Cybersecurity Case Study · Govern & Comply

SnowBe Online Security Maturity Assessment

This assessment rates all 17 CMMC domains for SnowBe Online, an AWS-hosted retailer that stores payment data, then ranks them by business risk and urgency instead of by score. Four priority domains are mapped to specific CMMC practices with concrete next steps for detection, logging, network control, and recovery.

By Sean Richard · Project date April 2026

At a glance

Scenario
SnowBe Online: AWS-hosted web sales, credit cards stored in the website database, and new technical controls (Active Directory, firewall, antivirus, backups, RMM) but thin governance and response.
Method
Rate all 17 CMMC domains with the Simple Maturity Model, prioritize by business risk and urgency, then map selected domains to CMMC capabilities and practices.
Key insight
Maturity score and remediation priority are different things. Awareness Training is weak, but Incident Response is more urgent.
Outcome
Four practice-mapped work items (IR.2.093, AU.2.042, SC.2.179, RE.2.137) with next steps for detection, evidence, network control, and recovery.

Rating all 17 CMMC domains

SnowBe had made real technical progress: job-based access in Active Directory, a new firewall with documented settings, antivirus on desktops, laptops, and servers, and backups and remote monitoring across endpoints and servers. The first step rated every CMMC domain on the Simple Maturity Model to see where that progress had and had not reached.

Simple Maturity Model ratings for the 17 CMMC domains at SnowBe Online
RatingDomains
3 (more defined)Access Control, Configuration Management, Identification & Authentication, Recovery, System & Communications Protection, System Integrity
2Asset Management, Audit & Accountability, Maintenance, Physical Protection, Security Assessment, Situational Awareness
1 (weakest)Incident Response, Risk Management, Awareness & Training, Media Protection, Personnel Security

The ratings showed that tools were present but the gaps were mostly process gaps. Existing controls covered Active Directory, firewall, antivirus, backups, and RMM. What was missing was incident response, risk management, log review, training, and personnel security. Technical progress had outrun security governance.

Why priority is not the same as maturity score

A low score identifies a gap, but risk determines what gets handled first. Five domains scored 1, yet they are not equally urgent. SnowBe processes and stores sensitive customer data, including credit cards, so the prioritization weighs risk exposure and business impact. The resulting order:

  1. Incident Response
  2. Risk Management
  3. Audit & Accountability
  4. System Integrity
  5. System & Communications Protection
  6. Access Control
  7. Recovery
  8. Identification & Authentication
  9. Situational Awareness
  10. Configuration Management
  11. Asset Management
  12. Security Assessment
  13. Maintenance
  14. Physical Protection
  15. Media Protection
  16. Personnel Security
  17. Awareness & Training

Incident Response ranks first because the company had no ability to detect or respond to attacks, so a breach could go unnoticed. Risk Management follows because there was no structured way to identify and prioritize threats. Audit & Accountability is critical for detecting malicious activity through logging and monitoring. Awareness & Training scored just as low as Incident Response but ranks last: it is important, but not urgent compared with breach detection and prevention.

CMMC practice mapping for four priority domains

Priorities 1, 3, 5, and 7 were selected for deeper analysis. Each was mapped to the capability with the highest coverage and the CMMC practice that represents the next best step. Together they form a focused path: response, evidence, network control, and continuity.

Priority domains mapped to CMMC capabilities, practices, and requirements
DomainCapabilityPracticeRequirement
1. Incident ResponseIncident response lifecycle (plan, detect, respond)IR.2.093Detect and report events
3. Audit & AccountabilityAudit logging and monitoringAU.2.042Create and retain audit logs
5. System & Communications ProtectionBoundary protection and secure communicationsSC.2.179Control communications at boundaries
7. RecoveryBackup and recovery managementRE.2.137Manage backups

Remediation roadmap

  • IR.2.093: define what constitutes a security event, establish detection, escalation, and response procedures, implement SIEM or enhanced RMM alerting, write incident response playbooks, train employees to report, and validate the plan with tabletop exercises.
  • AU.2.042: enable logging on servers, endpoints, firewalls, and AWS, aggregate logs in a centralized platform such as a SIEM, define retention and protect logs from tampering, review them regularly, and alert on anomalies such as failed logins or unauthorized access.
  • SC.2.179: review and harden firewall rules so only necessary ports and services are exposed, segment the network to separate systems such as the databases holding customer information, enforce TLS and encryption in transit, restrict VPN access by role, and introduce IDS/IPS.
  • RE.2.137: define a backup strategy covering frequency, on-site and off-site or cloud storage, and retention, encrypt backups and protect them from ransomware, test restores regularly, and write a disaster recovery plan with recovery time and recovery point objectives.

The professional lesson recorded in the report is that cybersecurity maturity is not about implementing tools but about building structured, repeatable processes. Organizations like SnowBe install firewalls, antivirus, and backups and remain vulnerable because they lack monitoring, response, and governance. Maturity requires people, processes, and technology working together in a structured and measurable way.

What this project demonstrates

  • Rating an organization across all 17 CMMC domains from documented evidence.
  • Ranking remediation by risk, urgency, and business impact instead of by score alone.
  • Mapping priorities to specific CMMC practices and writing actionable next steps.
  • Presenting the same analysis as a written report and an executive slide deck.
CMMCMaturity assessmentIncident responseSIEM/loggingNetwork segmentationBackup and recoveryExecutive communicationRisk prioritizationControl mapping

Read the full document

Portfolio edition of coursework completed for the B.S. in Cyber/Computer Forensics & Counterterrorism at Full Sail University. The organization and scenario are a course case study, and this page summarizes the full document.

Related work

Ready to build the system behind your growth?

Tell me what you're operating.