C3 Integrated Solutions
CMMC Level 2 Controls and Assessment Objectives
Pages
78
Time to read
55 mins
Publication
Language
English
Pages
78
Time to read
55 mins
Publication
Language
English
This document is a guide that outlines the controls and assessment objectives required for compliance with CMMC Level 2, specifically for organizations within the Defense Industrial Base (DIB) that handle Controlled Unclassified Information (CUI). It emphasizes the importance of adhering to the cybersecurity standards defined in NIST Special Publication 800-171 Rev. 2, which includes 110 cybersecurity requirements organized into 14 Security Requirement Families. The guide details the assessment framework provided by NIST Special Publication 800-171A, which breaks down these controls into 320 specific assessment objectives. These objectives serve as a comprehensive framework for organizations to evaluate their compliance with necessary cybersecurity protocols and prepare for a CMMC Level 2 assessment. The document further elaborates on various domains, including Access Control, Incident Response, and Media Protection, among others, specifying the requirements and objectives for each domain to ensure effective implementation of security measures.