Lesson 6 Definitions Flashcards
Organizational culture
A set of values and ideas that reflect acceptable and unacceptable practices and behaviors within an organization
Cybersecurity culture
The combined organizational factors that put every employee in the position to behave in ways that support cybersecurity or ways that place the company at risk
Institutionalization
The action of establishing something as a convention or norm in an organization or culture
Governance
The policies, procedures and controls that are utilized by the OSC to assure sustainment and continual improvement with respect to detection, prevention, and response to cyber incidents
Policy
An artifact or collection of artifacts that establishes governance over the implementation of CMMC practices and activities
Procedure
The documented details for how an activity is implemented to achieve a desired outcome. A procedure should provide enough detail for a trained individual to perform the activity.
Plan
An artifact or collection of artifacts that provide oversight for implementing defined CMMC policies
Gap Analysis
An evaluation that examines the organization’s processes ‘as performed’ to identify issues, impediments, and potential risks to sustained implementation
Evidence Validation
An evaluation that examines sufficiency of evidence presented by the OSC, ensuring it meets the intent and objectives of the control or practice
Certification Assessment Readiness Review (CA-RR)
A preliminary but formal review to verify the OSC’s readiness for the Assessment against the identified Assessment planning parameters and Assessment scope