Regulations Flashcards

Regulations

1
Q

32 CFR Part 170

A

Formalizes the CMMC program rules for protecting FCI and CUI.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

48 CFR Part 204

A

Defines DFARS rules that incorporate cybersecurity standards into DoD contracts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

48 CFR Part 3.502-1

A

Clarifies how CMMC requirements flow down to subcontractors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

1 CFR Part 51

A

Governs the incorporation of external standards, like NIST SP 800-171, into federal law.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

32 CFR Part 2002

A

Establishes rules for protecting Controlled Unclassified Information (CUI) in federal and nonfederal systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

FAR Clause 52.204-21

A

Outlines 15 basic safeguarding controls for protecting Federal Contract Information (FCI).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

DFARS Clause 252.204-7012

A

Requires contractors to safeguard CUI and report cyber incidents to the DoD; mandates NIST SP 800-171 compliance for Level 2.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

5 U.S.C. 301

A

Gives authority to department heads to establish regulations such as the CMMC program.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Public Law 116-92, Section 1648 (NDAA for FY 2020)

A

Directs the DoD to create a cybersecurity framework for the Defense Industrial Base (DIB).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Congressional Review Act (5 U.S.C. 801 et seq.)

A

Requires economically significant rules like CMMC to be submitted to Congress before taking effect.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Executive Orders 12866 and 13563

A

Directs agencies to assess the costs and benefits of regulations like CMMC to ensure maximum net benefits.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

NIST SP 800-171 R2

A

Provides 110 security controls for protecting CUI in nonfederal systems, forming the foundation for CMMC Level 2.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

NIST SP 800-172

A

Provides additional security controls for protecting highly sensitive CUI, forming the foundation for CMMC Level 3.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

NIST SP 800-171A

A

Provides guidelines for assessing the controls in NIST SP 800-171 for compliance with CMMC Level 2 and 3.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

ISO/IEC 17011:2017

A

Specifies requirements for bodies providing accreditation, like the CMMC Accreditation Body.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

ISO/IEC 17024:2012

A

Governs the certification process for individuals like CMMC Certified Professionals and Assessors.

17
Q

Section 1648 of the NDAA for FY 2020

A

Directs the creation of the CMMC program to improve cybersecurity across the defense industrial base.