New pages
Jump to navigation
Jump to search
28 March 2025
- 03:0703:07, 28 March 2025 Practice SI.L3-3.14.6e Details (hist | edit) [7,377 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SI.L3-3.14.6E – THREAT-GUIDED INTRUSION DETECTION == === SECURITY REQUIREMENT === Use threat indicator information and effective mitigations obtained from, <u>...")
- 03:0703:07, 28 March 2025 Practice SI.L3-3.14.3e Details (hist | edit) [7,562 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SI.L3-3.14.3E – SPECIALIZED ASSET SECURITY === === SECURITY REQUIREMENT === Ensure that <u>specialized assets including IoT, IIoT, OT, GFE, Restricted Informat...")
- 03:0603:06, 28 March 2025 Practice SI.L3-3.14.1e Details (hist | edit) [8,191 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SI.L3-3.14.1E – INTEGRITY VERIFICATION === === SECURITY REQUIREMENT === Verify the integrity of <u>security critical and essential software</u> using root of t...")
- 02:4802:48, 28 March 2025 Practice SC.L3-3.13.4e Details (hist | edit) [8,251 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SC.L3-3.13.4E – ISOLATION == === SECURITY REQUIREMENT === Employ <u>physical isolation techniques or logical isolation techniques or both</u> in organizational...")
- 02:3902:39, 28 March 2025 Practice CA.L3-3.12.1e Details (hist | edit) [6,299 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == CA.L3-3.12.1E – PENETRATION TESTING === Conduct penetration testing <u>at least annually or when significant security changes are made to the system</u>, lever...")
- 02:3202:32, 28 March 2025 Practice RA.L3-3.11.7e Details (hist | edit) [5,246 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == RA.L3-3.11.7E – SUPPLY CHAIN RISK PLAN == === SECURITY REQUIREMENT === Develop a plan for managing supply chain risks associated with organizational systems an...")
- 02:3002:30, 28 March 2025 Practice RA.L3-3.11.6e Details (hist | edit) [4,678 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == RA.L3-3.11.6E – SUPPLY CHAIN RISK RESPONSE == === SECURITY REQUIREMENT === Assess, respond to, and monitor supply chain risks associated with organizational sy...")
- 02:2702:27, 28 March 2025 Practice RA.L3-3.11.5e Details (hist | edit) [5,726 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == RA.L3-3.11.5E – SECURITY SOLUTION EFFECTIVENESS == === SECURITY REQUIREMENT === Assess the effectiveness of security solutions <u>at least annually or upon rec...")
- 02:2302:23, 28 March 2025 Practice RA.L3-3.11.4e Details (hist | edit) [6,532 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == RA.L3-3.11.4E – SECURITY SOLUTION RATIONALE === === SECURITY REQUIREMENT === Document or reference in the system security plan the security solution selected,...")
- 02:1702:17, 28 March 2025 Practice RA.L3-3.11.3e Details (hist | edit) [7,934 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == RA.L3-3.11.3E – ADVANCED RISK IDENTIFICATION == === SECURITY REQUIREMENT === Employ advanced automation and analytics capabilities in support of analysts to pr...")
- 02:1602:16, 28 March 2025 Practice RA.L3-3.11.2e Details (hist | edit) [8,773 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == RA.L3-3.11.2E – THREAT HUNTING == === SECURITY REQUIREMENT === Conduct cyber threat hunting activities <u>on an on-going aperiodic basis or when indications wa...")
- 01:4901:49, 28 March 2025 Practice RA.L3-3.11.1e Details (hist | edit) [7,337 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == RA.L3-3.11.1E – THREAT-INFORMED RISK ASSESSMENT == === SECURITY REQUIREMENT === Employ <u>threat intelligence, at a minimum from open or commercial sources, an...")
27 March 2025
- 03:4703:47, 27 March 2025 Commonly Accepted and Practiced CMMC Operation Matrix (hist | edit) [114,403 bytes] David (talk | contribs) (Created page with "== Commonly Accepted and Practiced CMMC Operating Model == Under Construction!!!") originally created as "Commonly Accepted and Practiced CMMC Operating Model"
- 01:5201:52, 27 March 2025 Evidence Collection Approach (hist | edit) [111,408 bytes] David (talk | contribs) (Created page with "For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == Evidence Collection Approach for CMMC Practices Levels 1 and 2 == The following table contains the DIBCAC Evidence collection approach for the CMMC Lvels 1 and 2 practices and their Assessment Objectives. The following tables provide a general approach between Assessment Objectives (AOs) and Assessment Methods that may be used. These are not to be construe...")
- 01:2801:28, 27 March 2025 Practice PS.L3-3.9.2e Details (hist | edit) [4,554 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == PS.L3-3.9.2E – ADVERSE INFORMATION == === SECURITY REQUIREMENT === Ensure that organizational systems are protected if adverse information develops or is obtai...")
- 01:2801:28, 27 March 2025 Practice IR.L3-3.6.2e Details (hist | edit) [5,875 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == IR.L3-3.6.2E – CYBER INCIDENT RESPONSE TEAM == === SECURITY REQUIREMENT === Establish and maintain a cyber incident response team that can be deployed by the o...")
- 01:2801:28, 27 March 2025 Practice IR.L3-3.6.1e Details (hist | edit) [5,817 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == IR.L3-3.6.1E – SECURITY OPERATIONS CENTER == === SECURITY REQUIREMENT === Establish and maintain a security operations center capability that operates <u>24/7,...")
- 01:2701:27, 27 March 2025 Practice IA.L3-3.5.3e Details (hist | edit) [7,786 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == IA.L3-3.5.3E – BLOCK UNTRUSTED ASSETS == === SECURITY REQUIREMENT === Employ automated or manual/procedural mechanisms to prohibit system components from conne...")
- 01:2701:27, 27 March 2025 Practice IA.L3-3.5.1e Details (hist | edit) [7,998 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == IA.L3-3.5.1E – BIDIRECTIONAL AUTHENTICATION == === SECURITY REQUIREMENT === Identify and authenticate <u>systems and system components, where possible</u>, bef...")
25 March 2025
- 03:1203:12, 25 March 2025 Practice CM.L3-3.4.3e Details (hist | edit) [5,520 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == CM.L3-3.4.3E – AUTOMATED INVENTORY == === SECURITY REQUIREMENT === Employ automated discovery and management tools to maintain an up-to-date, complete, accurat...")
- 03:1203:12, 25 March 2025 Practice CM.L3-3.4.2e Details (hist | edit) [7,207 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. === CM.L3-3.4.2E – AUTOMATED DETECTION & REMEDIATION === === SECURITY REQUIREMENT === Employ automated mechanisms to detect misconfigured or unauthorized system c...")
- 03:1203:12, 25 March 2025 Practice CM.L3-3.4.1e Details (hist | edit) [5,622 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == CM.L3-3.4.1E – AUTHORITATIVE REPOSITORY == === SECURITY REQUIREMENT === Establish and maintain an authoritative source and repository to provide a trusted sour...")
- 02:4402:44, 25 March 2025 Practice AT.L3-3.2.2e Details (hist | edit) [6,283 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AT.L3-3.2.2E – PRACTICAL TRAINING EXERCISES == === SECURITY REQUIREMENT === Include practical exercises in awareness training for all users, tailored by roles,...")
- 02:3902:39, 25 March 2025 Practice AT.L3-3.2.1e Details (hist | edit) [4,593 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AT.L3-3.2.1E – ADVANCED THREAT AWARENESS == === SECURITY REQUIREMENT === Provide awareness training upon initial hire, following a significant cyber event, and...")
24 March 2025
- 22:3522:35, 24 March 2025 Practice AC.L3-3.1.3e Details (hist | edit) [6,279 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AC.L3-3.1.3E – SECURED INFORMATION TRANSFER == === SECURITY REQUIREMENT === Employ secure information transfer solutions to control information flows between s...")
- 14:4814:48, 24 March 2025 Practice AC.L3-3.1.2e Details (hist | edit) [4,710 bytes] David (talk | contribs) (Created page with "'''Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AC.L3-3.1.2E – ORGANIZATIONALLY CONTROLLED ASSETS == === SECURITY REQUIREMENT === Restrict access to systems and system components to only those information re...")
23 February 2025
- 04:2204:22, 23 February 2025 32 CFR Part 170 (hist | edit) [158,384 bytes] Wikiadmin (talk | contribs) (Importing content from PDF File: https://www.govinfo.gov/content/pkg/FR-2024-10-15/pdf/2024-22905.pdf) originally created as "32 CFR Part 170 CMMC Rule"
- 03:2903:29, 23 February 2025 Level 3 Assessment Guide (hist | edit) [54,506 bytes] Wikiadmin (talk | contribs) (Importing content from PDF File: https://dodcio.defense.gov/Portals/0/Documents/CMMC/AssessmentGuideL3v2.pdf)
- 03:0503:05, 23 February 2025 Level 3 Scoping Guidance (hist | edit) [21,417 bytes] Wikiadmin (talk | contribs) (Importing content from PDF File: https://dodcio.defense.gov/Portals/0/Documents/CMMC/ScopingGuideL3v2.pdf) originally created as "Level 3 Scoping Guide"