Catalog
Controls & assessment objectives
Every control is stored with its full statement and each published assessment objective, quoted verbatim from the source document. Examples and verdicts hang off the objectives, not off a vague summary.
3 controls
- RA.L2-3.11.1RA · Risk AssessmentLevel 2CMMC L2
Risk Assessments
Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.
- 2objectives
- 1examples
- 0threads
- RA.L2-3.11.2RA · Risk AssessmentLevel 2CMMC L2
Vulnerability Scan
Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.
- 5objectives
- 1examples
- 0threads
- RA.L2-3.11.3RA · Risk AssessmentLevel 2CMMC L2
Vulnerability Remediation
Remediate vulnerabilities in accordance with risk assessments.
- 2objectives
- 1examples
- 0threads