You are the Lead Assessor for a CMMC assessment of an OSC that has previously obtained ISO 27001 certification for its information security management system. During the initial discussions, the OSC requests that you consider their ISO 27001 certification and grant them credit toward their CMMC certification. They believe there is a significant overlap between CMMC and ISO 27001. What should your response to the OSC be?
Comprehensive and Detailed in Depth
The CAP explicitly states that other certifications like ISO 27001 do not grant automatic CMMC credit unless DoD policy allows (Option C). Options A, B, and D suggest potential credit without basis.
Extract from Official Document (CAP v1.0):
Section 1.1 -- Purpose (pg. 7):'Alternative cybersecurity certifications do not automatically bestow any status or credit towards CMMC certification unless DoD publishes non-duplication policies.'
CMMC Assessment Process (CAP) v1.0, Section 1.1.
Elvera
5 days agoStefanie
10 days agoMeaghan
16 days agoHollis
21 days agoRolland
26 days agoMaricela
1 month agoCristy
1 month agoPete
1 month agoEric
2 months agoFrance
2 months agoTaryn
2 months agoDorcas
2 months agoDetra
2 months agoDaniel
2 months agoRosalind
3 months agoNorah
3 months agoMiss
3 months agoChandra
4 months agoMoon
4 months agoTy
4 months agoBecky
4 months agoDusti
4 months agoGlory
4 months agoLea
5 months agoMarjory
3 months ago