CCP Lesson 3 Flashcards
Maturity Model
A model that assesses how institutionalized critical practices and processes are in an organization and helps determine what capabilities they need in order to continue to improve their performance.
Domain
A grouping of like practices based on the 14 control families set forth in NIST SP 800-171
Practice
An activity or set of activities that are performed to meet the defined CMMC objectives
Assessment Objective (AO)
Identifies the specific set of objectives that must be met to receive MET for the practice as defined in NIST SP 800-171A
Self-assessment
Assessing your organization’s compliance to the practice requirements
Self-attestation
Making an official declaration that something complies with regulations without independent substantiating evidence
Maturity Model
Measures how well you perform a checklist practice consistently
Cybersecurity Maturity Model Certification (CMMC) Model 2.0
Identifies 3 levels of practices that lead to increasingly stronger cyber hygiene
Cybersecurity Maturity Model Certification (CMMC) Taxonomy
Cybersecurity Maturity Model Certification Model –> Domains –> Practices –> Assessment Objectives
Cybersecurity Maturity Model Certification (CMMC) Domains
14 Domains:
Access Control
Audit and Accountability
Awareness and Training
Configuration Management
Identification and Authentication
Incident Response
Maintenance
Media Protection
Personnel Security
Physical Protection
Risk Assessment
Security Assessment
System and Communication Protection
System and information Integrity
Cybersecurity Maturity Model Certification (CMMC) Practice
One or more activities that an organization regularly performs, demonstrating a particular cybersecurity capability
Cybersecurity Maturity Model Certification (CMMC) Practice Numbering System
Practice number indicate:
Domain
Level
Requirement number
Example: AC.L1-3.1.1
Access Control (AC) Domain
Manage who accesses your network and systems
Level 1 - 4 practices
Level 2 - 22 practices
Audit and Accountability (AU) Domain
Create logs and review them frequently
Level 1 - 0 practices
Level 2 - 9 practices
Awareness and Training (AT) Domain
Ensure your people are trained appropriately
Level 1 - 0 practices
Level 2 - 3 practices
Configuration Management (CM) Domain
Ensure baselines and other configurations are kept up to date
Level 1 - 0 practices
Level 2 - 9 practices
Identification and Authentication (IA) Domain
Know you is requesting access and authenticate appropriately
Level 1 - 2 practices
Level 2 - 11 practices
Incident Response (IR) Domain
Be able to recover once an incident occurs
Level 1 - 0 practices
Level 2 - 3 practices
Maintenance (MA) Domain
Keep your systems up to date and patched
Level 1 - 0 practices
Level 2 - 6 practices
Media Protection (MP) Domain
Ensure mobile media is protected against theft or loss
Level 1 - 1 practice
Level 2 - 9 practices
Personnel Security (PP) Domain
Manage risks to your environment by insiders
Level 1 - 0 practices
Level 2 - 2 practices
Physical Protection (PE) Domain
Employ physical protection mechanisms to prevent access to physical devices
Level 1 - 4 practices
Level 2 - 6 practices
Risk Assessment (RA) Domain
Have a process for identifying and managing enterprise risk
Level 1 - 0 practices
Level 2 - 3 practices
Security Assessment (CA) Domain
Independently verify your security posture
Level 1 - 0 practices
Level 2 - 4 practices
System and Communications Protection (SC) Domain
Manage security tools and processes related to system security
Level 1 - 2 practices
Level 2 - 16 practices
System and Information Integrity (SI) Domain
Monitor and protect the information system against malicious content
Level 1 - 4 practices
Level 2 - 7 practices
Cybersecurity Maturity Model Certification (CMMC) Documentation
Cybersecurity Maturity Model Certification (CMMC) Model Overview
Cybersecurity Maturity Model Certification (CMMC) Model Overview
Model framework and background for the creation of the Cybersecurity Maturity Model Certification (CMMC) Model
Cybersecurity Maturity Model Certification (CMMC) Self-Assessment Guide Level 1
assessment criteria and methodology used by Organization Seeking Certification (OSC) to conduct self-assessment
Cybersecurity Maturity Model Certification (CMMC) Assessment Guide Level 2
Assessment criteria and methodology used by Certified Cybersecurity Maturity Model Certification (CMMC) Assessors (CCA)