CA.L2-3.12.2 Plan of Action

CMMC Practice CA.L2-3.12.2 – Plan of Action: Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems. Links to Publicly Available Resources Centers for Medicare & Medicaid...

CA.L2-3.12.1 Security Control Assessment

CMMC Practice CA.L2-3.12.1 – Security Control Assessment: Periodically assess the security controls in organizational systems to determine if the controls are effective in their application. Links to Publicly Available Resources CMMC Level 2 Assessment Guide...

CA.L2-3.12.4 System Security Plan

CMMC Practice CA.L2-3.12.4 – System Security Plan: Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or...

RA.L2-3.11.3 Vulnerability Remediation

CMMC Practice RA.L2-3.11.3 – Vulnerability Remediation: Remediate vulnerabilities in accordance with risk assessments. Links to Publicly Available Resources BrightTALK – Is Your Vulnerability Management Program Vulnerable? In this two part webinar from...

RA.L2-3.11.2 Vulnerability Scan

CMMC Practice RA.L2-3.11.2 – Vulnerability Scan: Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified. Links to Publicly Available Resources Assured...

RA.L2-3.11.1 Risk Assessments

CMMC Practice RA.L2-3.11.1 – Risk Assessments: Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the...