Eli Selig – CMMC 2.0 Readiness Engineer

Eli Selig, an owner of San Diego Computer Consulting, serves as our CMMC 2.0 Master Prep Engineer, specializing in the design, implementation, and preparation of secured networks and workstations. Eli oversees the technical security measures necessary to help organizations prepare for CMMC 2.0 requirements, including secure workstation configurations, network security, access controls, authentication, endpoint protection, data protection, and other cybersecurity safeguards. His experience and hands-on involvement provide our clients with knowledgeable technical leadership throughout the CMMC preparation and implementation process.

Eli Gcc

CMMC 2.0 Security & Compliance

CMMC 2.0 is designed to protect Controlled Unclassified Information (CUI) and ensure that the systems handling that information have appropriate cybersecurity controls in place. For organizations working with Department of Defense contracts, achieving CMMC compliance requires more than simply installing security software—it requires documented policies, properly secured computers, continuous monitoring, and controls over how sensitive information is accessed and transferred.

San Diego Computer Consulting can help implement and maintain the technology and security controls necessary to support a CMMC 2.0 environment.

Data Loss Prevention (DLP)

Sophos DLP controls can be used to help control how sensitive information is copied, transferred, or removed from protected computers.

DLP policies can help restrict or monitor activities such as:

  • Copying sensitive information to USB drives
  • Transferring protected information to unauthorized locations
  • Copying or moving sensitive files
  • Unauthorized use of removable media
  • Other methods of removing CUI from the protected environment

These controls provide an additional layer of protection against accidental or unauthorized disclosure of CUI.

Building a Secure CMMC Environment

CMMC compliance is ultimately about creating a documented, controlled, and continuously monitored IT environment. The combination of security documentation, endpoint MDR, centralized Active Directory management, CUI controls, and DLP provides a strong foundation for protecting sensitive information and supporting CMMC requirements.

SDCC can assist with the implementation, management, documentation, and ongoing maintenance of the IT security environment required to support your CMMC 2.0 objectives.

Active Directory & Secure Computer Management

Computers within the CMMC environment should be centrally managed and properly secured. Active Directory provides centralized control over user accounts, permissions, security policies, authentication, and computer configurations.

Security policies can be applied consistently across the organization, helping ensure that computers are configured and maintained according to the organization’s CMMC security requirements.

CMMC 2.0 – Two-Factor Authentication on Every Computer

San Diego Computer Consulting implements Multi-Factor Authentication (MFA) as an important security control for protecting access to systems and Controlled Unclassified Information (CUI). User accounts are required to use two-factor authentication, combining a password with a second method of verification, such as Microsoft Authenticator, a security key, or another approved authentication application. MFA provides an additional layer of protection by helping prevent unauthorized access even if a user’s password is compromised. MFA is enforced for remote access, cloud applications, VPN connections, and administrative accounts, with access policies centrally managed through Microsoft Entra ID, Active Directory, and other approved security controls. These measures help ensure that only authorized users can access company systems and CUI and are an important component of the organization’s overall CMMC 2.0 security program.