CMMC Scoping & Process Flashcards

1
Q

FCI Asset

A

Any devices that stores, processes, or has access to FCI.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

CUI Asset

A

Any device that stores, processes, or has access to CUI.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Out-of-Scope Asset

A

Any device that does not have access to CUI, or FCI.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 5 categories of Special Assets?

A
  1. Government Equipment
  2. IoT and Industrial IoT
  3. Operation Technology (OT)
  4. Restricted Information Systems
  5. Test Equipment
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a Special Asset - Restricted Information System?

A

An information system or component essential to servicing a contract, such as a dev network. The OSC must clearly articulate how and why the asset is an SA and OoS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How long does a C3PAO have to respond during Phase 1?

A

5 Business Days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How long does the OSC have to correct items in the ‘Limited Practice Deficiency Correction” Program when =>% from the Final Findings Brief?

A

5 Business Day or by a date determined by the Lead Assessor, not to exceed 5 calendar days.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What score is required to allow an OSC to POA&M items?

A

80%, or 88/110 for practices Met.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How long after the Final Findings Briefing does the Assessment Team have to submit the Final Reports to the CQAP?

A

10 Business Days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How long after the Final Findings Brief must the final reports be uploaded to eMASS?

A

No later than 20 business days.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are details for a Level 1 Assessment?

A

Considered a Foundational Assessment, and address 17 practices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the details for a Level 2 Assessment?

A

Considered an Advanced assessment, and addresses 110 practices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the details for a Level 3 Assessment?

A

Considered an Expert assessment, and addresses 110 practices in 800-171, and additional practices listed in 800-172.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What 6 Domains are covered in a Foundation Assessment?

A

A Foundation, Level 1 Assessment, covers the following Cybersecurity Domains:

  1. Access Control (AC)
  2. Identification and Authentication (IA)
  3. Media Protection (MP)
  4. Physical Protection (PE)
  5. Systems and Communication Protections (SC)
  6. System and Information Integrity (SI)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How many domains are covered in an Advanced Assessment, and what are they?

A

Fourteen (14) Domains in a Level 2, Advanced, Assessment:

  1. Access Control
  2. Awareness and Training
  3. Audit and Accountability
  4. Identification and Authentication
  5. Configuration Management
  6. Incident Response
  7. Maintenance
  8. Media Protection
  9. Personnel Security
  10. Physical Security
  11. Risk Assessment
  12. Security Assessment
  13. Systems and Communication Protection (SC)
  14. Systems and Information Integrity (SI)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the four (4) phases of a CMMC assessment?

A

Phase 1 - Plan and Prepare
Phase 2 - Conducting Assessment
Phase 3 - Reporting
Phase 4 - Close-out POAM and Assessment

17
Q

What items are needed for Phase 1?

A
  1. A list of Evidence (Inventory)
    • Provided to C3PAO for each obj.
    • Ensure evidence is sufficient and adequate
  2. Scope Agreement between OSC and C3PAO
    • ensure the scope is thoroughly communicated and understood.
18
Q

What are some key points for Phase 2?

A

3 methods - Examine, Test, Interview

Examine is the #1 way to review evidence (usually one piece per objective)

19
Q

What are some key points for Phase 3?

A

Fully Implemented = All items found correct

Any item with a deficiency is NOT MET

20
Q

What is the LDPC?

A

Limited Practice Deficiency Program, which may be available for deficient practices worth one point. The overall assessment score must be 80% (88/110) or higher to be allowed a 180-day POAM option.

21
Q

What is a CRMA?

A

Contractor Risk Managed Asset - which is a device that can but does not touch CUI. It is not assessed.

22
Q

What is Assessment Framing?

A

The process of identifying the size, scale, date, time, place, manner, resources, and level of effort for a prospective CMMC assessment.

23
Q

What needs to be discussed during Assessment Framing?

A
  • Locations
  • ID OSC Staff who will provide evidence
  • Scope
  • Relevant Documentation, roles and responsibilities of IT and infosec staff
  • Evidence
  • A Rough Order-of-Magnitude (ROM) estimate for approx. duration and timing for the assessment
  • Assessment outputs for the OSC Assessment Official
  • Lead Assessor and OSC POC validate OSC Self-Assessment Practice Deficiency Items
24
Q
A