4 min. read • Email this page
Listen to this blog post:
The road to CMMC
Looking at Microsoft 365 GCC High
Microsoft’s Cambridge offices. GCC High means your data is on servers reserved for the US government, agencies and authorized contractors.
Everyone in the defense industry or who wants to be in the defense supply chain knows CMMC (Cybersecurity Maturity Model Certification). But unless you’re compliant or in-the-process, chances are you don’t know what it’s like on the ground to be held to such standards of security.
Microsoft 365 GCC High gives a window into what CMMC will be like for users
Microsoft 365 has options. Most organizations choose a commercial version. And then there’s GCC (Government Community Cloud) and the stricter GCC High.
The look and feel of M365 GCC High is the same as any iteration of M365. The difference is underneath: the US-based hosting facility must meet CMMC security standards, your data remains on US soil accessible only to screened US personnel and the backend offers admins a broader set of security controls. It was built for organizations handling CUI (controlled unclassified information) like schematics, specifications, pricing and vendor information — and for companies that need to be ITAR (International Traffic in Arms Regulations) compliant to cover data connected to weapons.
M365 GCC High is the familiar tools operating inside a much more tightly governed environment.
What’s different when you’re working in it
Log into GCC High email on your cell phone and you are logged out of your other email accounts. This is a deliberate control to prevent CUI and PII (personally identifiable information) from moving into unsecured personal or commercial environments. PII protections are included to safeguard identities of people associated with government-connected projects.
Quarantine behavior changes too. In a standard anti-spam setup, an end user can access their quarantine folder, review held messages and release them. In a CMMC-compliant environment, that access is removed. A user cannot retrieve a quarantined email, period.
Within GCC High external sharing is restricted by default. If a vendor asks for a drawing, the employee that tries to send it often will hit permissions blocks. Similarly employees can’t add external collaborators to a folder like they are used to doing in Teams, for example. The environment assumes every external recipient is a potential risk until proven otherwise. This is quite opposite to commercial M365 in which sharing is mostly allowed and user-controlled.
In the bigger CMMC picture
Bryley can help map the entire course of attaining CMMC compliance. M365 GCC High is built to be a significant piece of that CMMC compliance posture.
Bryley can provide, configure and manage M365 GCC High on your behalf. If you’re assessing whether GCC High fits your contracts, or trying to understand what a compliant M365 environment would look like for your operation, that’s a conversation Bryley’s Roy Pacitto is here for. Reach Roy at RPacitto@Bryley.com or reach him by phone at 978.562.6077 x217 or use the form, below.
Lawrence writes about networking and security. His consumer-scam writing has appeared on the Moneywise website. He’s written for Bryley since 2015.