<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://cmmcwiki.org/index.php?action=history&amp;feed=atom&amp;title=LLMResponse_AC.L2-3.1.4.b</id>
	<title>LLMResponse AC.L2-3.1.4.b - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://cmmcwiki.org/index.php?action=history&amp;feed=atom&amp;title=LLMResponse_AC.L2-3.1.4.b"/>
	<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=LLMResponse_AC.L2-3.1.4.b&amp;action=history"/>
	<updated>2026-05-31T11:46:24Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.8</generator>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=LLMResponse_AC.L2-3.1.4.b&amp;diff=1569&amp;oldid=prev</id>
		<title>David: Created page with &quot;Ranking Evidence Types for Assessment Objective [b]  For the assessment objective &quot;[b] responsibilities for duties that require separation are assigned to separate individuals,&quot; here&#039;s the ranking of evidence types supported by assessment objects:  == Evidence Type Ranking ==  1. **Artifacts (highest value)**    - User account listings with role assignments    - System access authorizations showing different individuals assigned to separated duties    - Access control ma...&quot;</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=LLMResponse_AC.L2-3.1.4.b&amp;diff=1569&amp;oldid=prev"/>
		<updated>2025-04-30T02:30:40Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;Ranking Evidence Types for Assessment Objective [b]  For the assessment objective &amp;quot;[b] responsibilities for duties that require separation are assigned to separate individuals,&amp;quot; here&amp;#039;s the ranking of evidence types supported by assessment objects:  == Evidence Type Ranking ==  1. **Artifacts (highest value)**    - User account listings with role assignments    - System access authorizations showing different individuals assigned to separated duties    - Access control ma...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Ranking Evidence Types for Assessment Objective [b]&lt;br /&gt;
&lt;br /&gt;
For the assessment objective &amp;quot;[b] responsibilities for duties that require separation are assigned to separate individuals,&amp;quot; here&amp;#039;s the ranking of evidence types supported by assessment objects:&lt;br /&gt;
&lt;br /&gt;
== Evidence Type Ranking ==&lt;br /&gt;
&lt;br /&gt;
1. **Artifacts (highest value)**&lt;br /&gt;
   - User account listings with role assignments&lt;br /&gt;
   - System access authorizations showing different individuals assigned to separated duties&lt;br /&gt;
   - Access control matrices demonstrating separation implementation&lt;br /&gt;
   - Change management records showing different people involved in change processes&lt;br /&gt;
&lt;br /&gt;
2. **Documents**&lt;br /&gt;
   - Procedures documenting how duties are assigned to different individuals&lt;br /&gt;
   - Organization charts showing actual staff assignments to roles&lt;br /&gt;
   - Job descriptions that specify individual responsibilities&lt;br /&gt;
   - Staff assignment records demonstrating separation of duties&lt;br /&gt;
&lt;br /&gt;
3. **Screen Share**&lt;br /&gt;
   - Live demonstration of access control systems showing individual assignments&lt;br /&gt;
   - Viewing system configurations showing how different accounts have separate privileges&lt;br /&gt;
&lt;br /&gt;
4. **Physical Review (lowest value)**&lt;br /&gt;
   - On-site verification of work arrangements supporting separation&lt;br /&gt;
   - Observation of individuals performing different roles in critical processes&lt;br /&gt;
&lt;br /&gt;
== Assessment Approach Prioritization ==&lt;br /&gt;
&lt;br /&gt;
For assessment objective [b], I recommend prioritizing the approaches as follows:&lt;br /&gt;
&lt;br /&gt;
1. **Interview (highest priority)**&lt;br /&gt;
   - Start by interviewing personnel with responsibilities for defining divisions of responsibility&lt;br /&gt;
   - Talk with system administrators who implement access controls&lt;br /&gt;
   - Interview security personnel about how they ensure proper separations&lt;br /&gt;
   - These interviews provide direct evidence of how responsibilities are assigned in practice&lt;br /&gt;
&lt;br /&gt;
2. **Examine**&lt;br /&gt;
   - Review staff assignment documentation&lt;br /&gt;
   - Check system access authorizations for different individuals&lt;br /&gt;
   - Analyze role assignments across the organization&lt;br /&gt;
   - This documentation validates what was learned in interviews&lt;br /&gt;
&lt;br /&gt;
3. **Test (supplementary)**&lt;br /&gt;
   - Test system access controls to verify different individuals have appropriate access&lt;br /&gt;
   - Attempt to perform incompatible functions using different accounts&lt;br /&gt;
   - This testing confirms that technical controls enforce the separation of individuals&lt;br /&gt;
&lt;br /&gt;
This prioritization focuses first on understanding how separations are actually implemented through personnel assignments, then verifies this through documentation, and finally confirms through technical verification that the separations are enforced.&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
</feed>