CMMC Level 2
Provenance. Practice statements and assessment objectives are quoted from the CMMC Assessment Guide — Level 2, Version 2.13 (drawing on NIST SP 800-171 Rev. 2 and NIST SP 800-171A). Primary references: https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final and https://csrc.nist.gov/pubs/sp/800/171/a/final. U.S. government works, not subject to copyright in the United States.
Domains
- AC22 practices
Access Control
Limits system access to authorized users, processes, and devices, and limits what those users are permitted to do.
- AT3 practices
Awareness and Training
Ensures that managers, system administrators, and users are aware of security risks and trained to carry out their security responsibilities.
- AU9 practices
Audit and Accountability
Creates, protects, and retains system audit records, and ensures actions can be uniquely traced to users.
- CM9 practices
Configuration Management
Establishes and maintains baseline configurations and inventories, and controls changes to systems.
- IA11 practices
Identification and Authentication
Identifies users, processes, and devices, and authenticates (or verifies) their identities.
- IR3 practices
Incident Response
Establishes an operational incident-handling capability and tracks, documents, and reports incidents.
- MA6 practices
Maintenance
Performs maintenance on systems and provides effective controls on tools, techniques, and personnel.
- MP9 practices
Media Protection
Protects system media, both paper and digital, and sanitizes or destroys media containing CUI before disposal or reuse.
- PS2 practices
Personnel Security
Screens individuals prior to authorizing access to systems containing CUI and ensures CUI access is removed upon termination or transfer.
- PE6 practices
Physical Protection
Limits physical access to systems, equipment, and operating environments, and protects and monitors physical facilities.
- RA3 practices
Risk Assessment
Periodically assesses risk to organizational operations, assets, and individuals, and scans for vulnerabilities.
- CA4 practices
Security Assessment
Periodically assesses security controls, develops and implements plans of action, and monitors control effectiveness.
- SC16 practices
System and Communications Protection
Monitors, controls, and protects communications at external and key internal boundaries, and employs architectural approaches.
- SI7 practices
System and Information Integrity
Identifies, reports, and corrects information and system flaws in a timely manner, and monitors system security alerts.