REVISION NOTES AND STRUCTURED
CYBERSECURITY FRAMEWORK OVERVIEW
GUIDE
◉ What is the role of external service providers in the assessment?
Answer: To be addressed during the assessment to ensure
compliance with security requirements.
◉ What is the purpose of the Out-Brief Meeting? Answer: To discuss
the assessment results with the assessed organization.
◉ What does POA&M stand for? Answer: Plan of Action and
Milestones.
◉ What is the significance of the CMMC eMASS? Answer: It is the
platform where assessment results are uploaded.
◉ What is the expected outcome of the CMMC Assessment? Answer:
To determine the organization's cybersecurity maturity level.
,◉ What should be done if there are conflicts of interest identified?
Answer: They should be managed before proceeding with the
assessment.
◉ What is the role of the Cyber AB? Answer: To oversee the CMMC
Accreditation Body and the assessment process.
◉ What is the importance of confirming the availability of evidence?
Answer: To ensure that all necessary documentation is available for
the assessment.
◉ What is the purpose of the Assessment Appeals process? Answer:
To provide a mechanism for organizations to appeal assessment
results if necessary.
◉ What is the purpose of the Cybersecurity Maturity Model
Certification (CMMC) Program? Answer: To assess and certify
conformance to established security requirements by companies
within the Defense Industrial Base (DIB).
◉ What type of information does CMMC aim to safeguard? Answer:
Controlled Unclassified Information (CUI) and Federal Contract
Information (FCI).
, ◉ Which office oversees the CMMC Program? Answer: The Office of
the DoD Chief Information Officer (ODCIO).
◉ What organization is the designated Accreditation Body for the
CMMC Program? Answer: The Cyber AB.
◉ What document codifies the CMMC Level 2 security
requirements? Answer: NIST Special Publication 800-171, Revision
2.
◉ What is the CMMC Assessment Process (CAP)? Answer: The
official procedural guide for CMMC Third-Party Assessment
Organizations (C3PAOs) conducting CMMC Level 2 certification
assessments.
◉ What is the main goal of the CAP? Answer: To ensure consistency
and integrity of CMMC Level 2 certification assessments.
◉ What are the four phases of the CMMC Assessment Process?
Answer: 1. Conduct the Pre-Assessment, 2. Assess Conformity to
Security Requirements, 3. Complete and Report Assessment Results,
4. Issue Certificate and Closeout POA&M.