Controls & assessment objectives
110 controls
- IA.L2-3.5.8IA · Identification and AuthenticationLevel 2CMMC L2
Password Reuse
Prohibit password reuse for a specified number of generations.
- 2objectives
- 1examples
- 0threads
- IA.L2-3.5.9IA · Identification and AuthenticationLevel 2CMMC L2
Temporary Passwords
Allow temporary password use for system logons with an immediate change to a permanent password.
- 1objectives
- 1examples
- 0threads
- IA.L2-3.5.10IA · Identification and AuthenticationLevel 2CMMC L2
Cryptographically-protected Passwords
Store and transmit only cryptographically-protected passwords.
- 2objectives
- 1examples
- 0threads
- IA.L2-3.5.11IA · Identification and AuthenticationLevel 2CMMC L2
Obscure Feedback
Obscure feedback of authentication information.
- 1objectives
- 1examples
- 0threads
- IR.L2-3.6.1IR · Incident ResponseLevel 2CMMC L2
Incident Handling
Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.
- 7objectives
- 1examples
- 0threads
- IR.L2-3.6.2IR · Incident ResponseLevel 2CMMC L2
Incident Reporting
Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.
- 6objectives
- 1examples
- 0threads
- IR.L2-3.6.3IR · Incident ResponseLevel 2CMMC L2
Incident Response Testing
Test the organizational incident response capability.
- 1objectives
- 1examples
- 0threads
- MA.L2-3.7.1MA · MaintenanceLevel 2CMMC L2
Perform Maintenance
Perform maintenance on organizational systems.
- 1objectives
- 1examples
- 0threads
- MA.L2-3.7.2MA · MaintenanceLevel 2CMMC L2
System Maintenance Control
Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.
- 4objectives
- 1examples
- 0threads
- MA.L2-3.7.3MA · MaintenanceLevel 2CMMC L2
Equipment Sanitization
Ensure equipment removed for off-site maintenance is sanitized of any CUI.
- 1objectives
- 1examples
- 0threads
- MA.L2-3.7.4MA · MaintenanceLevel 2CMMC L2
Media Inspection
Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.
- 1objectives
- 1examples
- 0threads
- MA.L2-3.7.5MA · MaintenanceLevel 2CMMC L2
Nonlocal Maintenance
Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.
- 2objectives
- 1examples
- 0threads
- MA.L2-3.7.6MA · MaintenanceLevel 2CMMC L2
Maintenance Personnel
Supervise the maintenance activities of maintenance personnel without required access authorization.
- 1objectives
- 1examples
- 0threads
- MP.L2-3.8.1MP · Media ProtectionLevel 2CMMC L2
Media Protection
Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.
- 4objectives
- 1examples
- 0threads
- MP.L2-3.8.2MP · Media ProtectionLevel 2CMMC L2
Media Access
Limit access to CUI on system media to authorized users.
- 1objectives
- 1examples
- 0threads
- MP.L2-3.8.3MP · Media ProtectionLevel 2CMMC L2
Media Disposal [CUI Data]
Sanitize or destroy system media containing CUI before disposal or release for reuse.
- 2objectives
- 1examples
- 0threads
- MP.L2-3.8.4MP · Media ProtectionLevel 2CMMC L2
Media Markings
Mark media with necessary CUI markings and distribution limitations.
- 2objectives
- 1examples
- 0threads
- MP.L2-3.8.5MP · Media ProtectionLevel 2CMMC L2
Media Accountability
Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.
- 2objectives
- 1examples
- 0threads
- MP.L2-3.8.6MP · Media ProtectionLevel 2CMMC L2
Portable Storage Encryption
Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.
- 1objectives
- 1examples
- 0threads
- MP.L2-3.8.7MP · Media ProtectionLevel 2CMMC L2
Removeable Media
Control the use of removable media on system components.
- 1objectives
- 1examples
- 0threads
- MP.L2-3.8.8MP · Media ProtectionLevel 2CMMC L2
Shared Media
Prohibit the use of portable storage devices when such devices have no identifiable owner.
- 1objectives
- 1examples
- 0threads
- MP.L2-3.8.9MP · Media ProtectionLevel 2CMMC L2
Protect Backups
Protect the confidentiality of backup CUI at storage locations.
- 1objectives
- 1examples
- 0threads
- PS.L2-3.9.1PS · Personnel SecurityLevel 2CMMC L2
Screen Individuals
Screen individuals prior to authorizing access to organizational systems containing CUI.
- 1objectives
- 1examples
- 0threads
- PS.L2-3.9.2PS · Personnel SecurityLevel 2CMMC L2
Personnel Actions
Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.
- 3objectives
- 1examples
- 0threads
- PE.L2-3.10.1PE · Physical ProtectionLevel 2CMMC L2
Limit Physical Access [CUI Data]
Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals.
- 4objectives
- 1examples
- 0threads