

Study with the several resources on Docsity
Earn points by helping other students or get them with a premium plan
Prepare for your exams
Study with the several resources on Docsity
Earn points to download
Earn points by helping other students or get them with a premium plan
Community
Ask the community for help and clear up your study doubts
Discover the best universities in your country according to Docsity users
Free resources
Download our free guides on studying techniques, anxiety management strategies, and thesis advice from Docsity tutors
An overview of the key authorities, organizations, and individuals that make up the cybersecurity maturity model certification (CMMC) ecosystem. The CMMC is a framework developed by the U.S. Department of Defense (DoD) to enhance the cybersecurity of the defense industrial base (DIB) and its supply chain. It describes the roles and responsibilities of various entities, such as the Office of the Undersecretary of Defense, the CMMC Accreditation Body, and the CMMC Assessors and Instructors Certification Organization. This information is crucial for understanding the structure and implementation of the CMMC program, which is becoming increasingly important for DoD contractors and subcontractors.
Typology: Exams
1 / 2
This page cannot be seen from the preview
Don't miss anything!
What are the three authorities in the CMMC ecosystem? - Office of the Undersecretary of Defense Cyber-AB CAICO Office of the Undersecretary of Defense: - Owns the CMMC program Cybersecurity Maturity Model Certification Accreditation Body (CMMC-AB, Cyber AB): - Nonprofit organization that implements CMMC assessments and training CMMC Assessors and Instructors Certification Organization (CAICO): - Future organization designed to be authorized to certify CMMC assessors and instructors What organizations are under Authority of the Cyber-AB? - C3PAOs, RPOs, and OSCs CMMC Third-Party Assessment Organization (C3PAO): - performs assessments for OSCs. Can also provide consulting services to OSCs Registered Practitioner Organization (RPO): - Provides recommendations and consulting advice about CMMC assessment preparation. Cannot perform assessments Organization Seeking Certification (OSC): - Organizations going through the CMMC assessment process. What individual contributors are under authority of the Cyber AB? - Registered Practioners Registered Practitioner (RP): - Implementers/consultants in certified CMMC assessments. Do not participate in assessments What organizations are under authority of the CAICO? - LPP & LTP Licensed Publishing Partner (LPP): - Creates the content used in CMMC training
Licensed Training Provider (LTP): - Provides training in CMMC courses using content provided by an LPP. What individuals are under authority of the CAICO? - CCPs, CCAs, Assessment Team Members, Lead Assessors and Certified CMMC Instructors Certified CMMC Professional (CCP): - Individuals who understand the requirements of CMMC for a DoD supplier. Can conduct level 1 assessments and have limited participation in level 2 assessments. o Must be a U.S. citizen to participate on an assessment o Exam will be available 4th quarter of 2022 Certified CMMC Assessor (CCA): - Certified to participate in a level 2 assessment and to assess all practices at level 2. o Must obtain CCP first. o Complete 3 assessments as a CCP o Pass the CCA exam o Exam is planned for 4th quarter of 2022 Assessment Team Members: - CCPs and CCAs participating on an assessment under the leadership of a Lead Assessor Lead Assessors: - Oversees and manages a CMMC assessment. Must be a CCA. Training and certification are under development. Certified CMMC Instructors (CCI): - Authorized to train CCPs and CCAs. Exam expected 1st quarter of 2023 Provisional Assessors (PA): - Trained by the Cyber AB to conduct assessments during the interim period. Will be phased out 6 months after the public release of the CCA exam. Provisional Instructors (PI): - Trained by the Cyber AB to conduct training classes during the interim period. Will be phased out 6 months after the public release of the CCI exam.