Glossary Flashcards
CUI Asset
Anything or anyone that processes, stores, or transmits CUI.
Security Protection Asset (SPA)
Anything or anyone that provides protections to the CUI assets
Contractor Risk Managed Asset (CRMA)
Anything or anyone that CAN access (touch, reach, see) CUI but are not authorized.
Specialized Asset
This is generally IoT, OT or test equipment
Out of Scope Asset
Anything or anyone that can’t access (touch, reach, see) CUI
People
Any human
Technology
Every device (CSP, VPN, router, printer, workstation, etc.)
Facility
Any place that hosts the above
Organization
An entity of any size, complexity, or positioning within an organizational structure (e.g. a federal agency, or, as appropriate any of its operational elements).
Headquarters (HQ) Organization is the legal entity that will deliver services or products under the terms of a DoD contract. The HQ Organization could be the OSC or it could designate a Host Unit as the OSC.
Process
A procedural activity that is performed to implement a defined objective.
Out-of-Scope Asset
Out-of-scope assets cannot process, store, or transmit CUI because they are physically or logically separated from CUI Assets or are inherently unable to do so.
Specialized Assets
The following are considered specialized assets for CMMC: Government Property, Internet of Things (IoT) or Industrial Internet of Things (IIoT), Operational Technology (OT) and Restricted Information Systems.
Government Property
All property owned or leased by the Government. Government property includes both government-furnished and contractor-acquired property. Government property includes material, equipment, special tooling, special test equipment, and real property. Government property does not include intellectual property or software.
Internet of Things (IoT)
Interconnected devices having physical or virtual representation in the digital world, sensing/actuation capability, and programmability features. They are uniquely identifiable and may include smart electric grids, lighting, heating air conditioning, and fire and smoke detectors.
Operational Technology (OT)
Hardware and software that detects or causes a change through the direct monitoring and/or control of physical devices, processes, and events in the enterprise.