC 2.0? We also do not allow any remote connections, we all work in the office, not from home. Not much need for cloud services as we can store everything on our in-house physical server.
Paul Meacham
Microsoft
Apr 13, 2022You certainly can be compliant on-premises, no argument about that. Cloud services do help customers get a leg up on compliance as we offer a breadth of tools and services that allow customers to meet requirements for collaboration, security, compliance, device management, hardware, compute, memory, storage, development, etc. The reason folks are using the cloud is because they may not have the technical skill sets or the capital investment and time required to manage hardware and software and networking. For large companies that do have the expertise and capital their work force is looking for modern tools to compete in the market as well as the ability to attract and retain new talent who want to work from anywhere with any device (coauthoring, text, chat, calling, email, calling, meeting join, whiteboarding, @mentioning, etc.). While you may say that you do not have much need for cloud services, I would point out that you have limited organizational resilience (BC/DR plan) with your servers in-house at a single location. You also cannot leverage cloud economies of scale to free up cash flow and transfer CAPEX to OPEX thereby gaining benefit from a positive net present value. Moreover, you are highly vulnerable to risks inside and outside the org without having advanced machine learning to reason over your behavioral analytics, logs, devices and files to expose risks and take remediating steps. Lastly, you are doing everything all on your own, there is no cloud service provider to help with shared scope of responsibility, support escalations or professional services. So yes, you can be compliant on-prem, but it may not be a good idea given the benefits of the cloud and the fact that that is the direction that every technology company is going.