Podcast
Questions and Answers
What must the HQ Organization or Host Unit possess for the Assessment to proceed?
What must the HQ Organization or Host Unit possess for the Assessment to proceed?
- A Unique Entity Identifier (UEI)
- A Business License
- An Assessment Completion Certificate
- A Commercial and Government Entity (CAGE) code (correct)
Which of the following must the HQ Organization or Host Unit register with?
Which of the following must the HQ Organization or Host Unit register with?
- Federal Procurement Data System
- Department of Defense Supplier Registry
- National Institute of Standards and Technology
- General Services Administration’s GSA SAM.gov system (correct)
Which statement is true regarding small and medium-sized businesses and their corporate architecture?
Which statement is true regarding small and medium-sized businesses and their corporate architecture?
- They require a CAGE code for each subsidiary.
- They must outsource most functions to Supporting Organizations.
- They generally do not delineate a Host Unit. (correct)
- They always have a multi-level corporate structure.
What role does All-American Cloud Services, Inc. play in the context of the OSC?
What role does All-American Cloud Services, Inc. play in the context of the OSC?
What is the specified body typeface according to the CMMC Assessment Process documentation?
What is the specified body typeface according to the CMMC Assessment Process documentation?
Which font size is designated for body text in the CMMC Assessment documentation?
Which font size is designated for body text in the CMMC Assessment documentation?
What is the font style used for table headings in the CMMC Assessment documentation?
What is the font style used for table headings in the CMMC Assessment documentation?
Which of the following terms is capitalized and defined in the CMMC Assessment documentation?
Which of the following terms is capitalized and defined in the CMMC Assessment documentation?
What auxiliary verb of compulsion is used to denote a requirement in the CMMC documentation?
What auxiliary verb of compulsion is used to denote a requirement in the CMMC documentation?
In which phase of the CMMC Assessment is planning and preparation emphasized?
In which phase of the CMMC Assessment is planning and preparation emphasized?
How is the effectiveness of the CMMC Certification Assessment determined?
How is the effectiveness of the CMMC Certification Assessment determined?
What is the ultimate goal of Phase I in the CMMC Assessment process?
What is the ultimate goal of Phase I in the CMMC Assessment process?
What is one of the primary roles of the Lead Assessor during interviews?
What is one of the primary roles of the Lead Assessor during interviews?
Why might interviews be considered an iterative activity during the assessment process?
Why might interviews be considered an iterative activity during the assessment process?
What is significant about mapping responses from interviewees to CMMC model practices?
What is significant about mapping responses from interviewees to CMMC model practices?
During interviews, what is the primary reason for asking clarifying questions?
During interviews, what is the primary reason for asking clarifying questions?
What does observing live tests provide for the Lead Assessor and Assessment Team?
What does observing live tests provide for the Lead Assessor and Assessment Team?
What might influence the decision of the Lead Assessor on whether to conduct single or group interviews?
What might influence the decision of the Lead Assessor on whether to conduct single or group interviews?
What should be recorded after conducting interviews according to best practices?
What should be recorded after conducting interviews according to best practices?
Which of the following is a key component of the interview process for CMMC assessments?
Which of the following is a key component of the interview process for CMMC assessments?
What is the purpose of the CMMC Confirmation of Destruction of OSC Data template?
What is the purpose of the CMMC Confirmation of Destruction of OSC Data template?
Which CMMC assessment template is marked as mandatory?
Which CMMC assessment template is marked as mandatory?
Which format is used for the CMMC Assessment Results Form?
Which format is used for the CMMC Assessment Results Form?
What is the function of the CMMC Assessment Appeals Process document?
What is the function of the CMMC Assessment Appeals Process document?
In which phase is the Limited Practice Deficiency Correction Program Worksheet mandatory?
In which phase is the Limited Practice Deficiency Correction Program Worksheet mandatory?
Which document format is used for the CMMC Assessment Quality Review Checklist?
Which document format is used for the CMMC Assessment Quality Review Checklist?
What is the primary requirement for C3PAOs and their Assessment Team Members concerning available templates?
What is the primary requirement for C3PAOs and their Assessment Team Members concerning available templates?
How is the CMMC Assessment In-Brief formatted?
How is the CMMC Assessment In-Brief formatted?
During which phase is the CMMC Assessment Findings Briefing required?
During which phase is the CMMC Assessment Findings Briefing required?
What type of document is the OSC Self-Assessment Practice Deficiency Tracker?
What type of document is the OSC Self-Assessment Practice Deficiency Tracker?
What is one implication of the Evidence collection approach on the Assessment process?
What is one implication of the Evidence collection approach on the Assessment process?
During which phase must the Evidence collection approach record virtual data collection techniques?
During which phase must the Evidence collection approach record virtual data collection techniques?
Which of the following must always be observed in person, according to the Evidence collection guidelines?
Which of the following must always be observed in person, according to the Evidence collection guidelines?
What type of information must be managed and protected during Phase 1?
What type of information must be managed and protected during Phase 1?
What decision does the OSC have concerning the Evidence collection activities?
What decision does the OSC have concerning the Evidence collection activities?
What is the primary purpose of Phase 2 in the CMMC Assessment Process?
What is the primary purpose of Phase 2 in the CMMC Assessment Process?
What is a requirement for conducting affirmation sessions during Phase 2?
What is a requirement for conducting affirmation sessions during Phase 2?
Who convenes the Assessment kickoff meeting?
Who convenes the Assessment kickoff meeting?
Which practice objective must be marked with applicable CUI markings?
Which practice objective must be marked with applicable CUI markings?
Which of the following is NOT typically included in the attendees of the Assessment kickoff meeting?
Which of the following is NOT typically included in the attendees of the Assessment kickoff meeting?
What technology can be utilized for virtual Evidence collection?
What technology can be utilized for virtual Evidence collection?
What role does the OSC Assessment Official play during the Assessment?
What role does the OSC Assessment Official play during the Assessment?
What type of information does the Lead Assessor communicate during the kickoff meeting?
What type of information does the Lead Assessor communicate during the kickoff meeting?
What does the Assessment Team aim to identify during the implementation phase?
What does the Assessment Team aim to identify during the implementation phase?
Which statement best characterizes the activities throughout Phase 2?
Which statement best characterizes the activities throughout Phase 2?
How might the Assessment kickoff meeting be conducted?
How might the Assessment kickoff meeting be conducted?
Flashcards
Phase 1 - Plan and Prepare the Assessment
Phase 1 - Plan and Prepare the Assessment
The initial phase of a CMMC Certification Assessment that focuses on planning, preparation, and laying the foundation for a successful assessment.
CMMC Third-Party Assessment Organizations (C3PAOs)
CMMC Third-Party Assessment Organizations (C3PAOs)
A third-party organization authorized to conduct CMMC assessments.
Organizations Seeking Certification (OSCs)
Organizations Seeking Certification (OSCs)
An organization actively seeking to achieve CMMC certification.
Host Unit
Host Unit
Signup and view all the flashcards
Headquarters Unit
Headquarters Unit
Signup and view all the flashcards
Lead Assessor
Lead Assessor
Signup and view all the flashcards
Supporting Organization
Supporting Organization
Signup and view all the flashcards
Why are all activities in Phase I important
Why are all activities in Phase I important
Signup and view all the flashcards
Confirmation of Destruction of OSC Data
Confirmation of Destruction of OSC Data
Signup and view all the flashcards
Confirmation of Destruction of OSC Data
Confirmation of Destruction of OSC Data
Signup and view all the flashcards
OSC Self-Assessment Practice Deficiency Tracker
OSC Self-Assessment Practice Deficiency Tracker
Signup and view all the flashcards
CMMC Scoring with DoD Assessment Scoring Methodology
CMMC Scoring with DoD Assessment Scoring Methodology
Signup and view all the flashcards
CMMC Assessor Waiver Process
CMMC Assessor Waiver Process
Signup and view all the flashcards
CMMC Assessment Appeals Process
CMMC Assessment Appeals Process
Signup and view all the flashcards
CMMC Assessment Evidence Collection Approaches
CMMC Assessment Evidence Collection Approaches
Signup and view all the flashcards
Virtual Assessment Evidence Preparation Template
Virtual Assessment Evidence Preparation Template
Signup and view all the flashcards
CMMC Assessment Readiness Review (CA-RR) Checklist
CMMC Assessment Readiness Review (CA-RR) Checklist
Signup and view all the flashcards
CMMC Assessment Results Form
CMMC Assessment Results Form
Signup and view all the flashcards
Headquarters (HQ) Organization
Headquarters (HQ) Organization
Signup and view all the flashcards
CAGE Code
CAGE Code
Signup and view all the flashcards
SAM.gov Registration and Unique Entity Identifier (UEI)
SAM.gov Registration and Unique Entity Identifier (UEI)
Signup and view all the flashcards
Evidence Collection Approach
Evidence Collection Approach
Signup and view all the flashcards
Virtual Evidence Collection
Virtual Evidence Collection
Signup and view all the flashcards
On-premises Evidence Collection
On-premises Evidence Collection
Signup and view all the flashcards
OSC's Decision on Evidence Collection
OSC's Decision on Evidence Collection
Signup and view all the flashcards
In-person Validation Requirements
In-person Validation Requirements
Signup and view all the flashcards
Examples of In-person Validation Requirements
Examples of In-person Validation Requirements
Signup and view all the flashcards
Impact of Evidence Collection Approach
Impact of Evidence Collection Approach
Signup and view all the flashcards
Accuracy of Assessment Results
Accuracy of Assessment Results
Signup and view all the flashcards
Assessment Kickoff Meeting
Assessment Kickoff Meeting
Signup and view all the flashcards
OSC Point of Contact (OSC POC)
OSC Point of Contact (OSC POC)
Signup and view all the flashcards
Assessment In-Brief
Assessment In-Brief
Signup and view all the flashcards
Contractual Agreement
Contractual Agreement
Signup and view all the flashcards
OSC Assessment Official
OSC Assessment Official
Signup and view all the flashcards
OSC RP or RPO
OSC RP or RPO
Signup and view all the flashcards
Evidence
Evidence
Signup and view all the flashcards
Interviewing for CMMC Compliance
Interviewing for CMMC Compliance
Signup and view all the flashcards
Assuring Interview Confidentiality
Assuring Interview Confidentiality
Signup and view all the flashcards
Mapping Interview Responses to CMMC Practices
Mapping Interview Responses to CMMC Practices
Signup and view all the flashcards
Observing Tests and Demonstrations for CMMC
Observing Tests and Demonstrations for CMMC
Signup and view all the flashcards
Analyzing Test and Demonstration Results
Analyzing Test and Demonstration Results
Signup and view all the flashcards
Recording Interviews During Daily Checkpoints
Recording Interviews During Daily Checkpoints
Signup and view all the flashcards
Iterative Nature of Interviews in CMMC Assessments
Iterative Nature of Interviews in CMMC Assessments
Signup and view all the flashcards
Documenting Findings from Interviews and Demonstrations
Documenting Findings from Interviews and Demonstrations
Signup and view all the flashcards
Study Notes
CMMC Assessment Process (CAP)
- Cybersecurity Maturity Model Certification (CMMC) Assessment Process (CAP) version 5.6.1, dated August 5, 2022
- Authorized for Training Providers and their respective training candidates
- For use in training and exam preparation for Certified CMMC Professional (CCP) and Certified CMMC Assessor (CCA) programs related to the DoD CMMC Framework V2.0 only
- This document has not yet been endorsed by the Department of Defense for use in authorized CMMC certification assessments
Table of Contents
- Includes a detailed table of contents listing sections and subsections. The document covers multiple phases of the assessment process from planning to reporting.
- References appendices with specific templates for data input, documentation, and other requirements
Disclaimer
- Copyright 2022, Cybersecurity Maturity Model Accreditation Body, Inc. (d/b/a The Cyber AB)
- Proprietary and confidential; not to be shared without explicit permission
- Material does not constitute official U.S. Government policy, unless otherwise stated in other documentation
- No warranties; furnished on an "as-is" basis
Introduction to the CMMC Assessment Process (CAP)
- CMMC framework is the DoD's standard for implementing cybersecurity measures within the Defense Industrial Base (DIB)
- Grounded in NIST Special Publication 800-171
- CMMC Assessment Guides (published by DoD) provide detailed objectives, criteria, and guidelines for assessment
- CMMC Assessment Process (CAP) is the overarching process and guidance for assessments.
- This version of the CAP applies to Level 2 (L2) of the CMMC Model only
- It's intended for use by C3PAOs (Certified Third-Party Assessment Organizations), Certified CMMC Assessors, and Certified CMMC Professionals
- The CAP is organized into four phases: Plan and Prepare the Assessment, Conduct the Assessment, Report Assessment Results, and Close-Out POA&Ms and Assessment.
Phase 1 - Plan and Prepare the Assessment
- The recipient OSC (Organization Seeking Certification) initiates the assessment.
- The C3PAO (CMMC Third-Party Assessment Organization) acknowledges and proposes a scheduling timeframe.
- This phase includes establishing roles, responsibilities, organizing documents/templates, confirming corporate identity, validating scope, inventorying, managing conflicts of interest, preparing for evidence collection, and verifying readiness for assessment.
Phase 2 - Conduct the Assessment
- Organizations will convene a kickoff meeting.
- Assessment team gathers and examines evidence.
- Interviews and reviews documentation for effective procedures
- Identify any evidence gaps between OSC’s implementation and CMMC requirements
- Scores and validates preliminary findings and documents procedures followed during assessment.
- Correct any limited practice deficiencies
Phase 3 - Report Recommended Assessment Results
- Delivers recommended assessment results to the OSC.
- Includes submission, packaging, and archiving of documentation into CMMC EMASS.
- This document provides links to templates used as part of the assessment
- This phase includes a Quality Assurance review of all deliverables before uploading them into CMMC EMASS
Phase 4 - Close-Out POA&Ms and Assessment
- Allows the OSC to close out POA&Ms (Plan of Action and Milestones).
- This includes determining if the OSC has corrected all deficiencies within a 180-day timeframe or requires a reassessment.
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.
Related Documents
Description
Test your knowledge on the Cybersecurity Maturity Model Certification (CMMC) Assessment Process. This quiz covers eligibility, organizational requirements, documentation specifics, and key terms associated with the CMMC. Enhance your understanding of this important cybersecurity framework.