Did you know that 3.3.3, Review and Update Logged Events, is a commonly and THOROUGHLY misunderstood requirement? Let’s be blunt, 3.3.3 has NOTHING to do with identifying potential events that indicate a compromise.
If your understanding of 3.3.3 is to review audit logs and look for indicators of malicious activity, you really need to watch this video…
Like all of the other As the CMMC Churns videos focusing “Understanding the Requirements,” we are taking a dive into one requirement, its related predecessor and dependent requirements, and what Certified CMMC Assessors (CCP) will be looking for when you get assessed on this requirement.
Key CMMC Organizations
- National Archives & Records Administration Controlled Unclassified Information (CUI) Homepage
- DoD CIO’s Cybersecurity Maturity Model Certification (CMMC) Home Page
- Cyber Accreditation Body (Cyber-AB)
- Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) Contractor Resource Page
- Defense Industrial Base (DIB) Cybersecurity Portal
Key Regulations
Key Acquisition References
- 48 CFR § 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems
- DFARS Clause 252.204-7008 Compliance with Safeguarding Covered Defense Information Controls.
- DFARS Clause 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
- DFARS Clause 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS Clause 252.204-7020 NIST SP 800-171 DoD Assessment Requirements.
- DFARS Clause 252.204-7021 Compliance with the Cybersecurity Maturity Model Certification Level Requirements.