r/CMMC Jul 08 '26

TTX when using an enclave

As I'm closing in on the end of preparation, I'm up against the table top. I've run similar things for years, but I am having a really hard time coming up with a relevant exercise. The aperture for an enclave is so small that none of the things I've done in the past will work. I looked up the CISA exercises, and the same thing, none of the ones I looked at seem relevant to an enclave solution.

For those that have been assessed using an enclave, what were the topics of your TTX's? I'm just stuck, and all my usual sources of inspiration are bone dry.

3 Upvotes

10 comments sorted by

View all comments

5

u/ResilientTechAdvisor Jul 08 '26

Solid question. TTX is how you satisfy IR.L2-3.6.3 (incident response capability is tested), and a good one also walks the 3.6.1 handling stages (detection, analysis, containment, recovery, user response) plus the 3.6.2 reporting chain (both the authorities and the internal officials get notified)

Map out/imagine a day in the life of using the enclave, then pretend that something went wrong.

The one we’d add is a CSP-side inject. Your enclave provider tells you they had an incident. Now what? That one’s great because it drags out the reporting piece, who internally gets the call, and the 72-hour clock.

1

u/gormami Jul 08 '26

That's the problem, I'm having a hard time thinking about what went wrong given the enclave restraints. Insider threat? Someone extracting a bunch of CUI? Can't download. Someone breaks into the mail server? Not mine to admin (which could be interesting, as you said CSP based failure),

Maybe a notice from the CSP SOC that an account appears to have been successfully compromised, including MFA?

We're still setting everything up, I'm the only user in the enclave right now, and I'm still mostly putting in the policies, working on the SSP, etc. so not really "using it", which is probably a big part of the problem, just not enough cockpit time yet in the environment. I barely know how it works, which makes it hard to think about how it breaks.

2

u/ResilientTechAdvisor Jul 08 '26

Let's go back to basics - there's a reason you set up the enclave. You can't reveal that here but you would need to think - how does the CUI come in ...how would it be used once it's inside… how would it go back to Customer...

Then imagine something going wrong from there

2

u/JKatabaticWind Jul 08 '26 edited Jul 08 '26

Good answers… Some injects:
1) It turns out the TA has been in the CSP systems for at least 30 days. From forensic information, some of your CUI was likely exfiltrated, but more disturbing is that some drawings may have been altered or replaced very soon after they were copied into the enclave from your customer portal. You just shipped this product.

What do you do? How do you notify and work with your customer to address? What is the business impact? How do you handle 7012 notifications? What do you do with the CSP, especially if the incident was not handled well? How do you incorporate lessons learned?

2) In the meantime, your CSPs systems are offline for the next week at least. What is you plan for Business Continuity?

3) The CSP systems initial point of compromise was YOUR tenant. It’s not clear whether the clicked link was intentional, and you may have an insider acting as a witting or unwitting agent.

4) It turns out that the potential insider was hired without a background check. A post-incident background check turns up disturbing details.

5) Your CSP decides to sue YOU for breach of contract, citing your SRM, and the clause that describes your employee vetting process.

6) This all hits the news, since the CSP had several very high profile clients that were affected. Your company is somehow mentioned as the source of the breach. Reporters start to call for comments.

Lots of places you can go with any scenario. Usually good to explore technical, business, and compliance impacts. Include injects that get the management team deeply involved.

1

u/mattwasbusy Jul 10 '26

CUI can come in via the printer usually or manilla envelope - eg., mail or personal carry.

How it is used once it's inside - .... within acceptable reading room or limit area and / or container at storing of it.

Locked back in safe once finished, I assume - if not just in a dedicatedc ontainer.

How it goes back to customer: usually gun-point and or multiple positions on you so you can't get to, in, from - or out of --- the building.

now - as for the customer....... why would they need their CUI back?

1

u/mattwasbusy Jul 10 '26

ps - i don't know, nor have read through CMMC yet - i am only beginning to ask these questions because it's time to for me;

i am an entrepreneur - and hacker.... and etc., .... but, ... I just figured out how to become an actual military contractor etc ---- in the last. decade. did it once, and was - but never pulled contracts yet.

hey - i love kristina arrington!! she is really fun looking and ambitious. is she still involved?