Level 2 Assessment Guide: Difference between revisions
Jump to navigation
Jump to search
(Created page with "'''Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' == Access Control (AC) == === Level 1 AC Practices === ==== AC.L1-3.1.1 – AUTHORIZED ACCESS CONTROL ==== {|class="wikitable" |- |'''SECURITY REQUIREMENT''' Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other...") |
No edit summary |
||
Line 3: | Line 3: | ||
== Access Control (AC) == | == Access Control (AC) == | ||
=== Level 1 AC Practices === | === Level 1 AC Practices === | ||
==== AC.L1-3.1.1 | ==== AC.L1-3.1.1 - Authorized Access Control ==== | ||
{|class="wikitable" | {|class="wikitable" | ||
|- | |- | ||
Line 20: | Line 20: | ||
|} | |} | ||
==== AC.L1-3.1.2 | ==== AC.L1-3.1.2 - Transaction & Function Control ==== | ||
{|class="wikitable" | {|class="wikitable" | ||
|- | |- | ||
Line 33: | Line 33: | ||
|} | |} | ||
==== AC.L1-3.1.20 | ==== AC.L1-3.1.20 - External Connections ==== | ||
{|class="wikitable" | {|class="wikitable" | ||
|- | |- | ||
Line 50: | Line 50: | ||
|} | |} | ||
==== AC.L1-3.1.22 | ==== AC.L1-3.1.22 - Control Public Information ==== | ||
{|class="wikitable" | {|class="wikitable" | ||
|- | |- |
Revision as of 03:12, 20 February 2022
Reference: The official CMMC Level 2 Assessment Guide from the Office of the Under Secretary of Defense Acquisition & Sustainment.
Access Control (AC)
Level 1 AC Practices
AC.L1-3.1.1 - Authorized Access Control
SECURITY REQUIREMENT
Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems). |
ASSESSMENT OBJECTIVES
|
More Practice Details... |
AC.L1-3.1.2 - Transaction & Function Control
SECURITY REQUIREMENT
Limit information system access to the types of transactions and functions that authorized users are permitted to execute. |
ASSESSMENT OBJECTIVES
|
More Practice Details... |
AC.L1-3.1.20 - External Connections
SECURITY REQUIREMENT
Verify and control/limit connections to and use of external information systems. |
ASSESSMENT OBJECTIVES
|
More Practice Details... |
AC.L1-3.1.22 - Control Public Information
SECURITY REQUIREMENT
Control information posted or processed on publicly accessible information systems. |
ASSESSMENT OBJECTIVES
|
More Practice Details... |