You are the Lead Assessor for a CMMC assessment of an OSC that has previously obtained ISO 27001 certification for its information security management system. During the initial discussions, the OSC requests that you consider their ISO 27001 certification and grant them credit toward their CMMC certification. They believe there is a significant overlap between CMMC and ISO 27001. What should your response to the OSC be?
Comprehensive and Detailed in Depth
The CAP explicitly states that other certifications like ISO 27001 do not grant automatic CMMC credit unless DoD policy allows (Option C). Options A, B, and D suggest potential credit without basis.
Extract from Official Document (CAP v1.0):
Section 1.1 -- Purpose (pg. 7):'Alternative cybersecurity certifications do not automatically bestow any status or credit towards CMMC certification unless DoD publishes non-duplication policies.'
CMMC Assessment Process (CAP) v1.0, Section 1.1.
Mollie
27 days agoElvera
2 months agoStefanie
2 months agoMeaghan
2 months agoHollis
2 months agoRolland
2 months agoMaricela
3 months agoCristy
3 months agoPete
3 months agoEric
3 months agoFrance
3 months agoTaryn
3 months agoDorcas
4 months agoDetra
4 months agoDaniel
4 months agoRosalind
4 months agoNorah
5 months agoMiss
5 months agoChandra
5 months agoMoon
5 months agoTy
5 months agoBecky
6 months agoDusti
6 months agoGlory
6 months agoLea
6 months agoTrinidad
11 days agoAlexia
17 days agoAnnelle
22 days agoMarjory
4 months ago