CCP Lesson 1 Flashcards
Defense Industrial Base (DIB) includes.
DoD Components, companies providing materials and services, government-owned facilities operated by the government or contractors
Does Defense Supply Chain extend beyond DIB? Give examples.
Yes. office equipment, janitors, food
What certification makes cybersecurity foundational for all acquisitions?
Cybersecurity Maturity Model Certification (CMMC)
Who receives contracts from the government?
Prime contractors
Who helps prime contractors fulfill portions of the contracts?
Subcontractors
As information is moved between government, prime contractors, and subcontractors it is __ ____.
At risk
What represents a philosophical change to securing the nation’s data?
CMMC program
What is the DoD’s initiative to verify defense contractors’ cybersecurity preparedness and effectiveness?
CMMC
CMMC standardized cybersecurity implementation across what?
Defense Industrial Base (DIB)
What year did the CMMC program kick off?
2019
What year was CMMC Model 1.0 released?
2020
What year was CMMC Model 2.0 released?
2021
What is considered the company’s own methods, techniques and inventions?
Internal Intellectual Property (IP)
Information from partners outside the government that is generally protected by contracts between parties such as license agreements and NDA’sis what tpe of Intellectual Property (IP)?
External Intellectual Property (IP)
As it pertains to Legal, Regulatory, and Policy (LRP) Drivers, what ensures proper actions?
Laws
As it pertains to Legal, Regulatory, and Policy (LRP) Drivers, what are laws interpreted and implemented throug?
Regulations
As it pertains to Legal, Regulatory, and Policy (LRP) Drivers, regulations are detailed thorugh?
Policies
What provides policies and procedures that apply to all Executive Branch departments and agencies regarding acquisitions?
Federal Acquisition Regulation (FAR)
48 CFR is also known as?
Federal Acquisition Regulation (FAR)
What regulation documents rules that government contractors are subject to, takes priority over Defense Federal Aquisition Regulation Supplement (DFARS), and provides a consistent set of baselines that apply to all solicitations?
Federal Acquisition Regulation (FAR)
What regulation is a supplement of the Federal Aquisition regulation?
Defense Federal Aquisition Regulation Supplement (DFARS)
Defense Federal Aquisition Regulation Supplement (DFARS) includes policies and procedures that apply to who and administered by who?
Department of Defense (DoD)
What does Defense Federal Acquisition Regulation Supplement (DFARS) cover?
Department of Defense acquisitions
The Federal Information Security Modernization Act is the Legal Authority for what type of information?
Federal Contract Information (FCI) and Controlled Unclassified Information (CUI)
What law requires government to protect sensitive information?
Federal Information Security Modernization Act
What is the Regulatory Authority for Federal Contract Information?
48 CFR Section 52
What regulations explain how to adhere to the law, as applied to a contractor’s information systems?
48 CFR Section 52
What is section 52 of the Federal Acquisition Regulation (FAR) is also called?
FAR 52
What is the primary source of information on handling requirements for FCI?
FAR 52
As defined in FAR 52, what is an information system that is owned or operated by a contractor that processes, stores, or transmits Federal Contract Information (FCI)?
Covered Contractor information System
As defined in FAR 52, What is information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public or simple transactional information?
Federal Contract Information (FCI)
As defined in FAR 52, what is any communication or representation of knowledge?
Information
As defined in FAR 52, what is a discrete set of information resources organized for collection, processing, maintenance, use, sharing, dissemination, or disposition of information?
Information System
As defined in FAR 52, what are measures or controls that are prescribed to protect information systems?
Safeguards
2002 Federal Information Security Management Act (FISMA) Amended in 2014 and Executive Order 13556, Controlled Unclassified Information is the legal Authority for what type of information?
Controlled Unclassified Information (CUI)
32 CFR Part 2002 is the regulatory authority for what type of information?
Controlled Unclassified Information (CUI)
Who oversees CUI Policy?
National Archives and Records Administration (NARA)
What regulatory Authority appointed the National Archives and Administration (NARA) to oversee CUI policy?
32 CFR Part 2002
What regulation stood up Information Security Oversight Office (ISOO), which publishes CUI notices?
32 CFR Part 2002