Which principles are included in defining the CMMC-AB Code of Professional Conduct?
The Cyber AB (formerly CMMC-AB) Code of Professional Conduct (CoPC) is a mandatory agreement that all CMMC ecosystem members---including Certified CMMC Professionals (CCPs) and Certified CMMC Assessors (CCAs)---must adhere to. This code ensures the reliability and trustworthiness of the assessment process.
The fundamental principles that form the foundation of the CoPC include:
Responsibility: This refers to the obligation of the CMMC professional to act in the best interest of the CMMC program, the Department of Defense (DoD), and the public. It includes maintaining professional competence and performing duties with due care.
Confidentiality: Assessors and professionals are granted access to sensitive information, including Controlled Unclassified Information (CUI) and proprietary business data of the Organization Seeking Certification (OSC). They must ensure this information is protected from unauthorized disclosure.
Information Integrity: This principle requires that all data, findings, and reports generated during the assessment are accurate, complete, and have not been tampered with. It ensures that the 'Met' or 'Not Met' determinations are based on honest evidence.
Why other options are incorrect:
Options A and B (Objectivity): While 'Objectivity' is a crucialbehavioralrequirement for an assessor (remaining unbiased), the specific high-level triad often emphasized in the CMMC Professional training and the formal CoPC documentation focuses on the Responsibility-Confidentiality-Integrity framework to align with standard professional ethics and information security pillars.
Options A and C (Classification): 'Classification' is a process used for National Security Information (Classified info), whereas CMMC is primarily focused on unclassified information (CUI and FCI). Classification is not a core principle of the professional code of conduct.
Options A and C (Information Accuracy): While accuracy is vital, it is considered a subset of Information Integrity within the formal definitions provided in the CCP curriculum.
Reference Documents:
CMMC-AB (The Cyber AB) Code of Professional Conduct: The official ethical framework for all credentialed individuals.
CMMC Professional (CCP) Study Guide: Section on 'Ethics and the Code of Professional Conduct.'
CMMC Assessment Process (CAP): Reference the ethical standards required to maintain the integrity of the assessment ecosystem.
Which method facilitates understanding by analyzing gathered artifacts as evidence?
The CMMC Assessment Process uses three methods: Examine, Interview, and Test. The method that involves analyzing artifacts (documents, system configurations, records, logs, etc.) is Examine.
Supporting Extracts from Official Content:
CMMC Assessment Guide: ''Examine consists of reviewing, inspecting, or analyzing assessment objects such as documents, system configurations, or other artifacts to evaluate compliance.''
Why Option B is Correct:
Examine = analyzing artifacts.
Interview = discussions with personnel.
Test = executing technical checks.
Behavior is not an assessment method.
Reference (Official CMMC v2.0 Content):
CMMC Assessment Guide, Levels 1 and 2 --- Assessment Methods (Examine, Interview, Test).
===========
An assessment is being conducted at a remote client site. For the duration of the assessment, the client has provided a designated hoteling space in their secure facility which consists of a desk with access to a shared printer. After noticing that the desk does not lock, a locked cabinet is requested but the client does not have one available. At the end of the day, the client provides a printout copy of an important network diagram. The diagram is clearly marked and contains CUI. What should be done NEXT to protect the document?
In this scenario, the primary concern is the protection of Controlled Unclassified Information (CUI) in an environment that lacks sufficient physical security controls (specifically, a lack of a locked cabinet or drawer). According to the CMMC Assessment Process (CAP) and NIST SP 800-171 (specifically the Physical Protection (PE) family), CUI must be protected from unauthorized access at all times.
Responsibility of the Assessor: CMMC Professionals (CCPs and CCAs) are bound by the CMMC Code of Professional Conduct and the C3PAO's internal security protocols to ensure that any CUI provided by the Organization Seeking Certification (OSC) is handled securely.
Physical Protection (PE.L2-3.10.1 and PE.L2-3.10.2): These practices require that an organization limit physical access to systems and equipment to authorized users and protect the physical facility. If the provided 'hoteling space' does not offer a locked container (like a cabinet) to secure the CUI overnight, leaving it in an unlocked drawer (Option C) or on the desk (Option B) would be a violation of CUI handling requirements and a security risk.
Why Option A is the best 'Next' step: In the absence of on-site secure storage, the assessor must maintain positive control of the CUI. Taking the document to a secure location (such as the assessor's hotel room or person) where they can ensure it remains under their control is the only viable way to prevent unauthorized access by janitorial staff or other unauthorized personnel at the client site overnight.
Why other options are incorrect:
Option B and C: Both fail to protect the CUI from unauthorized access in a non-secure, shared environment.
Option D: Taking a picture of CUI on a personal phone is a major security violation (spillage), as personal devices are generally not authorized to store or process CUI.
Reference Documents:
CMMC Assessment Process (CAP) v1.0: Section regarding 'Assessor Responsibilities for CUI and Proprietary Information.'
NIST SP 800-171 Rev 2: Physical Protection (PE) family (3.10.1, 3.10.2).
DoD Instruction 5200.48: 'Controlled Unclassified Information (CUI),' which specifies that CUI must be protected by at least one physical barrier when not in the direct control of an authorized individual.
Which phase of the CMMC Assessment Process includes the task to identify, obtain inventory, and verify evidence?
Understanding the CMMC Assessment Process
TheCMMC Assessment Process (CAP)consists offour phases, each with specific tasks and objectives.
Phase 1: Plan and Prepare Assessment-- Planning, scheduling, and preparing for the assessment.
Phase 2: Conduct Assessment--Gathering and verifying evidence, conducting interviews, and evaluating compliance.
Phase 3: Report Recommended Assessment Results-- Documenting findings and reporting results.
Phase 4: Remediation of Outstanding Assessment Issues-- Allowing the organization to address any deficiencies.
Why 'Phase 2: Conduct Assessment' is Correct?
DuringPhase 2: Conduct Assessment, theAssessment Teamperforms key activities, including:
Identifying required evidencefor compliance verification.
Obtaining and reviewing artifacts(e.g., security policies, configurations, logs).
Verifying the sufficiency of evidenceagainst CMMC practice requirements.
Interviewing key personneland observing cybersecurity implementations.
Since the question specifically mentions'identify, obtain inventory, and verify evidence,'this task directly falls underPhase 2: Conduct Assessment.
Breakdown of Answer Choices
Option
Description
Correct?
A . Phase 1: Plan and Prepare Assessment
Incorrect--This phase focuses onscheduling, logistics, and planning, not evidence collection.
B . Phase 2: Conduct Assessment
Correct -- This phase involves gathering, verifying, and reviewing evidence.
C . Phase 3: Report Recommended Assessment Results
Incorrect--This phasedocumentsresults but doesnotcollect evidence.
D . Phase 4: Remediation of Outstanding Assessment Issues
Incorrect--This phase focuses oncorrective actions, not evidence collection.
Official Reference from CMMC 2.0 Documentation
CMMC Assessment Process Guide (CAP)--Phase 2: Conduct Assessmentexplicitly includes tasks such asgathering and verifying evidence.
Final Verification and Conclusion
The correct answer isB. Phase 2: Conduct Assessment, as this phase includesidentifying, obtaining, and verifying evidence, which is critical for determining CMMC compliance.
During a Level 1 Self-Assessment, a smart thermostat was identified. It is connected to the Internet on the OSC's WiFi network. What type of asset is this?
Understanding Asset Categorization in CMMC 2.0
InCMMC 2.0, assets are categorized into different types based on their function, connectivity, and whether they process, store, or transmitFederal Contract Information (FCI) or Controlled Unclassified Information (CUI).
Why 'D. Specialized Asset' is Correct?
TheCMMC 2.0 Scoping GuidedefinesSpecialized Assetsas assetsthat do not fit traditional IT classificationsbut still exist within the organizational environment.
Asmart thermostatis anInternet of Things (IoT) device, which falls underSpecialized Assetsas defined in CMMC.
Why Other Answers Are Incorrect?
A . FCI Asset (Incorrect)
FCI Assets process, store, or transmit Federal Contract Information, which asmart thermostat does not.
B . CUI Asset (Incorrect)
CUI Assets handle Controlled Unclassified Information, and athermostat does not process CUI.
C . In-scope Asset (Incorrect)
In-scope Assets include FCI and CUI assets, which asmart thermostat does not qualify as.
Conclusion
The correct answer isD. Specialized Asset, as asmart thermostat is an IoT device, which falls into theSpecialized Assetcategory.
CMMC 2.0 Scoping Guide
DoD Cybersecurity Guidelines on IoT Devices
William Reed
7 days agoMatthew Moore
23 days agoChristopher Sanchez
1 month agoSharon Martinez
2 months agoCarol Anderson
2 months agoHeather Johnson
3 months agoCharles Lewis
3 months agoPatricia Sanchez
4 months agoDaniel Jones
3 months agoCarol Nguyen
3 months agoFrank Jones
3 months agoAngela Gonzalez
4 months agoDonald Young
3 months agoVallie
4 months agoMargery
5 months agoLarae
5 months agoRoyce
5 months agoGarry
5 months agoHassie
6 months agoSharita
6 months agoElvis
6 months agoDerrick
6 months agoRemedios
7 months agoEladia
7 months agoJeanice
7 months agoJamie
7 months agoNoah
8 months agoDudley
8 months agoBritt
8 months agoArlean
8 months agoYuki
9 months agoTiara
9 months agoBernardine
9 months agoRaylene
9 months agoVeta
10 months agoVallie
10 months agoTuyet
10 months agoArleen
10 months agoMargery
11 months agoTeri
11 months agoShawnee
11 months agoEladia
11 months agoFlorinda
11 months agoJanine
11 months ago