CMMC Governance & Source Documents Flashcards

1
Q

Directive requiring CUI program?

A

EO 13556

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What NIST SP is about CUI?

A

NIST SP 800-171

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which clause requires contractors to implement 800-171?

A

DFARS 252.204-7012 - Safeguarding CDI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which Title includes DFARS clauses for CMMC?

A

Title 48, Ch.2, Sub-Ch H, Part 252

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which is THE CUI Program?

A

Title 32 C.F.R., Part 2002

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which DFARS covers Rights in Technical Data? (non-commercial)

A

Clause 7013

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What requirements speak to Cloud Service Providers? (CSP)

A

FedRAMP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does an OSC need with a CSP for CMMC?

A

Shared Responsibility Matrix.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are three (3) focus areas for the move from CMMC 1.0 to 2.0?

A
  1. Reduced costs, especially for SB
  2. Increasing trust in the CMMC assessment ecosystem.
  3. Clarifying and aligning cybersecurity requirements to other federal requirements and commonly accepted standards.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the four (4) main tenets of the DoD Acquisition efforts?

A

Price - Performance - Schedule - Security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the policy for Designating, Controlling, and Decontrolling CUI?

A

Title 32 C.F.R., Part 2002

How well did you know this?
1
Not at all
2
3
4
5
Perfectly