American Additive Manufacturing
American Digital Services partnered with American Additive Manufacturing, a leader in advanced manufacturing, to align their cybersecurity practices with the stringent requirements of the Cybersecurity Maturity Model Certification (CMMC 2.0) and the National Institute of Standards and Technology (NIST) Special Publication 800-171. This collaboration ensured robust protection of Controlled Unclassified Information (CUI) while strengthening the company’s resilience against evolving cyber threats. This white paper highlights the strategic approach and key outcomes of the engagement, emphasizing American Additive Manufacturing’s commitment to compliance and operational excellence.
Strategic Framework for Compliance
American Digital Services executed a phased methodology to streamline compliance with federal regulations and industry best practices:
- Context and Governance
- Conducted a comprehensive review of regulatory obligations, including CMMC 2.0, NIST 800-171, and DFARS requirements.
- Collaborated with stakeholders to develop a prioritized roadmap addressing personnel, technology, and process gaps.
- Scope Definition
- Mapped CUI flows across systems using Data Flow Diagrams (DFDs) and identified third-party interactions.
- Performed a detailed asset inventory to clarify compliance boundaries and in-scope infrastructure.
- Risk Management
- Designed a formalized Risk Management Program (RMP) to address vulnerabilities in critical systems.
- Evaluated third-party vendors to ensure alignment with supply chain security requirements.
- Policy Development
- Authored tailored System Security Plans (SSP) and Plans of Action & Milestones (POA&M) to track remediation efforts.
- Modernized governance policies, including incident response, access control, and change management frameworks.
- Infrastructure Modernization
- Upgraded network security appliances and firmware to meet current standards.
- Implemented segmented network architecture to isolate CUI and enforce boundary protections.
- Identity and Access Management (IAM)
- Deployed role-based access controls (RBAC) and multi-factor authentication (MFA) for critical systems.
- Centralized authentication protocols to streamline credential management and reduce risk.
Cultural and Operational Enhancements
- Employee Handbook Integration
- Revised policies to embed cybersecurity responsibilities, including remote work protocols, data handling, and incident reporting.
- Aligned anti-discrimination, confidentiality, and social media guidelines with federal and Pennsylvania state laws.
- Training and Awareness
- Delivered mandatory cybersecurity training programs focused on CMMC 2.0 and NIST 800-171 requirements.
- Provided role-specific training to ensure personnel understood compliance obligations.
- Incident Preparedness
- Developed a compliant Incident Response Plan (IRP) with notification procedures aligned to Pennsylvania state law.
- Implemented centralized logging and monitoring tools to enhance threat detection and response.
Key Outcomes
- Regulatory Compliance: Full alignment with CMMC 2.0 and NIST 800-171 controls, ensuring visibility into CUI flows.
- Modernized Infrastructure: Enhanced network defenses, including next-gen firewalls, VPNs, and secure wireless protocols.
- Security-Centric Culture: Empowered employees through updated policies, training, and accountability frameworks.
Conclusion
Through its partnership with American Digital Services, American Additive Manufacturing has successfully transformed its cybersecurity posture to meet federal compliance requirements while fostering a proactive security culture. By prioritizing governance, infrastructure resilience, and employee engagement, the company now stands as a model for safeguarding sensitive data and mitigating risks in the manufacturing sector.