An OSC has a testing laboratory. The lab has several pieces of equipment, including a workstation that is used to analyze test information collected from the test equipment. All equipment is on the same VLAN that is part of the certification assessment. The OSC claims that the workstation is part of the test equipment (Specialized Asset) and only needs to be addressed under risk-based security policies. However, the OSC states that the data analysis output is CUI. What is the assessor's BEST response?
If an asset processes or generates CUI, it is a CUI Asset by definition, regardless of whether it is also part of a test lab or claimed as a Specialized Asset. Specialized Asset handling applies only when the asset does not process, store, or transmit CUI. Since the workstation outputs CUI, it must be assessed fully against CMMC practices.
Exact extracts:
''CUI Assets are those that process, store, or transmit CUI.''
''Specialized Assets... do not process, store, or transmit CUI.''
''If a Specialized Asset processes CUI, it must be categorized as a CUI Asset and is assessed against all applicable practices.''
Why the other options are incorrect:
B: The issue is not with the SSP practice; it is with misclassification of an asset.
C/D: Risk-based treatment applies only to Specialized Assets without CUI, which is not the case here.
CMMC Level 2 Scoping Guide -- Specialized Assets; CUI Asset definitions.
===========
Jani
5 hours agoNikita
5 days agoSabrina
11 days agoCasie
16 days ago