<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://cmmcwiki.org/index.php?action=history&amp;feed=atom&amp;title=LLMResponse_AC.L2-3.1.1.c</id>
	<title>LLMResponse AC.L2-3.1.1.c - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://cmmcwiki.org/index.php?action=history&amp;feed=atom&amp;title=LLMResponse_AC.L2-3.1.1.c"/>
	<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=LLMResponse_AC.L2-3.1.1.c&amp;action=history"/>
	<updated>2026-06-21T07:17:51Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.8</generator>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=LLMResponse_AC.L2-3.1.1.c&amp;diff=1267&amp;oldid=prev</id>
		<title>David: Created page with &quot;== Evidence Types and Assessment Approaches for AC.L2-3.1.1 Assessment Objective [c] ==  === Ranking of Evidence Types for Assessment Objective [c] ===  For the assessment objective &quot;[c] devices (and other systems) authorized to connect to the system are identified,&quot; I recommend prioritizing evidence types in this order:  1. **Artifacts**: These provide the strongest evidence for this objective, including:    - Network device inventories and asset management databases...&quot;</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=LLMResponse_AC.L2-3.1.1.c&amp;diff=1267&amp;oldid=prev"/>
		<updated>2025-03-28T04:45:39Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;== Evidence Types and Assessment Approaches for AC.L2-3.1.1 Assessment Objective [c] ==  === Ranking of Evidence Types for Assessment Objective [c] ===  For the assessment objective &amp;quot;[c] devices (and other systems) authorized to connect to the system are identified,&amp;quot; I recommend prioritizing evidence types in this order:  1. **Artifacts**: These provide the strongest evidence for this objective, including:    - Network device inventories and asset management databases...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== Evidence Types and Assessment Approaches for AC.L2-3.1.1 Assessment Objective [c] ==&lt;br /&gt;
&lt;br /&gt;
=== Ranking of Evidence Types for Assessment Objective [c] ===&lt;br /&gt;
&lt;br /&gt;
For the assessment objective &amp;quot;[c] devices (and other systems) authorized to connect to the system are identified,&amp;quot; I recommend prioritizing evidence types in this order:&lt;br /&gt;
&lt;br /&gt;
1. **Artifacts**: These provide the strongest evidence for this objective, including:&lt;br /&gt;
   - Network device inventories and asset management databases&lt;br /&gt;
   - Network access control (NAC) system records&lt;br /&gt;
   - DHCP server leases and reservations&lt;br /&gt;
   - Network diagrams showing authorized connections&lt;br /&gt;
   - MAC address whitelists and device registration records&lt;br /&gt;
&lt;br /&gt;
2. **Documents**: Supporting formal documentation including:&lt;br /&gt;
   - Device authorization policies and procedures&lt;br /&gt;
   - Network connection approval forms&lt;br /&gt;
   - System security plans describing device connection requirements&lt;br /&gt;
   - Network architecture documentation&lt;br /&gt;
   - Authorized device lists with ownership information&lt;br /&gt;
&lt;br /&gt;
3. **Screen Share**: Observing real-time demonstrations of:&lt;br /&gt;
   - Network management systems showing connected devices&lt;br /&gt;
   - Device registration processes&lt;br /&gt;
   - Network monitoring dashboards&lt;br /&gt;
   - Configuration of device authentication mechanisms&lt;br /&gt;
&lt;br /&gt;
4. **Physical Review**: On-site examination to verify:&lt;br /&gt;
   - Physical network infrastructure&lt;br /&gt;
   - Device identification labels&lt;br /&gt;
   - Physical access to network connection points&lt;br /&gt;
   - Network equipment configurations&lt;br /&gt;
&lt;br /&gt;
=== Prioritizing Assessment Approaches ===&lt;br /&gt;
&lt;br /&gt;
For assessment objective [c], I recommend prioritizing the three assessment approaches as follows:&lt;br /&gt;
&lt;br /&gt;
1. **Examine**: This should be your primary approach for this device-focused objective:&lt;br /&gt;
   - Review lists of devices and systems authorized to connect to organizational systems&lt;br /&gt;
   - Examine network device inventories and registration records&lt;br /&gt;
   - Review network diagrams showing permitted connections&lt;br /&gt;
   - Check device authentication and authorization procedures&lt;br /&gt;
   - Examine network access control configurations&lt;br /&gt;
&lt;br /&gt;
2. **Test**: Perform technical validation:&lt;br /&gt;
   - Test network access control mechanisms to verify unauthorized devices cannot connect&lt;br /&gt;
   - Observe device registration and authorization processes&lt;br /&gt;
   - Verify that network monitoring systems accurately identify connected devices&lt;br /&gt;
   - Confirm that device authentication methods work as documented&lt;br /&gt;
&lt;br /&gt;
3. **Interview**: Complete your assessment with supporting interviews:&lt;br /&gt;
   - Speak with network administrators about device authorization procedures&lt;br /&gt;
   - Interview IT staff responsible for network access management&lt;br /&gt;
   - Discuss device connection policies with security personnel&lt;br /&gt;
   - Query system administrators about how they identify and track authorized devices&lt;br /&gt;
&lt;br /&gt;
This prioritization recognizes that device authorization is fundamentally a documented and technically-enforced control, where examination of records and technical testing provide the most direct evidence that devices authorized to connect to the system are properly identified and tracked.&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
</feed>