Is your organization struggling with NIST SP 800-171’s Security Requirement 3.1.22, Publicly Accessible Content?
Did you know this is one requirement that applies to normally out-of-scope components while the remaining 109 apply to internal components?
This As the CMMC Churns Understanding the Requirements, focuses on 3.1.22, Publicly Accessible Content. The video will lay out the requirement, artifacts you will need to pass a CMMC assessment, and the underlying process we use at Peak InfoSec to support this procedure.
It is HIGHLY recommended that everyone watch this video. This is one of the most misunderstood and falsely skipped over requirements, such that during a Joint Surveillance Voluntary Assessment, the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) complimented a client when they got this right on the first time, and how rare that is.
This As the CMMC Churns was originally recorded live at CMMC Day 2024. Unfortunately, the audio was bad as two audio inputs happened.
Key CMMC Organizations
- National Archives & Records Administration Controlled Unclassified Information (CUI) Homepage
- DoD CIO’s Cybersecurity Maturity Model Certification (CMMC) Home Page
- Cyber Accreditation Body (Cyber-AB)
- Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) Contractor Resource Page
- Defense Industrial Base (DIB) Cybersecurity Portal
Key Regulations
Key Acquisition References
- 48 CFR § 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems
- DFARS Clause 252.204-7008 Compliance with Safeguarding Covered Defense Information Controls.
- DFARS Clause 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
- DFARS Clause 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS Clause 252.204-7020 NIST SP 800-171 DoD Assessment Requirements.
- DFARS Clause 252.204-7021 Compliance with the Cybersecurity Maturity Model Certification Level Requirements.