Trust Center

Trust Center
Security & Compliance at MNS Group

Security and compliance aren't features we add on; they're part of our DNA. At MNS Group, we operate to the same standards we help the Defense Industrial Base meet.

ISO-lockup

 

Overview

How We Protect Information

MNS Group is a Baltimore/DC-based managed security services provider and authorized C3PAO serving defense contractors, government contractors, financial services, medical providers, and non-profits. With more than 20 years of cybersecurity and technology experience, our security program is built on recognized frameworks and validated through independent, third-party audits.

20+ years

Two decades securing government contractors and the Defense Industrial Base.

Authorized C3PAO/RPO

CMMC Third-Party Assessment Organization with certified CCPs, CCAs, and RPs.

Independently audited

Certifications maintained through regular third-party audits and reviews.

Compliance-first

We operate deep within the compliance ecosystem we help our clients navigate.

Compliance & Certifications

Frameworks and Standards We Hold

ISO/IEC 27001

Information Security Management System certification.

Certified

ISO/IEC 20000

IT Service Management certification.

Certified

ISO 9001

Quality Management System certification.

Certified

SOC 2

Service Organization Control report on security controls.

Certified

C3PAO

Authorized Third-Party Assessment Organization for CMMC.

Authorized

NIST SP 800-171

Protection of Controlled Unclassified Information (CUI).

Aligned

CIS Controls

Center for Internet Security Critical Security Controls.

Aligned

NIST CSF 1.1

Cybersecurity Framework for risk management.

Aligned

Security Controls

Controls By Category

Our security program spans organizational, technical, and physical safeguards. Below is a summary of the control domains we operate and continuously monitor.

Information Security

  • ISO 27001-certified ISMS with documented policies
  • Role-based access control and least privilege
  • Encryption of data in transit and at rest
  • Formal risk assessment and treatment process

Organizational Security

  • Security awareness and role-based training
  • Background screening for personnel
  • Documented policies reviewed on a regular cadence
  • Defined security roles and responsibilities

Network & Infrastructure

  • Segmentation and defense-in-depth architecture
  • Firewalls, IDS/IPS, and endpoint protection
  • Hardened configurations aligned to CIS benchmarks
  • SecureCMMC℠ enclave for CUI environments

Threat & Vulnerability Management

  • Continuous monitoring and log management
  • Vulnerability scanning and patch management
  • Managed detection and response
  • Regular third-party security reviews

Incident Management

  • Documented incident response plan
  • Defined escalation and notification procedures
  • Post-incident review and remediation tracking
  • 24/7 monitoring for managed clients

Business Continuity

  • Backup and recovery procedures
  • Business continuity and disaster recovery planning
  • Tested restoration processes
  • Resilient, redundant infrastructure

Third-Party & Vendor Risk

  • Vendor due diligence and risk assessment
  • Contractual security and confidentiality requirements
  • Ongoing monitoring of critical suppliers

Compliance & Audit

  • Plan of Action & Milestones (POA&M) tracking
  • Independent third-party audits (ISO, SOC 2)
  • SPRS scoring support and self-assessment guidance
  • Transparent, clearly reported assessment results

FAQs

Frequently Asked Questions

Common questions from clients, partners, and prospects evaluating our security posture.

Is MNS Group an authorized CMMC assessor?

Yes. MNS Group is an authorized CMMC Third-Party Assessment Organization (C3PAO). Our team includes Certified CMMC Professionals (CCPs), Certified CMMC Assessors (CCAs), and Registered Practitioners (RPs), allowing us to perform mock assessments, readiness reviews, and formal certification assessments.

Which certifications does MNS Group hold?

MNS Group is certified to ISO/IEC 27001 (information security), ISO/IEC 20000 (IT service management), and ISO 9001 (quality management), and maintains a SOC 2 report. We also align our operations to NIST SP 800-171, the CIS Controls, and NIST CSF 1.1.

How can I obtain your SOC 2 report or ISO certificates?

Formal documentation — including our SOC 2 report, ISO certificates, and security policies — is available to clients and prospects under NDA. Use the request form and our team will follow up to share the appropriate materials.

How does MNS Group protect Controlled Unclassified Information (CUI)?

CUI is protected in accordance with NIST SP 800-171. For clients that need a compliant environment, our SecureCMMC℠ enclave provides a shared, controlled infrastructure with the technical and administrative safeguards required to handle CUI.

How often is your security program audited?

We undergo regular independent third-party audits and security reviews to maintain our certifications. Our compliance program is continuously monitored, and findings are tracked to remediation through a Plan of Action & Milestones (POA&M).

How do I report a security concern?

Security concerns or suspected vulnerabilities can be reported to our team by phone at 888-640-6674 or 410-838-1088. Please include enough detail for us to investigate, and we will respond promptly.

 

Reach Out to Us Today!