Docsity
Docsity

Prepare for your exams
Prepare for your exams

Study with the several resources on Docsity


Earn points to download
Earn points to download

Earn points by helping other students or get them with a premium plan


Guidelines and tips
Guidelines and tips

The CMMC Ecosystem: Authorities, Organizations, and Individuals, Exams of Cybercrime, Cybersecurity and Data Privacy

An overview of the key authorities, organizations, and individuals that make up the cybersecurity maturity model certification (CMMC) ecosystem. The CMMC is a framework developed by the U.S. Department of Defense (DoD) to enhance the cybersecurity of the defense industrial base (DIB) and its supply chain. It describes the roles and responsibilities of various entities, such as the Office of the Undersecretary of Defense, the CMMC Accreditation Body, and the CMMC Assessors and Instructors Certification Organization. This information is crucial for understanding the structure and implementation of the CMMC program, which is becoming increasingly important for DoD contractors and subcontractors.

Typology: Exams

2023/2024

Available from 10/07/2024

DANTUTOR
DANTUTOR 🇬🇧

62 documents

1 / 2

Toggle sidebar

This page cannot be seen from the preview

Don't miss anything!

bg1
CMMC Ecosystem
What are the three authorities in the CMMC ecosystem? -
Office of the Undersecretary of Defense
Cyber-AB
CAICO
Office of the Undersecretary of Defense: -
Owns the CMMC program
Cybersecurity Maturity Model Certification Accreditation Body (CMMC-AB, Cyber AB): -
Nonprofit organization that implements CMMC assessments and training
CMMC Assessors and Instructors Certification Organization (CAICO): -
Future
organization designed to be authorized to certify CMMC assessors and instructors
What organizations are under Authority of the Cyber-AB? -
C3PAOs, RPOs, and OSCs
CMMC Third-Party Assessment Organization (C3PAO): -
performs assessments for OSCs.
Can also provide consulting services to OSCs
Registered Practitioner Organization (RPO): -
Provides recommendations and consulting
advice about CMMC assessment preparation. Cannot perform assessments
Organization Seeking Certification (OSC): -
Organizations going through the CMMC
assessment process.
What individual contributors are under authority of the Cyber AB? -
Registered Practioners
Registered Practitioner (RP): -
Implementers/consultants in certified CMMC assessments.
Do not participate in assessments
What organizations are under authority of the CAICO? -
LPP & LTP
Licensed Publishing Partner (LPP): -
Creates the content used in CMMC training
pf2

Partial preview of the text

Download The CMMC Ecosystem: Authorities, Organizations, and Individuals and more Exams Cybercrime, Cybersecurity and Data Privacy in PDF only on Docsity!

CMMC Ecosystem

What are the three authorities in the CMMC ecosystem? - Office of the Undersecretary of Defense Cyber-AB CAICO Office of the Undersecretary of Defense: - Owns the CMMC program Cybersecurity Maturity Model Certification Accreditation Body (CMMC-AB, Cyber AB): - Nonprofit organization that implements CMMC assessments and training CMMC Assessors and Instructors Certification Organization (CAICO): - Future organization designed to be authorized to certify CMMC assessors and instructors What organizations are under Authority of the Cyber-AB? - C3PAOs, RPOs, and OSCs CMMC Third-Party Assessment Organization (C3PAO): - performs assessments for OSCs. Can also provide consulting services to OSCs Registered Practitioner Organization (RPO): - Provides recommendations and consulting advice about CMMC assessment preparation. Cannot perform assessments Organization Seeking Certification (OSC): - Organizations going through the CMMC assessment process. What individual contributors are under authority of the Cyber AB? - Registered Practioners Registered Practitioner (RP): - Implementers/consultants in certified CMMC assessments. Do not participate in assessments What organizations are under authority of the CAICO? - LPP & LTP Licensed Publishing Partner (LPP): - Creates the content used in CMMC training

Licensed Training Provider (LTP): - Provides training in CMMC courses using content provided by an LPP. What individuals are under authority of the CAICO? - CCPs, CCAs, Assessment Team Members, Lead Assessors and Certified CMMC Instructors Certified CMMC Professional (CCP): - Individuals who understand the requirements of CMMC for a DoD supplier. Can conduct level 1 assessments and have limited participation in level 2 assessments. o Must be a U.S. citizen to participate on an assessment o Exam will be available 4th quarter of 2022 Certified CMMC Assessor (CCA): - Certified to participate in a level 2 assessment and to assess all practices at level 2. o Must obtain CCP first. o Complete 3 assessments as a CCP o Pass the CCA exam o Exam is planned for 4th quarter of 2022 Assessment Team Members: - CCPs and CCAs participating on an assessment under the leadership of a Lead Assessor Lead Assessors: - Oversees and manages a CMMC assessment. Must be a CCA. Training and certification are under development. Certified CMMC Instructors (CCI): - Authorized to train CCPs and CCAs. Exam expected 1st quarter of 2023 Provisional Assessors (PA): - Trained by the Cyber AB to conduct assessments during the interim period. Will be phased out 6 months after the public release of the CCA exam. Provisional Instructors (PI): - Trained by the Cyber AB to conduct training classes during the interim period. Will be phased out 6 months after the public release of the CCI exam.