During an assessment, the OSC was found to have implemented 68% of CMMC practice SC.L2-3.13.11 -- CUI Encryption. However, the OSC Assessment Official cited issues with the vendor for not fully implementing the practice. Nonetheless, it has been listed in their POA&M. Which of the following is true regarding the use of a POA&M during a CMMC assessment?
Comprehensive and Detailed In-Depth Explanatio n:
SC.L2-3.13.11 (5-point practice) requires full implementation for certification. Per CAP, a POA&M documents deficiencies but isn't a substitute for completion (A). Options B, C, and D contradict CMMC rules, as partial implementation or POA&M listing doesn't equate to Met status, especially for 5-point practices ineligible for POA&M deferral.
Extract from Official CMMC Documentation:
CMMC Assessment Guide Level 2 (v2.0), SC.L2-3.13.11: 'Full implementation required.'
CAP v5.6.1: 'POA&M not a substitute for Met status.'
Resources:
https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_Level2_MasterV2.0_FINAL_202112016_508.pdf
Jin
15 days agoOliva
20 days agoAntonio
25 days agoGearldine
1 month agoReiko
1 month agoVince
1 month agoBen
2 months agoCrista
2 months agoElmer
2 months agoSharen
2 months agoTyra
2 months agoJutta
2 months ago