<img src="https://ad.doubleclick.net/ddm/activity/src=11631230;type=pagevw0;cat=pw_allpg;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=;tfua=;npa=;gdpr=${GDPR};gdpr_consent=${GDPR_CONSENT_755};ord=1;num=1?" width="1" height="1" alt="">

CASE STUDY

Checking the Box for CMMC vs. Actually Protecting CUI

26-Case Study Images-dev3
SHE BASH Logo
  • INDUSTRY

    IT & Software

  • PRODUCTS

    Virtru Private Keystore, Virtru for Google Gmail, Virtru for Google Drive

See Virtru in Action

"What if there is no box to check because the boxes are plugged into each other in a way that's automated?"

If you're pursuing CMMC compliance, there are a lot of boxes to check. These requirements for defense contractors are intended to safeguard CUI being handled as part of government contracts with the Department of Defense, or Department of War.

In this video, CEO of SHE BASH, Bunny Banowsky, explains the difference between "checking the box" for compliance and the true work of securing data in an intelligent way with Virtru as part of their tech stack.  

To learn more about how Virtru can support your compliance strategy with secure, intuitive tools that go beyond "checking the box," contact our team today

Read transcript Hide transcript
So checklists are good for some things, right? They're good when you're, a medical doctor or a nurse in an emergency room or an operating room, and you have your checklist of things to do so that the minutia doesn't get forgotten.

But in our industry, in our landscape where operation and monitoring phase post-implementation is actually also important and essential to not only maintaining compliance, but to maintaining a secure Zero Trust posture, pillar principle, etc., having a checklist of boxes to check, is actually cumbersome.

It introduces more overhead, more time, etc. And, again, coming back to being lean and staying lean, and being able to move fast while moving securely, all of that really just pointed to products like Virtru, products like Drata, and rethinking the box to check. Right?

What if there is no box to check because the boxes are plugged into each other in a way such that it's automated, right? And the monitoring of the compliance can be done in an ongoing fashion, thereby sort of curtailing the overhead that goes into that side of the life cycle. Moving forward in the monitoring of the policy portion of the journey as a business owner and operator, I'm actually excited because we have selected the these tools that are working together.

They're working smartly. They're saving time. And actually, you know, on this side of the of the journey, I can say CMMC actually was a great experience. Right?

And it was fun at the end of the day. Now it wasn't fun at the beginning of the day while we were trying to do the checkbox, checklist approach. But by the end of the journey, with smart tool selection, again, it was actually a streamlined experience.