In the Code of Professional Conduct, what does the practice of Professionalism require?
A CCP is part of a CMMC Assessment Team interviewing a subject-matter expert on Access Control (AC) within an OSC. During the interview process, what will the CCP ensure about the information exchanged during the interview?
When planning an assessment, the Lead Assessor should work with the OSC to select personnel to be interviewed who could:
A defense contractor needs to share FCI with a subcontractor and sends this data in an email. The email system involved in this process is being used to:
SI.L2-3.14.7: Identify unauthorized use of organizational systems is being assessed using two assessment objectives. The assessment objectives are to determine if authorized use of the system is defined and to determine if unauthorized use of the system is identified. What is the BEST evidence for this practice?
When are data and documents with legacy markings from or for the DoD required to be re-marked or redacted?
Which CMMC Levels meet the standards of protecting FCI (Federal Contract Information) ?
Which NIST SP discusses protecting CUI in nonfederal systems and organizations?
For the purpose of determining scope, what needs to be included as part of the assessment but would NOT receive a CMMC certification unless an enterprise assessment is conducted?