Onboarding Flashcards

1
Q

CUI

A

Controlled Unclassified Information

an umbrella term that encompasses all CDI and Controlled Technical Information (CTI)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

CDI

A

Covered Defense Information
technical information with a military or space application that is marked with a distribution statement in accordance with DoDI 5230.24

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

CTI

A

Controlled Technical Information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Who identifies a piece of information as CTI?

A

Both parties (DoD and contractor) share the responsibility to a certain extent.statements of work are in place and distribution statements are assigned to each piece of content

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Why am I required to protect CUI/CDI/CTI as a defense contractor?

A

bad actors (hostile states, individuals, and corporations) are trying to get it and if they succeed it could hurt individuals, organizations, or our national security; can result in a rapid loss of a contract

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Who identifies a piece of information as CTI?

A

Both parties (DoD and contractor) share the responsibility to an extent. While the DoD company is responsible for properly labeling a piece of info, both parties work on–> statements of work are in place and distribution statements are assigned to each piece of content

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Is there a way to search if a piece of info should/shouldn’t be CUI?

A

Yes, it can be searched in the CUI Registry to find this out. There are 24 Categories of content and 83 sub categories of content! Each category is defined as either CUI Basic or CUI Specified.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is ITAR?

A

International Traffic in Arms Regulations; it’s a CUI Specified data type

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

If a piece of CUI or ITAR information is suspected of being accessed by unauthorized parties, where should a contractor report this?

A

After reporting the incident to the contracting officer, they should file a report with BOTH Dibnet and DDTS within the first 72 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

DoD contractors may only utilize a cloud storage system if t is certified to what standard?

A

FedRAMP moderate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is DFARS

A

the government regulation for DoD acquisition

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Whats does the DFARS 7012 clause cover and why is it so important?

A

(Safeguarding Covered Defense Information and Cyber incident reporting)It specifically relates to securing information systems for contractors supporting the Department of Defense

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

DFARS

A

Defense Federal Acquisition Regulation Supplement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is NIST?

A

The National Institute of Standards and Technology is the United States agency tasked to advance measurement science, standards and technology in ways that enhance the economic security and improve quality of life.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

NIST’s Special Publication 800-171 was titled

A

“Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is NIST 800-171?

A

a comprehensive set (109 total) of requirements; a guideline for non-federal organizations that must securely process CUI content, within internal and external information systems, in support of federal activities.

17
Q

SSP

A

System Security Plan

18
Q

POA & M

A

Plan of Action & Milestones

19
Q

How does CMMC contrast DFARS 7012

A

it forces the requirement before award, or ‘award-time’.

20
Q

The CMMC requirements are broken down by…

A

Domains/Capabilities and then each Practice and Process within them is designated by level.

21
Q

CMMC primarily leans on…

A

NIST 800-171

22
Q

CMMC AB

A

CMMC Accreditation Body (12 people overseeing the training, quality, and administration of the third-party assessment organizations)

23
Q

What is SSP?

A

the collective details of a business’ security posture and system(s) profile

24
Q

What is POA & M?

A

it includes information about weaknesses and gaps according to NIST 800-171 standards, as well as the risk posture for each respective gap and any mitigating steps the company intends to make.

25
Q

What is a ‘complete’ SSP?

A

a working and living document

26
Q

What is a ‘complete’ POA & M?

A

an empty document once you configure Office 365 and your other systems properly.

27
Q

three primary components required for DFARS compliance:

A
  1. To Provide Adequate Security to a System holding CUI/CDI content via configuration to NIST 800-171 and FedRAMP Moderate
  2. To provide Incident Reporting within 72 hours of a suspected incident
  3. To flow down all contract clauses to sub contractors
28
Q

DIB

A

Defense Industrial Base

29
Q

SPRS

A

Supplier Performance Risk System

30
Q

DCMA

A

The Defense Contract Management Agency

31
Q

FCI

A

Federal Contract Information (not intended for release to the public)

32
Q

When did NIST 800-171 go into effect?

A

December ‘17

33
Q

DLP

A

Data Loss Prevention