User contributions for Wikiadmin

Jump to navigation Jump to search
Search for contributionsExpandCollapse
⧼contribs-top⧽
⧼contribs-date⧽
(newest | oldest) View (newer 500 | ) (20 | 50 | 100 | 250 | 500)

21 April 2024

10 April 2024

5 December 2023

8 May 2023

5 May 2023

9 April 2023

31 January 2023

28 January 2023

1 December 2022

30 November 2022

9 November 2022

4 October 2022

13 September 2022

26 August 2022

25 August 2022

24 August 2022

23 August 2022

22 August 2022

7 August 2022

6 August 2022

5 August 2022

4 August 2022

17 March 2022

16 March 2022

3 March 2022

28 February 2022

27 February 2022

26 February 2022

  • 23:3923:39, 26 February 2022 diff hist +2,281 Acronyms and AbbreviationsNo edit summary
  • 21:3021:30, 26 February 2022 diff hist +634 Acronyms and AbbreviationsNo edit summary
  • 19:0719:07, 26 February 2022 diff hist +1,307 Acronyms and Abbreviations→‎C
  • 18:5318:53, 26 February 2022 diff hist +52 Model GlossaryNo edit summary
  • 18:4318:43, 26 February 2022 diff hist +54 Acronyms and Abbreviations→‎B
  • 18:4218:42, 26 February 2022 diff hist +490 Acronyms and Abbreviations→‎A
  • 18:1118:11, 26 February 2022 diff hist +2,519 Level 2 Scoping GuidanceNo edit summary
  • 17:4417:44, 26 February 2022 diff hist +13,556 N Level 2 Scoping GuidanceCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Scoping Guidance] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == CMMC Asset Categories == The CMMC Assessment Guide – Level 2 maps contractor assets into one of five categories. Table 1 describes each asset category, contrac..."
  • 17:2017:20, 26 February 2022 diff hist +18 Level 1 Scoping GuidanceNo edit summary
  • 17:1917:19, 26 February 2022 diff hist +5,543 N Level 1 Scoping GuidanceCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 1 Scoping Guidance] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == FCI Assets == Federal Contract Information (FCI) Assets process, store, or transmit FCI as follows: * Process – FCI can be used by an asset (e.g., accessed, en..."
  • 17:1117:11, 26 February 2022 diff hist +58 Main PageNo edit summary
  • 16:5416:54, 26 February 2022 diff hist +106 MediaWiki:SidebarNo edit summary
  • 05:3105:31, 26 February 2022 diff hist +4,137 N Practice AC.L2-3.1.21 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AC.L2-3.1.21 – PORTABLE STORAGE USE == === SECURITY REQUIREMENT === Limit use of portable storage devices on external systems. === ASSESSMENT OBJECTIVES === De..." current
  • 05:3005:30, 26 February 2022 diff hist +4,131 N Practice AC.L2-3.1.19 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AC.L2-3.1.19 – ENCRYPT CUI ON MOBILE == === SECURITY REQUIREMENT === Encrypt CUI on mobile devices and mobile computing platforms. === ASSESSMENT OBJECTIVES ==..." current
  • 05:3005:30, 26 February 2022 diff hist +4,509 N Practice AC.L2-3.1.18 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AC.L2-3.1.18 – MOBILE DEVICE CONNECTION == === SECURITY REQUIREMENT === Control connection of mobile devices. === ASSESSMENT OBJECTIVES === Determine if: : [a]..." current
  • 05:3005:30, 26 February 2022 diff hist +5,333 N Practice AC.L2-3.1.17 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AC.L2-3.1.17 – WIRELESS ACCESS PROTECTION == === SECURITY REQUIREMENT === Protect wireless access using authentication and encryption. === ASSESSMENT OBJECTIVE..." current
  • 05:3005:30, 26 February 2022 diff hist +3,294 N Practice AC.L2-3.1.16 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AC.L2-3.1.16 – WIRELESS ACCESS AUTHORIZATION == === SECURITY REQUIREMENT === Authorize wireless access prior to allowing such connections. === ASSESSMENT OBJEC..." current
  • 05:2905:29, 26 February 2022 diff hist +4,799 N Practice AC.L2-3.1.15 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AC.L2-3.1.15 – PRIVILEGED REMOTE ACCESS == === SECURITY REQUIREMENT === Authorize remote execution of privileged commands and remote access to security-relevan..." current
  • 05:2905:29, 26 February 2022 diff hist +3,126 N Practice AC.L2-3.1.14 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AC.L2-3.1.14 – REMOTE ACCESS ROUTING == === SECURITY REQUIREMENT === Route remote access via managed access control points. === ASSESSMENT OBJECTIVES === Deter..." current
  • 05:2905:29, 26 February 2022 diff hist +4,146 N Practice AC.L2-3.1.13 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AC.L2-3.1.13 – REMOTE ACCESS CONFIDENTIALITY == === SECURITY REQUIREMENT === Employ cryptographic mechanisms to protect the confidentiality of remote access se..." current
  • 05:2905:29, 26 February 2022 diff hist +5,493 N Practice AC.L2-3.1.12 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AC.L2-3.1.12 – CONTROL REMOTE ACCESS == === SECURITY REQUIREMENT === Monitor and control remote access sessions. === ASSESSMENT OBJECTIVES === Determine if: :..." current
  • 05:2805:28, 26 February 2022 diff hist +4,188 N Practice AC.L2-3.1.11 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AC.L2-3.1.11 – SESSION TERMINATION == === SECURITY REQUIREMENT === Terminate (automatically) a user session after a defined condition. === ASSESSMENT OBJECTIVE..." current
  • 05:2805:28, 26 February 2022 diff hist +3,502 N Practice AC.L2-3.1.10 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AC.L2-3.1.10 – SESSION LOCK == === SECURITY REQUIREMENT === Use session lock with pattern-hiding displays to prevent access and viewing of data after a period..." current
  • 05:2705:27, 26 February 2022 diff hist +4,343 N Practice AC.L2-3.1.9 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AC.L2-3.1.9 – PRIVACY & SECURITY NOTICES == === SECURITY REQUIREMENT === Provide privacy and security notices consistent with applicable CUI rules. === ASSESSM..." current
  • 05:2705:27, 26 February 2022 diff hist +3,427 N Practice AC.L2-3.1.8 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AC.L2-3.1.8 – UNSUCCESSFUL LOGON ATTEMPTS == === SECURITY REQUIREMENT === Limit unsuccessful logon attempts. === ASSESSMENT OBJECTIVES === Determine if: : [a]..." current
  • 05:2705:27, 26 February 2022 diff hist +4,953 N Practice AC.L2-3.1.7 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AC.L2-3.1.7 – PRIVILEGED FUNCTIONS == === SECURITY REQUIREMENT === Prevent non-privileged users from executing privileged functions and capture the execution o..." current
  • 05:2705:27, 26 February 2022 diff hist +3,101 N Practice AC.L2-3.1.6 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AC.L2-3.1.6 – NON-PRIVILEGED ACCOUNT USE == === SECURITY REQUIREMENT === Use non-privileged accounts or roles when accessing nonsecurity functions. === ASSESSM..." current
  • 05:2605:26, 26 February 2022 diff hist +5,060 N Practice AC.L2-3.1.5 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AC.L2-3.1.5 – LEAST PRIVILEGE == === SECURITY REQUIREMENT === Employ the principle of least privilege, including for specific security functions and privileged..." current
  • 05:2605:26, 26 February 2022 diff hist +3,716 N Practice AC.L2-3.1.4 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AC.L2-3.1.4 – SEPARATION OF DUTIES == === SECURITY REQUIREMENT === Separate the duties of individuals to reduce the risk of malevolent activity without collusi..." current
  • 05:2605:26, 26 February 2022 diff hist +7,260 N Practice AC.L2-3.1.3 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AC.L2-3.1.3 – CONTROL CUI FLOW == === SECURITY REQUIREMENT === Control the flow of CUI in accordance with approved authorizations. === ASSESSMENT OBJECTIVES ==..." current
  • 03:4103:41, 26 February 2022 diff hist +3,396 N Practice AU.L2-3.3.9 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AU.L2-3.3.9 – AUDIT MANAGEMENT == ===SECURITY REQUIREMENT === Limit management of audit logging functionality to a subset of privileged users. === ASSESSMENT O..." current
  • 03:4103:41, 26 February 2022 diff hist +3,443 N Practice AU.L2-3.3.8 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AU.L2-3.3.8 – AUDIT PROTECTION == ===SECURITY REQUIREMENT === Protect audit information and audit logging tools from unauthorized access, modification, and del..." current
  • 03:4103:41, 26 February 2022 diff hist +3,538 N Practice AU.L2-3.3.7 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AU.L2-3.3.7 – AUTHORITATIVE TIME SOURCE == ===SECURITY REQUIREMENT === Provide a system capability that compares and synchronizes internal system clocks with a..." current
  • 03:4003:40, 26 February 2022 diff hist +3,845 N Practice AU.L2-3.3.6 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AU.L2-3.3.6 – REDUCTION & REPORTING == ===SECURITY REQUIREMENT === Provide audit record reduction and report generation to support on-demand analysis and repor..." current
  • 03:4003:40, 26 February 2022 diff hist +3,596 N Practice AU.L2-3.3.5 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AU.L2-3.3.5 – AUDIT CORRELATION == ===SECURITY REQUIREMENT === Correlate audit record review, analysis, and reporting processes for investigation and response..." current
  • 03:3903:39, 26 February 2022 diff hist +2 Practice AU.L2-3.3.4 Details→‎FURTHER DISCUSSION current
  • 03:3903:39, 26 February 2022 diff hist +3,626 N Practice AU.L2-3.3.4 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AU.L2-3.3.4 – AUDIT FAILURE ALERTING == ===SECURITY REQUIREMENT === Alert in the event of an audit logging process failure. === ASSESSMENT OBJECTIVES === Deter..."
  • 03:3803:38, 26 February 2022 diff hist +3,272 N Practice AU.L2-3.3.3 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AU.L2-3.3.3 – EVENT REVIEW == ===SECURITY REQUIREMENT === Review and update logged events. === ASSESSMENT OBJECTIVES === Determine if: : [a] a process for dete..." current
  • 03:3803:38, 26 February 2022 diff hist +3,348 N Practice AU.L2-3.3.2 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AU.L2-3.3.2 – USER ACCOUNTABILITY == ===SECURITY REQUIREMENT === Ensure that the actions of individual system users can be uniquely traced to those users so th..." current
  • 03:3803:38, 26 February 2022 diff hist +6,122 N Practice AU.L2-3.3.1 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AU.L2-3.3.1 – SYSTEM AUDITING == ===SECURITY REQUIREMENT === Create and retain system audit logs and records to the extent needed to enable the monitoring, ana..." current
  • 03:3703:37, 26 February 2022 diff hist +3,849 N Practice CM.L2-3.4.9 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == CM.L2-3.4.9 – USER-INSTALLED SOFTWARE == ===SECURITY REQUIREMENT === Control and monitor user-installed software. === ASSESSMENT OBJECTIVES === Determine if: :..." current
  • 03:3603:36, 26 February 2022 diff hist +4,818 N Practice CM.L2-3.4.8 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == CM.L2-3.4.8 – APPLICATION EXECUTION POLICY == ===SECURITY REQUIREMENT === Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized soft..." current
  • 03:3603:36, 26 February 2022 diff hist +6,159 N Practice CM.L2-3.4.7 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == CM.L2-3.4.7 – NONESSENTIAL FUNCTIONALITY == ===SECURITY REQUIREMENT === Restrict, disable, or prevent the use of nonessential programs, functions, ports, proto..." current
  • 03:3603:36, 26 February 2022 diff hist +3,900 N Practice CM.L2-3.4.6 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == CM.L2-3.4.6 – LEAST FUNCTIONALITY == ===SECURITY REQUIREMENT === Employ the principle of least functionality by configuring organizational systems to provide o..." current
  • 03:3503:35, 26 February 2022 diff hist +5,729 N Practice CM.L2-3.4.5 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == CM.L2-3.4.5 – ACCESS RESTRICTIONS FOR CHANGE == ===SECURITY REQUIREMENT === Define, document, approve, and enforce physical and logical access restrictions ass..." current
  • 03:3503:35, 26 February 2022 diff hist +3,256 N Practice CM.L2-3.4.4 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == CM.L2-3.4.4 – SECURITY IMPACT ANALYSIS == ===SECURITY REQUIREMENT === Analyze the security impact of changes prior to implementation. === ASSESSMENT OBJECTIVES..." current
  • 03:3503:35, 26 February 2022 diff hist +4,060 N Practice CM.L2-3.4.3 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == CM.L2-3.4.3 – SYSTEM CHANGE MANAGEMENT == ===SECURITY REQUIREMENT === Track, review, approve or disapprove, and log changes to organizational systems. === ASSE..." current
  • 03:3503:35, 26 February 2022 diff hist +5,186 N Practice CM.L2-3.4.2 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == CM.L2-3.4.2 – SECURITY CONFIGURATION ENFORCEMENT == ===SECURITY REQUIREMENT === Establish and enforce security configuration settings for information technolog..." current
  • 03:3403:34, 26 February 2022 diff hist +6,004 N Practice CM.L2-3.4.1 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == CM.L2-3.4.1 – SYSTEM BASELINING == ===SECURITY REQUIREMENT === Establish and maintain baseline configurations and inventories of organizational systems (includ..." current

25 February 2022

  • 23:2523:25, 25 February 2022 diff hist +2,738 N Practice MP.L2-3.8.9 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == MP.L2-3.8.9 – PROTECT BACKUPS == === SECURITY REQUIREMENT === Protect the confidentiality of backup CUI at storage locations. === ASSESSMENT OBJECTIVES === Det..." current
  • 23:2523:25, 25 February 2022 diff hist +2,890 N Practice MP.L2-3.8.8 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == MP.L2-3.8.8 – SHARED MEDIA == === SECURITY REQUIREMENT === Prohibit the use of portable storage devices when such devices have no identifiable owner. === ASSES..." current
  • 23:2523:25, 25 February 2022 diff hist +4,578 N Practice MP.L2-3.8.7 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == MP.L2-3.8.7 – REMOVEABLE MEDIA == === SECURITY REQUIREMENT === Control the use of removable media on system components. === ASSESSMENT OBJECTIVES === Determine..." current
  • 23:2423:24, 25 February 2022 diff hist +3,360 N Practice MP.L2-3.8.6 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == MP.L2-3.8.6 – PORTABLE STORAGE ENCRYPTION == === SECURITY REQUIREMENT === Implement cryptographic mechanisms to protect the confidentiality of CUI stored on di..." current
  • 23:2423:24, 25 February 2022 diff hist +3,915 N Practice MP.L2-3.8.5 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == MP.L2-3.8.5 – MEDIA ACCOUNTABILITY == === SECURITY REQUIREMENT === Control access to media containing CUI and maintain accountability for media during transpor..." current
  • 23:2423:24, 25 February 2022 diff hist +126 Practice MP.L2-3.8.4 DetailsNo edit summary current
  • 23:2423:24, 25 February 2022 diff hist +2,738 N Practice MP.L2-3.8.4 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == MP.L2-3.8.9 – PROTECT BACKUPS == === SECURITY REQUIREMENT === Protect the confidentiality of backup CUI at storage locations. === ASSESSMENT OBJECTIVES === Det..."
  • 23:2323:23, 25 February 2022 diff hist +2,727 N Practice MP.L2-3.8.2 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == MP.L2-3.8.2 – MEDIA ACCESS == === SECURITY REQUIREMENT === Limit access to CUI on system media to authorized users. === ASSESSMENT OBJECTIVES === Determine if:..." current
  • 23:2323:23, 25 February 2022 diff hist +3,955 N Practice MP.L2-3.8.1 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == MP.L2-3.8.1 – MEDIA PROTECTION == === SECURITY REQUIREMENT === Protect (i.e., physically control and securely store) system media containing CUI, both paper an..." current
  • 23:2323:23, 25 February 2022 diff hist +3,324 N Practice MA.L2-3.7.6 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == MA.L2-3.7.6 – MAINTENANCE PERSONNEL == === SECURITY REQUIREMENT === Supervise the maintenance activities of maintenance personnel without required access autho..." current
  • 23:2223:22, 25 February 2022 diff hist +4,487 N Practice MA.L2-3.7.5 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == MA.L2-3.7.5 – NONLOCAL MAINTENANCE == === SECURITY REQUIREMENT === Require multifactor authentication to establish nonlocal maintenance sessions via external n..." current
  • 23:2223:22, 25 February 2022 diff hist +3,292 N Practice MA.L2-3.7.4 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == MA.L2-3.7.4 – MEDIA INSPECTION == === SECURITY REQUIREMENT === Check media containing diagnostic and test programs for malicious code before the media are used..." current
  • 23:2123:21, 25 February 2022 diff hist +3,586 N Practice MA.L2-3.7.3 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == MA.L2-3.7.3 – EQUIPMENT SANITIZATION == === SECURITY REQUIREMENT === Ensure equipment removed for off-site maintenance is sanitized of any CUI. === ASSESSMENT..." current
  • 23:2123:21, 25 February 2022 diff hist +1 Practice MA.L2-3.7.1 DetailsNo edit summary current
  • 23:2023:20, 25 February 2022 diff hist +4,156 N Practice MA.L2-3.7.2 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == MA.L2-3.7.2 – SYSTEM MAINTENANCE CONTROL == === SECURITY REQUIREMENT === Provide controls on the tools, techniques, mechanisms, and personnel used to conduct s..." current
  • 23:1923:19, 25 February 2022 diff hist +3,055 N Practice MA.L2-3.7.1 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == MA.L2-3.7.1 – PERFORM MAINTENANCE == === SECURITY REQUIREMENT === Perform maintenance on organizational systems.=== ASSESSMENT OBJECTIVES === Determine if: : [..."
  • 20:5820:58, 25 February 2022 diff hist +2,988 N Practice IA.L2-3.5.11 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == IA.L2-3.5.11 – OBSCURE FEEDBACK == === SECURITY REQUIREMENT === Obscure feedback of authentication information. === ASSESSMENT OBJECTIVES === Determine if: : [..." current
  • 20:5820:58, 25 February 2022 diff hist +2,524 N Practice IA.L2-3.5.10 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == IA.L2-3.5.10 – CRYPTOGRAPHICALLY-PROTECTED PASSWORDS == === SECURITY REQUIREMENT === Store and transmit only cryptographically-protected passwords. === ASSESSM..." current
  • 20:5820:58, 25 February 2022 diff hist +2,578 N Practice IA.L2-3.5.9 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == IA.L2-3.5.9 – TEMPORARY PASSWORDS == === SECURITY REQUIREMENT === Allow temporary password use for system logons with an immediate change to a permanent passwo..." current
  • 20:5720:57, 25 February 2022 diff hist +2,313 N Practice IA.L2-3.5.8 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == IA.L2-3.5.8 – PASSWORD REUSE == === SECURITY REQUIREMENT === Prohibit password reuse for a specified number of generations. === ASSESSMENT OBJECTIVES === Deter..." current
  • 20:5720:57, 25 February 2022 diff hist +3,608 N Practice IA.L2-3.5.7 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == IA.L2-3.5.7 – PASSWORD COMPLEXITY == === SECURITY REQUIREMENT === Enforce a minimum password complexity and change of characters when new passwords are created..." current
  • 20:5620:56, 25 February 2022 diff hist +2,863 N Practice IA.L2-3.5.6 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == IA.L2-3.5.6 – IDENTIFIER HANDLING == === SECURITY REQUIREMENT === Disable identifiers after a defined period of inactivity. === ASSESSMENT OBJECTIVES === Deter..." current
  • 20:5620:56, 25 February 2022 diff hist +3,057 N Practice IA.L2-3.5.5 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == IA.L2-3.5.5 – IDENTIFIER REUSE == === SECURITY REQUIREMENT === Prevent reuse of identifiers for a defined period. === ASSESSMENT OBJECTIVES === Determine if: :..." current
  • 20:5620:56, 25 February 2022 diff hist +2,760 N Practice IA.L2-3.5.4 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == IA.L2-3.5.4 – REPLAY-RESISTANT AUTHENTICATION == === SECURITY REQUIREMENT === Employ replay-resistant authentication mechanisms for network access to privilege..." current
  • 20:5520:55, 25 February 2022 diff hist −3 Practice IA.L2-3.5.3 DetailsNo edit summary current
  • 20:5520:55, 25 February 2022 diff hist +5,462 N Practice IA.L2-3.5.3 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == IA.L2-3.5.3 – MULTIFACTOR AUTHENTICATION == === SECURITY REQUIREMENT === Use multifactor authentication for local and network access to privileged accounts and..."
  • 20:1420:14, 25 February 2022 diff hist −43 MediaWiki:SidebarNo edit summary
  • 20:1320:13, 25 February 2022 diff hist −4 Main PageNo edit summary
  • 03:0503:05, 25 February 2022 diff hist +4,313 N Practice SC.L2-3.13.16 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SC.L2-3.13.16 – DATA AT REST == === SECURITY REQUIREMENT === Protect the confidentiality of CUI at rest. === ASSESSMENT OBJECTIVES === Determine if: : [a] the..." current
  • 03:0503:05, 25 February 2022 diff hist +3,205 N Practice SC.L2-3.13.15 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SC.L2-3.13.15 – COMMUNICATIONS AUTHENTICITY == === SECURITY REQUIREMENT === Protect the authenticity of communications sessions. === ASSESSMENT OBJECTIVES ===..." current
  • 03:0503:05, 25 February 2022 diff hist +3,913 N Practice SC.L2-3.13.14 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SC.L2-3.13.14 – VOICE OVER INTERNET PROTOCOL == === SECURITY REQUIREMENT === Control and monitor the use of Voice over Internet Protocol (VoIP) technologies. =..." current
  • 03:0503:05, 25 February 2022 diff hist +4,788 N Practice SC.L2-3.13.13 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SC.L2-3.13.13 – MOBILE CODE == === SECURITY REQUIREMENT === Control and monitor the use of mobile code. === ASSESSMENT OBJECTIVES === Determine if: : [a] use o..." current
  • 03:0503:05, 25 February 2022 diff hist +3,515 N Practice SC.L2-3.13.12 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SC.L2-3.13.12 – COLLABORATIVE DEVICE CONTROL == === SECURITY REQUIREMENT === Prohibit remote activation of collaborative computing devices and provide indicati..." current
  • 03:0403:04, 25 February 2022 diff hist +3,719 N Practice SC.L2-3.13.11 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SC.L2-3.13.11 – CUI ENCRYPTION == === SECURITY REQUIREMENT === Employ FIPS-validated cryptography when used to protect the confidentiality of CUI. === ASSESSME..." current
  • 03:0403:04, 25 February 2022 diff hist +4,952 N Practice SC.L2-3.13.10 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SC.L2-3.13.10 – KEY MANAGEMENT == === SECURITY REQUIREMENT === Establish and manage cryptographic keys for cryptography employed in organizational systems. ===..." current
  • 03:0403:04, 25 February 2022 diff hist +3,212 N Practice SC.L2-3.13.9 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SC.L2-3.13.9 – CONNECTIONS TERMINATION == === SECURITY REQUIREMENT === Terminate network connections associated with communications sessions at the end of the..." current
  • 03:0403:04, 25 February 2022 diff hist +5,548 N Practice SC.L2-3.13.8 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SC.L2-3.13.8 – DATA IN TRANSIT == === SECURITY REQUIREMENT === Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission..." current
  • 03:0303:03, 25 February 2022 diff hist +3,943 N Practice SC.L2-3.13.7 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SC.L2-3.13.7 – SPLIT TUNNELING == === SECURITY REQUIREMENT === Prevent remote devices from simultaneously establishing non-remote connections with organization..." current
  • 03:0303:03, 25 February 2022 diff hist +3,462 N Practice SC.L2-3.13.6 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SC.L2-3.13.6 – NETWORK COMMUNICATION BY EXCEPTION == === SECURITY REQUIREMENT === Deny network communications traffic by default and allow network communicatio..." current
  • 03:0303:03, 25 February 2022 diff hist +3,233 N Practice SC.L2-3.13.4 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SC.L2-3.13.4 – SHARED RESOURCE CONTROL == === SECURITY REQUIREMENT === Prevent unauthorized and unintended information transfer via shared system resources.===..." current
  • 03:0203:02, 25 February 2022 diff hist +3,716 N Practice SC.L2-3.13.3 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SC.L2-3.13.3 – ROLE SEPARATION == === SECURITY REQUIREMENT === Separate user functionality from system management functionality. === ASSESSMENT OBJECTIVES ===..." current
  • 03:0203:02, 25 February 2022 diff hist +2 Practice SC.L2-3.13.2 Details→‎FURTHER DISCUSSION current
  • 03:0203:02, 25 February 2022 diff hist +6,679 N Practice SC.L2-3.13.2 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SC.L2-3.13.2 – SECURITY ENGINEERING == === SECURITY REQUIREMENT === Employ architectural designs, software development techniques, and systems engineering prin..."

24 February 2022

  • 20:0120:01, 24 February 2022 diff hist +2 Practice AT.L2-3.2.3 Details→‎POTENTIAL ASSESSMENT METHODS AND OBJECTS current
  • 20:0120:01, 24 February 2022 diff hist +4,637 N Practice AT.L2-3.2.3 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AT.L2-3.2.3 – INSIDER THREAT AWARENESS == === SECURITY REQUIREMENT === Provide security awareness training on recognizing and reporting potential indicators of..."
  • 20:0120:01, 24 February 2022 diff hist +4,925 N Practice AT.L2-3.2.2 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AT.L2-3.2.2 – ROLE-BASED TRAINING == === SECURITY REQUIREMENT === Ensure that personnel are trained to carry out their assigned information security-related du..." current
  • 20:0020:00, 24 February 2022 diff hist +4,732 N Practice AT.L2-3.2.1 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == AT.L2-3.2.1 – ROLE-BASED RISK AWARENESS == === SECURITY REQUIREMENT === Ensure that managers, systems administrators, and users of organizational systems are m..." current
  • 19:2619:26, 24 February 2022 diff hist −18 Level 2 Assessment GuideNo edit summary
  • 19:1019:10, 24 February 2022 diff hist +3,469 N Practice IR.L2-3.6.3 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == IR.L2-3.6.3 – INCIDENT RESPONSE TESTING == === SECURITY REQUIREMENT === Test the organizational incident response capability. === ASSESSMENT OBJECTIVES === Det..." current
  • 19:1019:10, 24 February 2022 diff hist +5,169 N Practice IR.L2-3.6.2 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == IR.L2-3.6.2 – INCIDENT REPORTING == === SECURITY REQUIREMENT === Track, document, and report incidents to designated officials and/or authorities both internal..." current
  • 19:1019:10, 24 February 2022 diff hist +6,524 N Practice IR.L2-3.6.1 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == IR.L2-3.6.1 – INCIDENT HANDLING == === SECURITY REQUIREMENT === Establish an operational incident-handling capability for organizational systems that includes..." current
  • 19:0919:09, 24 February 2022 diff hist +6,441 N Practice PS.L2-3.9.2 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == PS.L2-3.9.2 – PERSONNEL ACTIONS == === SECURITY REQUIREMENT === Ensure that organizational systems containing CUI are protected during and after personnel acti..." current
  • 19:0919:09, 24 February 2022 diff hist +2,486 N Practice PS.L2-3.9.1 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == PS.L2-3.9.1 – SCREEN INDIVIDUALS == === SECURITY REQUIREMENT === Screen individuals prior to authorizing access to organizational systems containing CUI. === A..." current
  • 18:3418:34, 24 February 2022 diff hist +3,388 N Practice RA.L2-3.11.3 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == RA.L2-3.11.3 – VULNERABILITY REMEDIATION == === SECURITY REQUIREMENT === Remediate vulnerabilities in accordance with risk assessments. === ASSESSMENT OBJECTIV..." current
  • 18:3318:33, 24 February 2022 diff hist +7,198 N Practice RA.L2-3.11.2 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == RA.L2-3.11.2 – VULNERABILITY SCAN == === SECURITY REQUIREMENT === Scan for vulnerabilities in organizational systems and applications periodically and when new..." current
  • 18:3318:33, 24 February 2022 diff hist +3 Practice RA.L2-3.11.1 Details→‎POTENTIAL ASSESSMENT METHODS AND OBJECTS current
  • 18:3218:32, 24 February 2022 diff hist +5,377 N Practice RA.L2-3.11.1 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == RA.L2-3.11.1 – RISK ASSESSMENTS == === SECURITY REQUIREMENT === Periodically assess the risk to organizational operations (including mission, functions, image,..."
  • 18:3218:32, 24 February 2022 diff hist +3,381 N Practice PE.L2-3.10.6 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == PE.L2-3.10.6 – ALTERNATIVE WORK SITES == === SECURITY REQUIREMENT === Enforce safeguarding measures for CUI at alternate work sites. === ASSESSMENT OBJECTIVES..." current
  • 18:3118:31, 24 February 2022 diff hist +2 Practice PE.L2-3.10.2 Details→‎FURTHER DISCUSSION current
  • 18:3118:31, 24 February 2022 diff hist +3,148 N Practice PE.L2-3.10.2 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == PE.L2-3.10.2 – MONITOR FACILITY == === SECURITY REQUIREMENT === Protect and monitor the physical facility and support infrastructure for organizational systems..."
  • 17:4217:42, 24 February 2022 diff hist −5 Practice CA.L2-3.12.4 DetailsNo edit summary current
  • 17:4217:42, 24 February 2022 diff hist −5 Practice CA.L2-3.12.3 DetailsNo edit summary current
  • 17:4217:42, 24 February 2022 diff hist −5 Practice CA.L2-3.12.2 DetailsNo edit summary current
  • 17:4117:41, 24 February 2022 diff hist −5 Practice CA.L2-3.12.1 DetailsNo edit summary current
  • 17:2917:29, 24 February 2022 diff hist +6,472 N Practice CA.L2-3.12.4 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 1 Self-Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == CA.L2-3.12.4 – SYSTEM SECURITY PLAN == === SECURITY REQUIREMENT === Develop, document, and periodically update system security plans that describe system..."
  • 17:2917:29, 24 February 2022 diff hist +4,279 N Practice CA.L2-3.12.3 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 1 Self-Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == CA.L2-3.12.3 – SECURITY CONTROL MONITORING == === SECURITY REQUIREMENT === Monitor security controls on an ongoing basis to ensure the continued effective..."
  • 17:2917:29, 24 February 2022 diff hist +4,079 N Practice CA.L2-3.12.2 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 1 Self-Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == CA.L2-3.12.2 – PLAN OF ACTION == === SECURITY REQUIREMENT === Develop and implement plans of action designed to correct deficiencies and reduce or elimina..."
  • 17:2817:28, 24 February 2022 diff hist +4,801 N Practice CA.L2-3.12.1 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 1 Self-Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == CA.L2-3.12.1 – SECURITY CONTROL ASSESSMENT == === SECURITY REQUIREMENT === Periodically assess the security controls in organizational systems to determin..."
  • 17:2717:27, 24 February 2022 diff hist −3 Level 2 Assessment Guide→‎RA.L2-3.11.1 – RISK ASSESSMENTS
  • 17:2717:27, 24 February 2022 diff hist −5 Level 2 Assessment Guide→‎RA.L2-3.11.2 – VULNERABILITY SCAN
  • 17:2617:26, 24 February 2022 diff hist −1 Level 2 Assessment Guide→‎CA.L2-3.12.1 – SECURITY CONTROL ASSESSMENT
  • 17:2617:26, 24 February 2022 diff hist −1 Level 2 Assessment Guide→‎CA.L2-3.12.3 – SECURITY CONTROL MONITORING
  • 17:2517:25, 24 February 2022 diff hist −2 Level 2 Assessment Guide→‎CA.L2-3.12.2 – PLAN OF ACTION
  • 17:2517:25, 24 February 2022 diff hist −5 Level 2 Assessment Guide→‎SC.L2-3.13.2 – SECURITY ENGINEERING
  • 17:2317:23, 24 February 2022 diff hist −4 Level 2 Assessment Guide→‎CA.L2-3.12.4 – SYSTEM SECURITY PLAN
  • 02:4502:45, 24 February 2022 diff hist +5,044 N Practice SI.L2-3.14.7 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SI.L2-3.14.7 – IDENTIFY UNAUTHORIZED USE == === SECURITY REQUIREMENT === Identify unauthorized use of organizational systems. === ASSESSMENT OBJECTIVES === Det..." current
  • 02:4502:45, 24 February 2022 diff hist +6,630 N Practice SI.L2-3.14.6 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SI.L2-3.14.6 – MONITOR COMMUNICATIONS FOR ATTACKS == === SECURITY REQUIREMENT === Monitor organizational systems, including inbound and outbound communications..." current
  • 02:4502:45, 24 February 2022 diff hist +1 Practice SI.L2-3.14.3 DetailsNo edit summary current
  • 02:4402:44, 24 February 2022 diff hist +4,490 N Practice SI.L2-3.14.3 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 2 Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SI.L2-3.14.3 – SECURITY ALERTS & ADVISORIES == ===SECURITY REQUIREMENT === Monitor system security alerts and advisories and take action in response. === ASSES..."
  • 01:5001:50, 24 February 2022 diff hist 0 Model OverviewNo edit summary
  • 01:5001:50, 24 February 2022 diff hist +1 Model OverviewNo edit summary
  • 01:4901:49, 24 February 2022 diff hist +3,114 Model OverviewNo edit summary
  • 00:2900:29, 24 February 2022 diff hist +2 Model OverviewNo edit summary
  • 00:2700:27, 24 February 2022 diff hist +571 Model OverviewNo edit summary
  • 00:1100:11, 24 February 2022 diff hist +3,838 N Practice SI.L1-3.14.5 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 1 Self-Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SI.L1-3.14.5 – SYSTEM & FILE SCANNING == === SECURITY REQUIREMENT === Perform periodic scans of the information system and real-time scans of files from e..." current
  • 00:1100:11, 24 February 2022 diff hist +3,680 N Practice SI.L1-3.14.4 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 1 Self-Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SI.L1-3.14.4 – UPDATE MALICIOUS CODE PROTECTION == === SECURITY REQUIREMENT === Update malicious code protection mechanisms when new releases are availabl..." current
  • 00:1000:10, 24 February 2022 diff hist +1 Practice SI.L1-3.14.2 DetailsNo edit summary current Tag: Visual edit: Switched
  • 00:1000:10, 24 February 2022 diff hist +5,229 N Practice SI.L1-3.14.2 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 1 Self-Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SI.L1-3.14.2 – MALICIOUS CODE PROTECTION == === SECURITY REQUIREMENT === Provide protection from malicious code at appropriate locations within organizati..."
  • 00:0900:09, 24 February 2022 diff hist +5,574 N Practice SI.L1-3.14.1 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 1 Self-Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SI.L1-3.14.1 – FLAW REMEDIATION == === SECURITY REQUIREMENT === Identify, report, and correct information and information system flaws in a timely manner...." current

23 February 2022

  • 23:4923:49, 23 February 2022 diff hist +3,518 N Practice SC.L1-3.13.5 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 1 Self-Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SC.L1-3.13.5 – PUBLIC-ACCESS SYSTEM SEPARATION == === SECURITY REQUIREMENT === Implement subnetworks for publicly accessible system components that are ph..." current
  • 23:4923:49, 23 February 2022 diff hist +6,819 N Practice SC.L1-3.13.1 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 1 Self-Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == SC.L1-3.13.1 – BOUNDARY PROTECTION == === SECURITY REQUIREMENT === Monitor, control, and protect organizational communications (i.e., information transmit..." current
  • 23:2823:28, 23 February 2022 diff hist +3,013 N Practice PE.L1-3.10.5 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 1 Self-Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == PE.L1-3.10.5 – MANAGE PHYSICAL ACCESS == === SECURITY REQUIREMENT === Control and manage physical access devices. === ASSESSMENT OBJECTIVES === Determine..." current
  • 23:2323:23, 23 February 2022 diff hist +3,276 N Practice PE.L1-3.10.4 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 1 Self-Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == PE.L1-3.10.4 – PHYSICAL ACCESS LOGS == === SECURITY REQUIREMENT === Maintain audit logs of physical access. === ASSESSMENT OBJECTIVES === Determine if: [..." current
  • 23:1123:11, 23 February 2022 diff hist +2,969 N Practice PE.L1-3.10.3 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 1 Self-Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == PE.L1-3.10.3 – ESCORT VISITORS == === SECURITY REQUIREMENT === Escort visitors and monitor visitor activity. === ASSESSMENT OBJECTIVES === Determine if:..." current
  • 23:0523:05, 23 February 2022 diff hist +1 Practice PE.L1-3.10.1 DetailsNo edit summary current
  • 23:0523:05, 23 February 2022 diff hist +4,269 N Practice PE.L1-3.10.1 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 1 Self-Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == PE.L1-3.10.1 – LIMIT PHYSICAL ACCESS == === SECURITY REQUIREMENT === Limit physical access to organizational information systems, equipment, and the respe..."
  • 22:1422:14, 23 February 2022 diff hist +1 Practice MP.L1-3.8.3 DetailsNo edit summary current
  • 22:0722:07, 23 February 2022 diff hist +4,089 N Practice MP.L1-3.8.3 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 1 Self-Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == MP.L1-3.8.3 – MEDIA DISPOSAL == === SECURITY REQUIREMENT === Sanitize or destroy information system media containing Federal Contract Information before d..."
  • 18:5618:56, 23 February 2022 diff hist −4 Practice IA.L1-3.5.2 DetailsNo edit summary current
  • 18:5618:56, 23 February 2022 diff hist +5,198 N Practice IA.L1-3.5.2 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 1 Self-Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == IA.L1-3.5.2 – AUTHENTICATION == === SECURITY REQUIREMENT === Authenticate (or verify) the identities of those users, processes, or devices, as a prerequis..."
  • 18:5618:56, 23 February 2022 diff hist +3,626 N Practice IA.L1-3.5.1 DetailsCreated page with "'''Source of Reference: The official [https://www.acq.osd.mil/cmmc/documentation.html CMMC Level 1 Self-Assessment Guide] from the Office of the Under Secretary of Defense Acquisition & Sustainment.''' For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you. == IA.L1-3.5.1 – IDENTIFICATION == === SECURITY REQUIREMENT === Identify information system users, processes acting on behalf of users, or devices. === ASSES..." current
  • 18:5318:53, 23 February 2022 diff hist +14 Practice AC.L1-3.1.22 DetailsNo edit summary current
  • 18:5118:51, 23 February 2022 diff hist +4 Practice AC.L1-3.1.20 DetailsNo edit summary current
(newest | oldest) View (newer 500 | ) (20 | 50 | 100 | 250 | 500)