Controls & assessment objectives
110 controls
- PE.L2-3.10.2PE · Physical ProtectionLevel 2CMMC L2
Monitor Facility
Protect and monitor the physical facility and support infrastructure for organizational systems.
- 4objectives
- 1examples
- 0threads
- PE.L2-3.10.3PE · Physical ProtectionLevel 2CMMC L2
Escort Visitors [CUI Data]
Escort visitors and monitor visitor activity.
- 2objectives
- 1examples
- 0threads
- PE.L2-3.10.4PE · Physical ProtectionLevel 2CMMC L2
Physical Access Logs [CUI Data]
Maintain audit logs of physical access.
- 1objectives
- 1examples
- 0threads
- PE.L2-3.10.5PE · Physical ProtectionLevel 2CMMC L2
Manage Physical Access [CUI Data]
Control and manage physical access devices.
- 3objectives
- 1examples
- 0threads
- PE.L2-3.10.6PE · Physical ProtectionLevel 2CMMC L2
Alternative Work Sites
Enforce safeguarding measures for CUI at alternate work sites.
- 2objectives
- 1examples
- 0threads
- RA.L2-3.11.1RA · Risk AssessmentLevel 2CMMC L2
Risk Assessments
Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.
- 2objectives
- 1examples
- 0threads
- RA.L2-3.11.2RA · Risk AssessmentLevel 2CMMC L2
Vulnerability Scan
Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.
- 5objectives
- 1examples
- 0threads
- RA.L2-3.11.3RA · Risk AssessmentLevel 2CMMC L2
Vulnerability Remediation
Remediate vulnerabilities in accordance with risk assessments.
- 2objectives
- 1examples
- 0threads
- CA.L2-3.12.1CA · Security AssessmentLevel 2CMMC L2
Security Control Assessment
Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.
- 2objectives
- 1examples
- 0threads
- CA.L2-3.12.2CA · Security AssessmentLevel 2CMMC L2
Operational Plan of Action
Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.
- 3objectives
- 1examples
- 0threads
- CA.L2-3.12.3CA · Security AssessmentLevel 2CMMC L2
Security Control Monitoring
Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.
- 1objectives
- 1examples
- 0threads
- CA.L2-3.12.4CA · Security AssessmentLevel 2CMMC L2
System Security Plan
Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.
- 8objectives
- 1examples
- 0threads
- SC.L2-3.13.1SC · System and Communications ProtectionLevel 2CMMC L2
Boundary Protection [CUI Data]
Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.
- 8objectives
- 1examples
- 0threads
- SC.L2-3.13.2SC · System and Communications ProtectionLevel 2CMMC L2
Security Engineering
Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.
- 6objectives
- 1examples
- 0threads
- SC.L2-3.13.3SC · System and Communications ProtectionLevel 2CMMC L2
Role Separation
Separate user functionality from system management functionality.
- 3objectives
- 1examples
- 0threads
- SC.L2-3.13.4SC · System and Communications ProtectionLevel 2CMMC L2
Shared Resource Control
Prevent unauthorized and unintended information transfer via shared system resources.
- 1objectives
- 1examples
- 0threads
- SC.L2-3.13.5SC · System and Communications ProtectionLevel 2CMMC L2
Public-access System Separation [CUI Data]
Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
- 2objectives
- 1examples
- 0threads
- SC.L2-3.13.6SC · System and Communications ProtectionLevel 2CMMC L2
Network Communication By Exception
Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).
- 2objectives
- 1examples
- 0threads
- SC.L2-3.13.7SC · System and Communications ProtectionLevel 2CMMC L2
Split Tunneling
Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).
- 1objectives
- 1examples
- 0threads
- SC.L2-3.13.8SC · System and Communications ProtectionLevel 2CMMC L2
Data in Transit
Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.
- 3objectives
- 1examples
- 0threads
- SC.L2-3.13.9SC · System and Communications ProtectionLevel 2CMMC L2
Connections Termination
Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.
- 3objectives
- 1examples
- 0threads
- SC.L2-3.13.10SC · System and Communications ProtectionLevel 2CMMC L2
Key Management
Establish and manage cryptographic keys for cryptography employed in organizational systems.
- 2objectives
- 1examples
- 0threads
- SC.L2-3.13.11SC · System and Communications ProtectionLevel 2CMMC L2
CUI Encryption
Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.
- 1objectives
- 1examples
- 0threads
- SC.L2-3.13.12SC · System and Communications ProtectionLevel 2CMMC L2
Collaborative Device Control
Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.
- 3objectives
- 1examples
- 0threads
- SC.L2-3.13.13SC · System and Communications ProtectionLevel 2CMMC L2
Mobile Code
Control and monitor the use of mobile code.
- 2objectives
- 1examples
- 0threads