CMMC Assessors Requirements Announced

By Kathryn Daily, CISSP, CAP, RDRP Despite the current pandemic, the CMMC AB (Cybersecurity Maturity Model Certification Accreditation Body) is moving right along. They have now announced the requirements to become a Certified Professional (CP), Certified Assessor (CA), Certified Third Party Assessment Organization (C3PAO), or Registered Practitioner. The C3PAO will…

Continue Reading

Post Categories: CMMC Tags:

CMMC Continues to Mature

By Kathryn Daily, CISSP, CAP, RDRP CMMC is still a hot conversation topic in the DoD world.  The model as well as the process surrounding the model continue to develop and has largely stuck to the initial schedule set out by Katie Arrington at the onset of this project, no…

Continue Reading

Post Categories: CMMCUncategorized Tags:

Dear Dr. RMF

Dear Dr. RMF, I am doing an annual review for an information system I have. Originally, this was inherited from our network boundary, but in reviewing this again it speaks specifically to information systems, which from my under-standing this cannot be inherited. If I am reading this control correctly it…

Continue Reading

Post Categories: Dr. RMFUncategorized Tags:

Dear Dr. RMF

Dear Dr. RMF, I have an information system that is current-ly being assessed and authorized and the boundary consists of desktops, laptops, printers, a major OS, and about 10 to 15 applications, which is spread throughout an enterprise. In reviewing the DoDI 8510.01 and the definition of IT products it…

Continue Reading

Post Categories: Dr. RMFUncategorized Tags:

Dear Dr. RMF

Dear Dr. RMF, In my office we are disputing whether RMF Control SA-4 can be inherited, or if it needs to be system-specific. The control description includes the work “Organization”, but the compelling evidence (per eMASS) calls for SSP. Furthermore, the Assessment Procedure calls for the contract/agreement to be inspected….

Continue Reading

Post Categories: Dr. RMFUncategorized Tags: