<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://cmmcwiki.org/index.php?action=history&amp;feed=atom&amp;title=LLMResponse_AC.L2-3.1.4.a</id>
	<title>LLMResponse AC.L2-3.1.4.a - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://cmmcwiki.org/index.php?action=history&amp;feed=atom&amp;title=LLMResponse_AC.L2-3.1.4.a"/>
	<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=LLMResponse_AC.L2-3.1.4.a&amp;action=history"/>
	<updated>2026-05-31T11:46:23Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.8</generator>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=LLMResponse_AC.L2-3.1.4.a&amp;diff=1568&amp;oldid=prev</id>
		<title>David: Created page with &quot;Ranking Evidence Types for Assessment Objective [a]  For the assessment objective &quot;[a] the duties of individuals requiring separation are defined,&quot; I&#039;ll rank the evidence types supported by assessment objects from most to least valuable:  == Evidence Type Ranking ==  1. **Documents (highest value)**    - Access control policy documents    - Written procedures addressing divisions of responsibility and separation of duties    - System security plan with defined separation...&quot;</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=LLMResponse_AC.L2-3.1.4.a&amp;diff=1568&amp;oldid=prev"/>
		<updated>2025-04-30T02:29:31Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;Ranking Evidence Types for Assessment Objective [a]  For the assessment objective &amp;quot;[a] the duties of individuals requiring separation are defined,&amp;quot; I&amp;#039;ll rank the evidence types supported by assessment objects from most to least valuable:  == Evidence Type Ranking ==  1. **Documents (highest value)**    - Access control policy documents    - Written procedures addressing divisions of responsibility and separation of duties    - System security plan with defined separation...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Ranking Evidence Types for Assessment Objective [a]&lt;br /&gt;
&lt;br /&gt;
For the assessment objective &amp;quot;[a] the duties of individuals requiring separation are defined,&amp;quot; I&amp;#039;ll rank the evidence types supported by assessment objects from most to least valuable:&lt;br /&gt;
&lt;br /&gt;
== Evidence Type Ranking ==&lt;br /&gt;
&lt;br /&gt;
1. **Documents (highest value)**&lt;br /&gt;
   - Access control policy documents&lt;br /&gt;
   - Written procedures addressing divisions of responsibility and separation of duties&lt;br /&gt;
   - System security plan with defined separation requirements&lt;br /&gt;
   - List of divisions of responsibility and separation of duties&lt;br /&gt;
   - Job descriptions that specify segregated duties&lt;br /&gt;
&lt;br /&gt;
2. **Artifacts**&lt;br /&gt;
   - System configuration settings showing role separations&lt;br /&gt;
   - Role matrices showing incompatible functions&lt;br /&gt;
   - Access control lists demonstrating separation implementation&lt;br /&gt;
   - Organizational charts showing functional separation&lt;br /&gt;
&lt;br /&gt;
3. **Physical Review**&lt;br /&gt;
   - On-site verification of physical access controls supporting separation&lt;br /&gt;
   - Observation of work areas arranged to support separation&lt;br /&gt;
&lt;br /&gt;
4. **Screen Share (lowest value)**&lt;br /&gt;
   - Demonstration of access control systems showing separation enforcement&lt;br /&gt;
   - Viewing system configurations that implement separation&lt;br /&gt;
&lt;br /&gt;
== Assessment Approach Prioritization ==&lt;br /&gt;
&lt;br /&gt;
I recommend prioritizing the three assessment approaches as follows:&lt;br /&gt;
&lt;br /&gt;
1. **Examine (highest priority)**&lt;br /&gt;
   - Start by examining documentation that explicitly defines which duties require separation&lt;br /&gt;
   - This provides the foundation for understanding how separation of duties is conceptualized in your organization&lt;br /&gt;
   - Focus on formal policies, procedures, and system security plans&lt;br /&gt;
&lt;br /&gt;
2. **Interview**&lt;br /&gt;
   - After examining documents, interview personnel with responsibilities for defining divisions of responsibility&lt;br /&gt;
   - Interview security personnel and system administrators to verify understanding&lt;br /&gt;
   - These interviews validate that the documented definitions are understood and followed&lt;br /&gt;
&lt;br /&gt;
3. **Test (supplementary)**&lt;br /&gt;
   - Finally, test mechanisms implementing separation of duties&lt;br /&gt;
   - This confirms that technical controls enforce the defined separations&lt;br /&gt;
   - Testing serves as verification of actual implementation rather than primary evidence&lt;br /&gt;
&lt;br /&gt;
This prioritization follows a logical progression: first understand what&amp;#039;s defined, then verify understanding through interviews, and finally confirm implementation through testing.&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
</feed>