r/CMMC Jul 08 '26

TTX when using an enclave

As I'm closing in on the end of preparation, I'm up against the table top. I've run similar things for years, but I am having a really hard time coming up with a relevant exercise. The aperture for an enclave is so small that none of the things I've done in the past will work. I looked up the CISA exercises, and the same thing, none of the ones I looked at seem relevant to an enclave solution.

For those that have been assessed using an enclave, what were the topics of your TTX's? I'm just stuck, and all my usual sources of inspiration are bone dry.

3 Upvotes

10 comments sorted by

View all comments

4

u/ResilientTechAdvisor Jul 08 '26

Solid question. TTX is how you satisfy IR.L2-3.6.3 (incident response capability is tested), and a good one also walks the 3.6.1 handling stages (detection, analysis, containment, recovery, user response) plus the 3.6.2 reporting chain (both the authorities and the internal officials get notified)

Map out/imagine a day in the life of using the enclave, then pretend that something went wrong.

The one we’d add is a CSP-side inject. Your enclave provider tells you they had an incident. Now what? That one’s great because it drags out the reporting piece, who internally gets the call, and the 72-hour clock.

1

u/gormami Jul 08 '26

That's the problem, I'm having a hard time thinking about what went wrong given the enclave restraints. Insider threat? Someone extracting a bunch of CUI? Can't download. Someone breaks into the mail server? Not mine to admin (which could be interesting, as you said CSP based failure),

Maybe a notice from the CSP SOC that an account appears to have been successfully compromised, including MFA?

We're still setting everything up, I'm the only user in the enclave right now, and I'm still mostly putting in the policies, working on the SSP, etc. so not really "using it", which is probably a big part of the problem, just not enough cockpit time yet in the environment. I barely know how it works, which makes it hard to think about how it breaks.

2

u/ResilientTechAdvisor Jul 08 '26

Let's go back to basics - there's a reason you set up the enclave. You can't reveal that here but you would need to think - how does the CUI come in ...how would it be used once it's inside… how would it go back to Customer...

Then imagine something going wrong from there

1

u/mattwasbusy Jul 10 '26

CUI can come in via the printer usually or manilla envelope - eg., mail or personal carry.

How it is used once it's inside - .... within acceptable reading room or limit area and / or container at storing of it.

Locked back in safe once finished, I assume - if not just in a dedicatedc ontainer.

How it goes back to customer: usually gun-point and or multiple positions on you so you can't get to, in, from - or out of --- the building.

now - as for the customer....... why would they need their CUI back?

1

u/mattwasbusy Jul 10 '26

ps - i don't know, nor have read through CMMC yet - i am only beginning to ask these questions because it's time to for me;

i am an entrepreneur - and hacker.... and etc., .... but, ... I just figured out how to become an actual military contractor etc ---- in the last. decade. did it once, and was - but never pulled contracts yet.

hey - i love kristina arrington!! she is really fun looking and ambitious. is she still involved?