Are looking to understand how to document your SSP? How does the NIST SP 800-171 Scope of Applicability and CMMC Assessment Scope fit in the SSP?
In this “At the CMMC Churns,” we take the Scope of Applicability, turn it into a diagram, and incorporate it into your SSP. Yes, incredibly exciting!!! A very foundational to building a solid SSP.
This episode builds on two previous Churns episodes:
- How to apply the NIST SP 800-171 Scope of Applicability (https://peakinfosec.com/as-the-cmmc-churns/as-the-cmmc-churns-nist-sp-800-171-scope-of-applicability/)
- The Three Descoping Methods (https://peakinfosec.com/as-the-cmmc-churns/as-the-cmmc-churns-the-three-descoping-methods/)
We also reference the NIST SP 800-171 and CMMC Level 2 Assessment Scoping Process Diagram at https://peakinfosec.com/information-security/compliance/nist-sp-800-171-and-cmmc-level-2-assessment-scoping-process-diagram/.
Key CMMC Organizations
- National Archives & Records Administration Controlled Unclassified Information (CUI) Homepage
- DoD CIO’s Cybersecurity Maturity Model Certification (CMMC) Home Page
- Cyber Accreditation Body (Cyber-AB)
- Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) Contractor Resource Page
- Defense Industrial Base (DIB) Cybersecurity Portal
Key Regulations
Key Acquisition References
- 48 CFR § 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems
- DFARS Clause 252.204-7008 Compliance with Safeguarding Covered Defense Information Controls.
- DFARS Clause 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
- DFARS Clause 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS Clause 252.204-7020 NIST SP 800-171 DoD Assessment Requirements.
- DFARS Clause 252.204-7021 Compliance with the Cybersecurity Maturity Model Certification Level Requirements.