What is the 4 phases of the CAP ?
Phase 1: Plan and Prepare Assessment
Phase 2: Conduct the Assessment
Phase 3: Report recommended assessment Results
Phase 4: Close-Out POA&M and Assessment
Acronym: CUI ?
Control Unclassified Information
Acronym: FCI ?
Federal Contract Information
Acronym: DIB ?
Defense Industrial Base - Provides research and development services to US military such as design, manufacture, distribution and maintenance of military weapons systems and components.
Acronym: LPP ?
Licensed Partner Publishers - develop training courses based on the CyberAB curriculum
Acronym: FAR ?
Federal Acquisition Regulation - main set of rules that all U.S. federal executive agencies must follow when they buy goods or services using government funds.
Acronym: DFARS ?
Defense Federal Acquisition Regulation Supplement - extension of the Federal Acquisition Regulation (FAR) that adds specific rules for Department of Defense (DoD) contracts.
How many domains are there ?
14
How many domains does level 1 have ?
6
How many domains does level 2 have ?
14
Is it true or false that CCP is only authorized to analyze only level 1 practices when conducting a CMMC assessment ?
True
What is Phase 2 of the CAP ?
Phase 2: Conduct Assessment
What are the 4 sub-phases of Phase 2 ?
What are the 3 steps in examining practices ?
Examine, interview, and Test
When viewing evidence for a practice you must ensure ?
Adequacy and Sufficiency
When a practice has not been effectively implemented but not appropriately documented, the assessment team should define it as ?
Limited Practice Deficiency Correction
Does the CAP provide a list of ineligible and eligible practice for LPDC ?
Yes (true)
True or False: During Phase 2, the CCP can assist the assessment team in collecting and examining evidence, scoring practices, and validating preliminary results and generating final assessment results for level 2 practices.
False
What is Phase 3 of the CAP?
Phase 3: Report Recommended Assessment Results
What are the two steps in Phase 3 of the CAP ?
What template is to be using to deliver the assessment results to the OSC assessment official ?
Final Findings Briefing Template
True or False: The C3PAO must use the CMMC eMASS JSON schema (detailed in the eMASS CONOPS ) for uploading the assessment results into CMMC eMASS. In how many days after the final findings briefing ?
True, in 20 days.
Acronym: LPDCP ?
Limited Practice Deficiency Correction Program
What happens if any practices on the LPDCP fail to result in a score of “MET” ?
The Lead Assessor will recommend moving the OSCs practice deficiency’s to a POA&M.