CMMC Scoping & Process Flashcards
FCI Asset
Any devices that stores, processes, or has access to FCI.
CUI Asset
Any device that stores, processes, or has access to CUI.
Out-of-Scope Asset
Any device that does not have access to CUI, or FCI.
What are the 5 categories of Special Assets?
- Government Equipment
- IoT and Industrial IoT
- Operation Technology (OT)
- Restricted Information Systems
- Test Equipment
What is a Special Asset - Restricted Information System?
An information system or component essential to servicing a contract, such as a dev network. The OSC must clearly articulate how and why the asset is an SA and OoS.
How long does a C3PAO have to respond during Phase 1?
5 Business Days
How long does the OSC have to correct items in the ‘Limited Practice Deficiency Correction” Program when =>% from the Final Findings Brief?
5 Business Day or by a date determined by the Lead Assessor, not to exceed 5 calendar days.
What score is required to allow an OSC to POA&M items?
80%, or 88/110 for practices Met.
How long after the Final Findings Briefing does the Assessment Team have to submit the Final Reports to the CQAP?
10 Business Days
How long after the Final Findings Brief must the final reports be uploaded to eMASS?
No later than 20 business days.
What are details for a Level 1 Assessment?
Considered a Foundational Assessment, and address 17 practices.
What are the details for a Level 2 Assessment?
Considered an Advanced assessment, and addresses 110 practices.
What are the details for a Level 3 Assessment?
Considered an Expert assessment, and addresses 110 practices in 800-171, and additional practices listed in 800-172.
What 6 Domains are covered in a Foundation Assessment?
A Foundation, Level 1 Assessment, covers the following Cybersecurity Domains:
- Access Control (AC)
- Identification and Authentication (IA)
- Media Protection (MP)
- Physical Protection (PE)
- Systems and Communication Protections (SC)
- System and Information Integrity (SI)
How many domains are covered in an Advanced Assessment, and what are they?
Fourteen (14) Domains in a Level 2, Advanced, Assessment:
- Access Control
- Awareness and Training
- Audit and Accountability
- Identification and Authentication
- Configuration Management
- Incident Response
- Maintenance
- Media Protection
- Personnel Security
- Physical Security
- Risk Assessment
- Security Assessment
- Systems and Communication Protection (SC)
- Systems and Information Integrity (SI)