CMMC Governance & Source Documents Flashcards
Directive requiring CUI program?
EO 13556
What NIST SP is about CUI?
NIST SP 800-171
Which clause requires contractors to implement 800-171?
DFARS 252.204-7012 - Safeguarding CDI
Which Title includes DFARS clauses for CMMC?
Title 48, Ch.2, Sub-Ch H, Part 252
Which is THE CUI Program?
Title 32 C.F.R., Part 2002
Which DFARS covers Rights in Technical Data? (non-commercial)
Clause 7013
What requirements speak to Cloud Service Providers? (CSP)
FedRAMP
What does an OSC need with a CSP for CMMC?
Shared Responsibility Matrix.
What are three (3) focus areas for the move from CMMC 1.0 to 2.0?
- Reduced costs, especially for SB
- Increasing trust in the CMMC assessment ecosystem.
- Clarifying and aligning cybersecurity requirements to other federal requirements and commonly accepted standards.
What are the four (4) main tenets of the DoD Acquisition efforts?
Price - Performance - Schedule - Security
What is the policy for Designating, Controlling, and Decontrolling CUI?
Title 32 C.F.R., Part 2002