Which phase of the CMMC Assessment Process includes the task to identify, obtain inventory, and verify evidence?
Understanding the CMMC Assessment Process
TheCMMC Assessment Process (CAP)consists offour phases, each with specific tasks and objectives.
Phase 1: Plan and Prepare Assessment-- Planning, scheduling, and preparing for the assessment.
Phase 2: Conduct Assessment--Gathering and verifying evidence, conducting interviews, and evaluating compliance.
Phase 3: Report Recommended Assessment Results-- Documenting findings and reporting results.
Phase 4: Remediation of Outstanding Assessment Issues-- Allowing the organization to address any deficiencies.
Why 'Phase 2: Conduct Assessment' is Correct?
DuringPhase 2: Conduct Assessment, theAssessment Teamperforms key activities, including:
Identifying required evidencefor compliance verification.
Obtaining and reviewing artifacts(e.g., security policies, configurations, logs).
Verifying the sufficiency of evidenceagainst CMMC practice requirements.
Interviewing key personneland observing cybersecurity implementations.
Since the question specifically mentions'identify, obtain inventory, and verify evidence,'this task directly falls underPhase 2: Conduct Assessment.
Breakdown of Answer Choices
Option
Description
Correct?
A . Phase 1: Plan and Prepare Assessment
Incorrect--This phase focuses onscheduling, logistics, and planning, not evidence collection.
B . Phase 2: Conduct Assessment
Correct -- This phase involves gathering, verifying, and reviewing evidence.
C . Phase 3: Report Recommended Assessment Results
Incorrect--This phasedocumentsresults but doesnotcollect evidence.
D . Phase 4: Remediation of Outstanding Assessment Issues
Incorrect--This phase focuses oncorrective actions, not evidence collection.
Official Reference from CMMC 2.0 Documentation
CMMC Assessment Process Guide (CAP)--Phase 2: Conduct Assessmentexplicitly includes tasks such asgathering and verifying evidence.
Final Verification and Conclusion
The correct answer isB. Phase 2: Conduct Assessment, as this phase includesidentifying, obtaining, and verifying evidence, which is critical for determining CMMC compliance.
Currently there are no comments in this discussion, be the first to comment!