Platform

How it works The analyst team Trust & audit Integrations Deployment Evidence

Solutions

Defense & suppliers Government Healthcare Financial services MSSPs

Company

About Partners Resources Contact Responsible disclosure
Home/Defense

Defense & the supplier base

NIST 800-171 has three requirement families
a policy binder cannot satisfy

§3.3.5 asks you to review, analyze and report audit records. §3.6 asks you to operate an incident-handling capability. §3.14 asks you to monitor. Every one of those is a verb, and a subcontractor with 40 people and no security team cannot perform them by writing them down.

The gap

The flow-down lands on companies with no SOC

The requirement does not scale down

A prime with a security operations center and a subcontractor with a two-person IT team inherit the same control set. One of them can staff it. The other has a shared services provider, a firewall, and a spreadsheet.

A system security plan is not an operating capability

SSPs and POA&Ms describe what you intend to do. An assessor increasingly wants to see that it happened: dated records of activity being reviewed, incidents being handled, and monitoring producing output somebody read.

CUI constrains where the tooling can run

The obvious answer to "we have no analysts" is a managed vendor cloud. For controlled unclassified information that answer creates a new problem, and for some programs it is simply not available.

The mechanism

The monitoring happens. The evidence comes with it.

Intruex reviews and analyzes every alert your stack produces, escalates what warrants a human, and retains a dated record of each decision with its reasoning. The evidence an assessor wants is generated by the work rather than assembled before the visit.

And because the same platform runs on-premises with no outbound network calls, the capability does not have to be purchased at the cost of a data-residency exception.

Requirement familyWhat Intruex performs
3.3 Audit & accountability
§3.3.5 review, analyze, report
Every alert triaged with written reasoning and a dated disposition
3.6 Incident response
§3.6.1 handling capability
Detection, analysis, escalation packages and an approval-gated response path
3.14 System & information integrity
§3.14.6 monitor
Continuous monitoring of alert output with correlation into incidents
3.1 Access control
§3.1.12 monitor remote access
Identity and remote-access alerts routed to specialists that own that class

CMMC

The families a document cannot cover

Several CMMC families assume that monitoring and review are actually happening in your environment: not planned, not policied, happening. Those are the ones a supplier typically cannot evidence, because nothing in the environment is producing a record.

Intruex performs that activity and leaves a dated, attributable record of it: what fired, what it was found to be, on what reasoning, and who or what closed it. Evidence is cryptographically hashed on capture, so a record produced six months ago can be shown to be the record that was produced six months ago.

Control alignment is cross-mapped through the Secure Controls Framework, so the same activity that satisfies a CMMC family also lands against NIST CSF, ISO 27001 and SOC 2 without a second mapping exercise.

If you have no SOC

We stand the detections up first

A 40-person machining shop with a DFARS clause in its contract does not need alert triage yet. It needs something producing alerts worth triaging. We build that first as an engagement, then the platform has work to do.

That is a real advantage in this segment. Vendors whose value story is analyst hours saved need you to already employ analysts. We can start from zero and hand you an operating capability with the record attached.

Contracting

Prime, sub and teaming

Intruex is the original manufacturer and developer of the Intruex SOC Platform, not a reseller. We work as a subcontractor to primes, as a technology partner on teaming arrangements, and through cooperative vehicles where one applies.

GDIT Emerging Tech Program OEM
Partner with us

Bring us an alert you already know the answer to

Hand it something from last week and read the reasoning. If the verdict is wrong, you will see exactly where it went wrong, which is the whole point.