CUI Compliant

0 NIST 800-171 gaps detected. FedRAMP authorized at Moderate impact level. Approved for CUI handling in DoD environments.

Video Conferencing

Webex for Government

by Cisco

FedRAMP AuthorizedModerate Impact

FedRAMP Status

FedRAMP Authorized

Impact Level

Moderate

Category

Video Conferencing

Authorized: February 2, 2016

Overview

Cisco Webex for Government is a FedRAMP Moderate authorized video conferencing and collaboration platform. It provides encrypted meetings, messaging, and calling for government users.

CUI Risk Assessment

FedRAMP authorized at Moderate impact level. Approved for CUI handling in DoD environments.

Deployment & Architecture

Deployment Model: Government Cloud (FedRAMP boundary)

Webex for Government operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.

Configuration Checklist

  1. 1ISSO must coordinate with Cisco Government Cloud support to provision tenant within FedRAMP Moderate boundary and configure FIPS 140-2 encryption settings.
  2. 2System administrator shall implement single sign-on integration with contractor's Active Directory to ensure user provisioning aligns with contract personnel access lists per DFARS 252.204-7012.
  3. 3ISSO shall configure audit logging retention policies to meet 1-year minimum requirement and establish automated log forwarding to contractor's SIEM solution.
  4. 4System administrator must disable public meeting creation capabilities and implement guest access controls requiring approval workflow for external participants.
  5. 5ISSO shall update System Security Plan Section 10.2 to document Webex integration points and data flow diagrams showing encrypted communication paths.
  6. 6Training coordinator must develop CUI-specific user training covering screen sharing protocols, meeting recording policies, and incident reporting procedures.
  7. 7ISSO shall create POA&M entries for quarterly configuration reviews and monthly user access audits to maintain CMMC Level 2 compliance.
  8. 8System administrator must implement endpoint compliance checking to ensure only managed devices can access CUI-enabled Webex sessions.
  9. 9ISSO shall establish meeting recording classification procedures aligned with contract CUI categories and retention schedules.
  10. 10Contracts officer must review current DoD contracts to ensure Webex for Government usage aligns with approved collaboration tool listings in contract clauses.

Frequently Asked Questions

Is Webex for Government FedRAMP authorized?

Yes. Cisco Webex for Government holds FedRAMP Moderate authorization for video conferencing and collaboration.

Can I discuss CUI on Webex for Government?

Webex for Government is authorized at Moderate and can be used for CUI discussions at that impact level.

Run a Full Tech Stack Audit

Check all your enterprise tools at once with our free CUI Compliance Auditor.

Launch CUI Auditor

Get a defensible CUI architecture

This Webex for Government CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures