SnowBe Online Security Maturity Assessment
This assessment rates all 17 CMMC domains for SnowBe Online, an AWS-hosted retailer that stores payment data, then ranks them by business risk and urgency instead of by score. Four priority domains are mapped to specific CMMC practices with concrete next steps for detection, logging, network control, and recovery.
By Sean Richard · Project date April 2026
At a glance
- Scenario
- SnowBe Online: AWS-hosted web sales, credit cards stored in the website database, and new technical controls (Active Directory, firewall, antivirus, backups, RMM) but thin governance and response.
- Method
- Rate all 17 CMMC domains with the Simple Maturity Model, prioritize by business risk and urgency, then map selected domains to CMMC capabilities and practices.
- Key insight
- Maturity score and remediation priority are different things. Awareness Training is weak, but Incident Response is more urgent.
- Outcome
- Four practice-mapped work items (IR.2.093, AU.2.042, SC.2.179, RE.2.137) with next steps for detection, evidence, network control, and recovery.
Rating all 17 CMMC domains
SnowBe had made real technical progress: job-based access in Active Directory, a new firewall with documented settings, antivirus on desktops, laptops, and servers, and backups and remote monitoring across endpoints and servers. The first step rated every CMMC domain on the Simple Maturity Model to see where that progress had and had not reached.
| Rating | Domains |
|---|---|
| 3 (more defined) | Access Control, Configuration Management, Identification & Authentication, Recovery, System & Communications Protection, System Integrity |
| 2 | Asset Management, Audit & Accountability, Maintenance, Physical Protection, Security Assessment, Situational Awareness |
| 1 (weakest) | Incident Response, Risk Management, Awareness & Training, Media Protection, Personnel Security |
The ratings showed that tools were present but the gaps were mostly process gaps. Existing controls covered Active Directory, firewall, antivirus, backups, and RMM. What was missing was incident response, risk management, log review, training, and personnel security. Technical progress had outrun security governance.
Why priority is not the same as maturity score
A low score identifies a gap, but risk determines what gets handled first. Five domains scored 1, yet they are not equally urgent. SnowBe processes and stores sensitive customer data, including credit cards, so the prioritization weighs risk exposure and business impact. The resulting order:
- Incident Response
- Risk Management
- Audit & Accountability
- System Integrity
- System & Communications Protection
- Access Control
- Recovery
- Identification & Authentication
- Situational Awareness
- Configuration Management
- Asset Management
- Security Assessment
- Maintenance
- Physical Protection
- Media Protection
- Personnel Security
- Awareness & Training
Incident Response ranks first because the company had no ability to detect or respond to attacks, so a breach could go unnoticed. Risk Management follows because there was no structured way to identify and prioritize threats. Audit & Accountability is critical for detecting malicious activity through logging and monitoring. Awareness & Training scored just as low as Incident Response but ranks last: it is important, but not urgent compared with breach detection and prevention.
CMMC practice mapping for four priority domains
Priorities 1, 3, 5, and 7 were selected for deeper analysis. Each was mapped to the capability with the highest coverage and the CMMC practice that represents the next best step. Together they form a focused path: response, evidence, network control, and continuity.
| Domain | Capability | Practice | Requirement |
|---|---|---|---|
| 1. Incident Response | Incident response lifecycle (plan, detect, respond) | IR.2.093 | Detect and report events |
| 3. Audit & Accountability | Audit logging and monitoring | AU.2.042 | Create and retain audit logs |
| 5. System & Communications Protection | Boundary protection and secure communications | SC.2.179 | Control communications at boundaries |
| 7. Recovery | Backup and recovery management | RE.2.137 | Manage backups |
Remediation roadmap
- IR.2.093: define what constitutes a security event, establish detection, escalation, and response procedures, implement SIEM or enhanced RMM alerting, write incident response playbooks, train employees to report, and validate the plan with tabletop exercises.
- AU.2.042: enable logging on servers, endpoints, firewalls, and AWS, aggregate logs in a centralized platform such as a SIEM, define retention and protect logs from tampering, review them regularly, and alert on anomalies such as failed logins or unauthorized access.
- SC.2.179: review and harden firewall rules so only necessary ports and services are exposed, segment the network to separate systems such as the databases holding customer information, enforce TLS and encryption in transit, restrict VPN access by role, and introduce IDS/IPS.
- RE.2.137: define a backup strategy covering frequency, on-site and off-site or cloud storage, and retention, encrypt backups and protect them from ransomware, test restores regularly, and write a disaster recovery plan with recovery time and recovery point objectives.
The professional lesson recorded in the report is that cybersecurity maturity is not about implementing tools but about building structured, repeatable processes. Organizations like SnowBe install firewalls, antivirus, and backups and remain vulnerable because they lack monitoring, response, and governance. Maturity requires people, processes, and technology working together in a structured and measurable way.
What this project demonstrates
- Rating an organization across all 17 CMMC domains from documented evidence.
- Ranking remediation by risk, urgency, and business impact instead of by score alone.
- Mapping priorities to specific CMMC practices and writing actionable next steps.
- Presenting the same analysis as a written report and an executive slide deck.
Read the full document
Portfolio edition of coursework completed for the B.S. in Cyber/Computer Forensics & Counterterrorism at Full Sail University. The organization and scenario are a course case study, and this page summarizes the full document.