We are currently using Connectwise Screenconnect for our customers that are NIST and soon to be CMMC audited. Based on what I read with MSPs, MSPs will also need to be audited if they connect into NIST / CMMC based systems. Are there any specific configurations that must be met for this to work? For example do I need to disable File Transfer within Screenconnect to prevent exfiltration of sensitive data? Do I need to disable Copy/Paste Clipboard? Just looking at what configurations we will need to be compliant.
[link] [comments]