CMMC Assessment Process Flashcards

(22 cards)

1
Q

What is the purpose of the CMMC Assessment Process (CAP)?

A

To ensure all assessments are accurate, consistent, and improve cybersecurity across the Defense Industrial Base (DIB).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Who conducts CMMC Level 2 certification assessments?

A

A Certified Third-Party Assessment Organization (C3PAO) and a Certified CMMC Assessor.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What organization initiates the CMMC assessment?

A

The Organization Seeking Certification (OSC).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the four phases of the CMMC Assessment Process?

A

1.Plan and Prepare the Assessment

2.Conduct the Assessment

3.Report and Recommend Findings

4.Perform POA&M Close-Out Assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What roles exist within the OSC during an assessment?

A

OSC Assessment Official: decision authority for the assessment

OSC POC: main contact coordinating between OSC and assessment team

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Who leads the assessment team?

A

The Lead Assessor, assigned by the C3PAO.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the purpose of the Readiness Review in CAP?

A

To confirm both parties (OSC and C3PAO) are ready to conduct the assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What document must exist before the assessment starts?

A

A formal Assessment Plan based on the CAP template (or C3PAO equivalent).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the three primary assessment methods used in CAP?

A

Examine, Interview, and Test.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are artifacts in a CMMC assessment?

A

Tangible evidence (e.g., policies, screenshots, logs) showing practices are performed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does “Inherited Practice” mean in CAP?

A

A practice objective performed by another entity (e.g., cloud or managed service provider) with sufficient evidence provided to the assessor.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the Limited Practice Deficiency Correction (LPDC) program?

A

Allows OSCs to fix documentation errors or minor gaps in a short timeframe before final scoring.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which practices cannot use Limited Practice Deficiency Correction?

A

Practices not implemented before assessment or those critical to CUI protection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the POA&M Close-Out Assessment?

A

A follow-up review within 180 days for OSCs to demonstrate that previously “NOT MET” practices are now complete.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the CAP scoring method aligned with?

A

The DoD Assessment Scoring Methodology (based on NIST SP 800-171).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How are results finalized and reported?

A

The Lead Assessor submits the assessment report and all evidence to The Cyber AB via eMASS.

17
Q

What system is used to upload assessment results?

A

CMMC eMASS (Enterprise Mission Assurance Support Service).

18
Q

What document is used for quality review of assessments?

A

The CQAP (Certified Quality Auditor) Checklist

19
Q

Who can participate as a team member in an assessment?

A

A Certified CMMC Professional (CCP) may assist the Lead Assessor but cannot lead the assessment.

20
Q

What are the three main types of evidence collection approaches in Appendix S?

A

Document review, technical testing, and personnel interviews.

21
Q

What document outlines the scope, timeline, and participants of the assessment?

A

The Assessment Plan (created jointly by the OSC and Lead Assessor).

22
Q

What does the Organization Seeking Certification (OSC) provide the Lead Assessor to help understand the CMMC Assessment Scope?

A

Supporting Documentation